2021-07-14 19:10:41 +00:00
|
|
|
name: helm-release
|
|
|
|
on:
|
|
|
|
push:
|
2021-08-20 22:06:58 +00:00
|
|
|
tags:
|
2022-04-27 03:52:45 +00:00
|
|
|
- 'kyverno-chart-v*'
|
|
|
|
- 'kyverno-policies-chart-v*'
|
2022-09-08 17:34:09 +00:00
|
|
|
- 'kyverno-chart-*'
|
|
|
|
- 'kyverno-policies-chart-*'
|
2021-07-14 19:10:41 +00:00
|
|
|
|
|
|
|
jobs:
|
2021-07-21 00:06:56 +00:00
|
|
|
helm-tests:
|
|
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
|
|
- name: Checkout
|
2022-01-13 05:23:05 +00:00
|
|
|
uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579 # v2.4.0
|
2021-07-21 00:06:56 +00:00
|
|
|
|
|
|
|
- name: Unshallow
|
|
|
|
run: git fetch --prune --unshallow
|
|
|
|
|
2022-01-13 05:23:05 +00:00
|
|
|
- uses: actions/setup-python@f38219332975fe8f9c04cca981d674bf22aea1d3 # v2.3.1
|
2021-07-21 00:06:56 +00:00
|
|
|
with:
|
|
|
|
python-version: 3.7
|
|
|
|
|
|
|
|
- name: Set up chart-testing
|
2022-01-13 05:23:05 +00:00
|
|
|
uses: helm/chart-testing-action@b0d4458c71155b54fcf33e11dd465dc923550009 # v2.0.1
|
2021-07-21 00:06:56 +00:00
|
|
|
|
|
|
|
- name: Run chart-testing (lint)
|
|
|
|
run: ct lint --target-branch=main --check-version-increment=false
|
|
|
|
|
2021-07-14 19:10:41 +00:00
|
|
|
create-release:
|
|
|
|
runs-on: ubuntu-latest
|
2021-07-21 00:06:56 +00:00
|
|
|
needs: helm-tests
|
2022-10-12 20:14:44 +00:00
|
|
|
permissions:
|
|
|
|
contents: write
|
|
|
|
packages: write
|
|
|
|
id-token: write
|
|
|
|
pages: write
|
2021-07-14 19:10:41 +00:00
|
|
|
steps:
|
2021-07-19 20:01:17 +00:00
|
|
|
- name: Checkout
|
2022-01-13 05:23:05 +00:00
|
|
|
uses: actions/checkout@ec3a7ce113134d7a93b817d10a8272cb61118579 # v2.4.0
|
2021-07-19 20:01:17 +00:00
|
|
|
with:
|
|
|
|
fetch-depth: 0
|
2022-09-02 08:55:41 +00:00
|
|
|
|
2021-07-14 19:10:41 +00:00
|
|
|
- name: Install Helm
|
2022-01-13 05:23:05 +00:00
|
|
|
uses: azure/setup-helm@18bc76811624f360dbd7f18c2d4ecb32c7b87bab # v1.1
|
2021-07-14 19:10:41 +00:00
|
|
|
with:
|
2022-09-01 19:15:33 +00:00
|
|
|
version: v3.8.0
|
2021-07-14 19:10:41 +00:00
|
|
|
|
2022-10-12 20:14:44 +00:00
|
|
|
- name: Install Cosign
|
2022-12-02 09:47:04 +00:00
|
|
|
uses: sigstore/cosign-installer@9becc617647dfa20ae7b1151972e9b3a2c338a2b # v2.8.1
|
2022-10-12 20:14:44 +00:00
|
|
|
with:
|
|
|
|
cosign-release: 'v1.13.0'
|
|
|
|
|
|
|
|
|
2022-04-27 03:52:45 +00:00
|
|
|
- name: Set version
|
|
|
|
run: echo "RELEASE_VERSION=${GITHUB_REF#refs/*/}" >> $GITHUB_ENV
|
|
|
|
|
|
|
|
- name: Create charts tmp directory
|
|
|
|
run: |
|
|
|
|
mkdir charts-tmp
|
|
|
|
if [[ "$RELEASE_VERSION" = "kyverno-policies-chart-v"* ]]; then
|
|
|
|
cp -a charts/kyverno-policies charts-tmp/kyverno-policies
|
|
|
|
fi
|
|
|
|
if [[ "$RELEASE_VERSION" = "kyverno-chart-v"* ]]; then
|
|
|
|
cp -a charts/kyverno charts-tmp/kyverno
|
|
|
|
fi
|
2022-09-12 07:36:46 +00:00
|
|
|
if [[ "$RELEASE_VERSION" = "kyverno-policies-chart-"* ]]; then
|
|
|
|
cp -a charts/kyverno-policies charts-tmp/kyverno-policies
|
|
|
|
fi
|
|
|
|
if [[ "$RELEASE_VERSION" = "kyverno-chart-"* ]]; then
|
|
|
|
cp -a charts/kyverno charts-tmp/kyverno
|
|
|
|
fi
|
2022-04-27 03:52:45 +00:00
|
|
|
|
2021-07-14 19:10:41 +00:00
|
|
|
- name: Run chart-releaser
|
2022-02-21 15:50:42 +00:00
|
|
|
uses: stefanprodan/helm-gh-pages@b43a8719cc63fdb3aa943cc57359ab19118eab3f #v1.5.0
|
2021-07-14 19:10:41 +00:00
|
|
|
with:
|
2021-07-20 19:49:37 +00:00
|
|
|
token: "${{ secrets.GITHUB_TOKEN }}"
|
2022-02-21 15:50:42 +00:00
|
|
|
linting: off
|
2022-04-27 03:52:45 +00:00
|
|
|
charts_dir: charts-tmp
|
2022-09-01 19:15:33 +00:00
|
|
|
|
|
|
|
- name: Login to GitHub Container Registry
|
|
|
|
run: |
|
|
|
|
helm registry login --username ${GITHUB_ACTOR} --password ${{ secrets.GITHUB_TOKEN }} ghcr.io
|
|
|
|
|
|
|
|
- name: Publish OCI Charts
|
2022-10-12 20:14:44 +00:00
|
|
|
env:
|
|
|
|
COSIGN_EXPERIMENTAL: 1
|
2022-09-01 19:15:33 +00:00
|
|
|
run: |
|
|
|
|
for dir in `find charts-tmp -maxdepth 1 -mindepth 1 -type d -print`; do
|
|
|
|
chart=${dir##*/}
|
|
|
|
echo "Found chart: ${chart}"
|
2022-10-02 20:20:33 +00:00
|
|
|
helm package charts-tmp/${chart} --destination .dist
|
2022-10-12 20:14:44 +00:00
|
|
|
helm push .dist/${chart}-*.tgz oci://ghcr.io/${{ github.repository_owner }}/charts > .digest
|
|
|
|
cosign login --username ${GITHUB_ACTOR} --password ${{ secrets.CR_PAT_ARTIFACTS }} ghcr.io
|
|
|
|
cosign sign ghcr.io/${{ github.repository_owner }}/charts/${chart}@$(cat .digest | awk -F "[, ]+" '/Digest/{print $NF}')
|
2022-10-02 20:20:33 +00:00
|
|
|
done
|