mirror of
https://github.com/kyverno/kyverno.git
synced 2025-03-31 03:45:17 +00:00
chore: add setup test env gh action (#5897)
* chore: add setup test env gh action Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com> * fix Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com> * score card Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com> Signed-off-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
This commit is contained in:
parent
07cf2c120b
commit
8f65abd5d8
3 changed files with 33 additions and 29 deletions
17
.github/actions/setup-test-env/action.yaml
vendored
Normal file
17
.github/actions/setup-test-env/action.yaml
vendored
Normal file
|
@ -0,0 +1,17 @@
|
||||||
|
name: Setup test env
|
||||||
|
|
||||||
|
description: Create kind cluster, deploy kyverno, and wait pods are ready.
|
||||||
|
|
||||||
|
inputs:
|
||||||
|
version:
|
||||||
|
description: kubernetes version
|
||||||
|
required: true
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
- shell: bash
|
||||||
|
run: |
|
||||||
|
export KIND_IMAGE=kindest/node:${{ inputs.version }}
|
||||||
|
make kind-create-cluster kind-deploy-kyverno
|
||||||
|
- uses: ./.github/actions/kyverno-wait-ready
|
10
.github/workflows/conformance.yaml
vendored
10
.github/workflows/conformance.yaml
vendored
|
@ -24,12 +24,10 @@ jobs:
|
||||||
uses: ./.github/actions/setup-build-env
|
uses: ./.github/actions/setup-build-env
|
||||||
with:
|
with:
|
||||||
build-cache-key: run-conformance
|
build-cache-key: run-conformance
|
||||||
- name: Prepare environment
|
- name: Setup test env
|
||||||
run: |
|
uses: ./.github/actions/setup-test-env
|
||||||
export KIND_IMAGE=kindest/node:${{ matrix.k8s-version }}
|
with:
|
||||||
make kind-create-cluster kind-deploy-kyverno
|
version: ${{ matrix.k8s-version }}
|
||||||
- name: Wait for Kyverno to start
|
|
||||||
uses: ./.github/actions/kyverno-wait-ready
|
|
||||||
- name: Test with kuttl
|
- name: Test with kuttl
|
||||||
run: make test-kuttl
|
run: make test-kuttl
|
||||||
- name: Debug failure
|
- name: Debug failure
|
||||||
|
|
35
.github/workflows/scorecard.yaml
vendored
35
.github/workflows/scorecard.yaml
vendored
|
@ -1,50 +1,39 @@
|
||||||
name: Scorecards supply-chain security
|
name: Scorecards supply-chain security
|
||||||
|
|
||||||
on:
|
on:
|
||||||
# Only the default branch is supported.
|
|
||||||
branch_protection_rule:
|
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '30 1 * * 6'
|
- cron: '30 1 * * 6'
|
||||||
push:
|
push:
|
||||||
branches: [ "main" ]
|
branches:
|
||||||
|
- main
|
||||||
# Declare default permissions as read only.
|
|
||||||
permissions: read-all
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
analysis:
|
analysis:
|
||||||
name: Scorecards analysis
|
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
permissions:
|
permissions:
|
||||||
# Needed to upload the results to code-scanning dashboard.
|
|
||||||
security-events: write
|
security-events: write
|
||||||
# Used to receive a badge.
|
|
||||||
id-token: write
|
id-token: write
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: "Checkout code"
|
- name: Checkout
|
||||||
uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b # v3.2.0
|
uses: actions/checkout@755da8c3cf115ac066823e79a1e1788f8940201b # v3.2.0
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
- name: Setup build env
|
||||||
- name: "Run analysis"
|
uses: ./.github/actions/setup-build-env
|
||||||
uses: ossf/scorecard-action@937ffa90d79c7d720498178154ad4c7ba1e4ad8c # tag=v2.1.0
|
- name: Run analysis
|
||||||
|
uses: ossf/scorecard-action@e38b1902ae4f44df626f11ba0734b14fb91f8f86 # v2.1.2
|
||||||
with:
|
with:
|
||||||
results_file: results.sarif
|
results_file: results.sarif
|
||||||
results_format: sarif
|
results_format: sarif
|
||||||
repo_token: ${{ secrets.SCORECARD_READ_TOKEN }}
|
repo_token: ${{ secrets.SCORECARD_READ_TOKEN }}
|
||||||
publish_results: true
|
publish_results: true
|
||||||
|
- name: Upload artifact
|
||||||
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
|
uses: actions/upload-artifact@83fd05a356d7e2593de66fc9913b3002723633cb # v3.1.1
|
||||||
# format to the repository Actions tab.
|
|
||||||
- name: "Upload artifact"
|
|
||||||
uses: actions/upload-artifact@83fd05a356d7e2593de66fc9913b3002723633cb # tag=v3.0.0
|
|
||||||
with:
|
with:
|
||||||
name: SARIF file
|
name: SARIF file
|
||||||
path: results.sarif
|
path: results.sarif
|
||||||
retention-days: 5
|
retention-days: 5
|
||||||
|
- name: Upload to code-scanning
|
||||||
# Upload the results to GitHub's code scanning dashboard.
|
uses: github/codeql-action/upload-sarif@959cbb7472c4d4ad70cdfe6f4976053fe48ab394 # v2.1.37
|
||||||
- name: "Upload to code-scanning"
|
|
||||||
uses: github/codeql-action/upload-sarif@959cbb7472c4d4ad70cdfe6f4976053fe48ab394 # tag=v2.1.37
|
|
||||||
with:
|
with:
|
||||||
sarif_file: results.sarif
|
sarif_file: results.sarif
|
||||||
|
|
Loading…
Add table
Reference in a new issue