mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-01 19:12:14 +00:00
e2b2bdcc34
Three hardening changes with no effect on what any workflow produces. Declare timeout-minutes on the 25 jobs that lacked it. GitHub's default is 360 minutes, and this repository has a history of runners stalling intermittently (#5394) plus a measured 9m57s plain `git checkout` under node-level I/O contention, so one wedged job could hold a runner for six hours out of a pool of roughly 15-21. Budgets follow what the jobs actually do: 10 minutes for echo-only and guard-script jobs, 30 for anything calling the GitHub API, uploading release assets or pushing over the network. scripts/security/check_job_timeouts.sh keeps it that way, checking only jobs that declare runs-on so reusable-workflow callers are not flagged. Pass workflow inputs and workflow_run fields through env instead of `${{ }}` interpolation in run blocks. A git ref name may contain `$(...)` — any string without a space is a legal tag — and interpolation pastes it into the script where bash evaluates it. The worst instance was helm-package's final commit message: it is built from the triggering tag name inside the job that holds the cross-repository push token with rustfs/helm already checked out. Also converted in build.yml, docker.yml and performance-ab.yml; the last is currently disabled, but a disabled workflow can be re-enabled. Not touched: helm-package's `contains(head_branch, '.')` tag test, since GitHub expressions have no regex and this repository's tags carry no `v` prefix, so rewriting the condition would change which builds publish a chart. Give audit.yml a scheduled-failure alert and run it daily. A scheduled cargo-deny failure usually means the dependency tree just matched a newly published RustSec advisory — the most important signal this workflow produces, and until now it was visible only to whoever happened to open the Actions tab. coverage.yml and e2e-replication-nightly.yml already use this ci-8 mechanism. The cron moves from weekly to daily so a new advisory against an unchanged tree surfaces within a day instead of seven; the check list is untouched, since splitting it into a light daily run and a weekly full run would create runs where sources, bans and licenses go unverified. Refs: rustfs/backlog#1598, rustfs/backlog#1602
155 lines
5.3 KiB
YAML
155 lines
5.3 KiB
YAML
# Copyright 2024 RustFS Team
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
name: Publish helm chart to artifacthub
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows: [ "Build and Release" ]
|
|
types: [ completed ]
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: "Release version to publish, e.g. 1.0.0-beta.1 or v1.0.0-beta.1"
|
|
required: true
|
|
default: "1.0.0-beta.1"
|
|
type: string
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build-helm-package:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
if: |
|
|
(github.event_name == 'workflow_dispatch' && !contains(github.event.inputs.version, '-preview')) ||
|
|
(
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
contains(github.event.workflow_run.head_branch, '.') &&
|
|
!contains(github.event.workflow_run.head_branch, '-preview')
|
|
)
|
|
|
|
outputs:
|
|
raw_tag: ${{ steps.version.outputs.raw_tag }}
|
|
app_version: ${{ steps.version.outputs.app_version }}
|
|
chart_version: ${{ steps.version.outputs.chart_version }}
|
|
|
|
steps:
|
|
- name: Checkout helm chart repo
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
|
|
# Both inputs reach the shell through env rather than `${{ }}`
|
|
# interpolation. A git ref name may contain `$(...)` — anything without a
|
|
# space is a legal tag — and interpolation pastes it into the script
|
|
# verbatim, where bash would run it. Reading "$RAW_INPUT" instead makes it
|
|
# data.
|
|
- name: Normalize release version
|
|
id: version
|
|
env:
|
|
RAW_INPUT: ${{ github.event.inputs.version }}
|
|
RAW_BRANCH: ${{ github.event.workflow_run.head_branch }}
|
|
run: |
|
|
set -eux
|
|
|
|
if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then
|
|
RAW="$RAW_INPUT"
|
|
else
|
|
RAW="$RAW_BRANCH"
|
|
fi
|
|
|
|
case "$RAW" in
|
|
refs/tags/*)
|
|
RAW_TAG="${RAW#refs/tags/}"
|
|
;;
|
|
*)
|
|
RAW_TAG="$RAW"
|
|
;;
|
|
esac
|
|
|
|
./scripts/helm_chart_version.sh "$RAW_TAG"
|
|
|
|
- name: Replace chart version and app version
|
|
env:
|
|
CHART_VERSION: ${{ steps.version.outputs.chart_version }}
|
|
APP_VERSION: ${{ steps.version.outputs.app_version }}
|
|
run: |
|
|
set -eux
|
|
sed -i -E "s/^version:.*/version: \"${CHART_VERSION}\"/" helm/rustfs/Chart.yaml
|
|
sed -i -E "s/^appVersion:.*/appVersion: \"${APP_VERSION}\"/" helm/rustfs/Chart.yaml
|
|
|
|
- name: Set up Helm
|
|
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 # v4.3.0
|
|
|
|
- name: Test Helm Chart Templates
|
|
run: ./scripts/test_helm_templates.sh
|
|
|
|
- name: Package Helm Chart
|
|
run: |
|
|
set -eux
|
|
cp helm/README.md helm/rustfs/
|
|
helm package ./helm/rustfs \
|
|
--destination helm/rustfs/ \
|
|
--version "${{ steps.version.outputs.chart_version }}"
|
|
|
|
- name: Upload helm package as artifact
|
|
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6
|
|
with:
|
|
name: helm-package
|
|
path: helm/rustfs/*.tgz
|
|
retention-days: 1
|
|
|
|
publish-helm-package:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
needs: [ build-helm-package ]
|
|
if: needs.build-helm-package.result == 'success'
|
|
|
|
steps:
|
|
- name: Checkout helm package repo
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
repository: rustfs/helm
|
|
token: ${{ secrets.RUSTFS_HELM_PACKAGE }}
|
|
|
|
- name: Download helm package
|
|
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7
|
|
with:
|
|
name: helm-package
|
|
path: ./
|
|
|
|
- name: Set up helm
|
|
uses: azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 # v4.3.0
|
|
|
|
- name: Generate index
|
|
run: helm repo index . --url https://charts.rustfs.com
|
|
|
|
# app_version is derived from the triggering tag name, and this job holds
|
|
# the cross-repository push token with rustfs/helm already checked out —
|
|
# the worst place in the repo to paste an attacker-influenced string into
|
|
# a shell line. Passed through env so bash treats it as data.
|
|
- name: Push helm package and index file
|
|
env:
|
|
GIT_USERNAME: ${{ secrets.USERNAME }}
|
|
GIT_EMAIL: ${{ secrets.EMAIL_ADDRESS }}
|
|
APP_VERSION: ${{ needs.build-helm-package.outputs.app_version }}
|
|
run: |
|
|
set -eux
|
|
git config --global user.name "${GIT_USERNAME}"
|
|
git config --global user.email "${GIT_EMAIL}"
|
|
git add .
|
|
git commit -m "Update rustfs helm package with ${APP_VERSION}." || echo "No changes to commit"
|
|
git push origin main
|