Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[G-12] Validate examples and kubeconform in CI

Aperta
#155 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
68/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Tranquilla
Stack tecnologico
github-actions, kubernetes
Ambito
ci-cd, devops

Direzione di ricerca

Inizia da .github/workflows/lint-and-test.yaml ed esamina i file dei valori sotto examples/ e charts/graylog/ci/ci-values.yaml. Esamina le versioni di Kubernetes esistenti nella matrice di installazione e determina come dovrebbero essere coperti i manifest renderizzati, gli schemi di CRDs-catalog e il rendering di TLS Issuer. Il lavoro è completo quando CI convalida tutti gli esempi rispetto a values.schema.json ed esegue controlli kubeconform rigorosi per i rendering specificati e i manifest di esempio semplici.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

improvement infrastructure

Summary

PR #95 (chart-testing lint and install) and PR #96 (helm-unittest) closed the core CI gap. Two follow-ups remain:

  • Validate the values files under examples/ against values.schema.json
  • Run kubeconform against rendered manifests
Details

Today .github/workflows/lint-and-test.yaml lints and installs only charts/graylog/ci/ci-values.yaml. Nothing in CI reads examples/, and kubeconform appears nowhere in the repo.

Examples validation. helm template -f <example> enforces the values schema, so a loop over the three example values files is enough. All of them pass today, so the step starts green, and it would have flagged the pre-fix AWS example from #121 (input entries missing the schema-required name).

kubeconform. Render the defaults, the ci values, and each example, then pipe through kubeconform -strict with -kubernetes-version set from the existing install-matrix versions (v1.32.11, v1.33.7, v1.34.3). Note kubeconform wants the version without the v prefix. The chart renders two CRs, MongoDBCommunity and the cert-manager Issuer, neither in kubeconform's default catalog. Add the datreeio CRDs-catalog as a second -schema-location (it carries both schemas) using the template {{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json. The Issuer only renders when ingress.enabled and ingress.config.tls.issuer.managed.enabled are both set, which no current values file does, so add one extra render with those flags to cover it.

Both checks are static and need no cluster, so they fit the existing lint job or a small new job.

Reference: G-12 (Production Readiness Review)

Impact

Example files are the first thing users copy, and nothing stops them from drifting. That is how #121 happened. kubeconform adds Kubernetes API validation of rendered manifests, which neither helm template nor the unit tests provide.

Notes for maintainers

  • The schema check is only as strong as the schema. values.schema.json sets no additionalProperties: false anywhere, so unknown and deprecated keys pass silently. Tightening it is a separate discussion (#63 touches the same file).
  • Schema validation cannot see YAML duplicate keys. examples/values-existing-secret-external-mongodb.yaml declares graylog: twice (lines 43 and 77) and last-key-wins parsing silently drops the first block. A yamllint pass over examples/ catches this class, and the duplicate itself deserves a fix.
  • examples/graylog-secret.yaml and examples/testing/test-gelf-input.yaml are plain manifests, so kubeconform can check them directly in the same step.
  • kubeconform needs network access to fetch schemas, or a pre-populated cache.
Lingua principale
Go Template
Stelle
12
Fork
4
Merge medio
6g 2h
PR unite (30g)
3

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Graylog2/graylog-helm

Tutte le issue di Graylog2/graylog-helm

Issue simili

Altre issue su DevOps

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.