[G-12] Validate examples and kubeconform in CI
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 68/100
Direzione di ricerca
Inizia da .github/workflows/lint-and-test.yaml ed esamina i file dei valori sotto examples/ e charts/graylog/ci/ci-values.yaml. Esamina le versioni di Kubernetes esistenti nella matrice di installazione e determina come dovrebbero essere coperti i manifest renderizzati, gli schemi di CRDs-catalog e il rendering di TLS Issuer. Il lavoro è completo quando CI convalida tutti gli esempi rispetto a values.schema.json ed esegue controlli kubeconform rigorosi per i rendering specificati e i manifest di esempio semplici.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
PR #95 (chart-testing lint and install) and PR #96 (helm-unittest) closed the core CI gap. Two follow-ups remain:
- Validate the values files under
examples/againstvalues.schema.json - Run kubeconform against rendered manifests
Details
Today .github/workflows/lint-and-test.yaml lints and installs only charts/graylog/ci/ci-values.yaml. Nothing in CI reads examples/, and kubeconform appears nowhere in the repo.
Examples validation. helm template -f <example> enforces the values schema, so a loop over the three example values files is enough. All of them pass today, so the step starts green, and it would have flagged the pre-fix AWS example from #121 (input entries missing the schema-required name).
kubeconform. Render the defaults, the ci values, and each example, then pipe through kubeconform -strict with -kubernetes-version set from the existing install-matrix versions (v1.32.11, v1.33.7, v1.34.3). Note kubeconform wants the version without the v prefix. The chart renders two CRs, MongoDBCommunity and the cert-manager Issuer, neither in kubeconform's default catalog. Add the datreeio CRDs-catalog as a second -schema-location (it carries both schemas) using the template {{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json. The Issuer only renders when ingress.enabled and ingress.config.tls.issuer.managed.enabled are both set, which no current values file does, so add one extra render with those flags to cover it.
Both checks are static and need no cluster, so they fit the existing lint job or a small new job.
Reference: G-12 (Production Readiness Review)
Impact
Example files are the first thing users copy, and nothing stops them from drifting. That is how #121 happened. kubeconform adds Kubernetes API validation of rendered manifests, which neither helm template nor the unit tests provide.
Notes for maintainers
- The schema check is only as strong as the schema.
values.schema.jsonsets noadditionalProperties: falseanywhere, so unknown and deprecated keys pass silently. Tightening it is a separate discussion (#63 touches the same file). - Schema validation cannot see YAML duplicate keys.
examples/values-existing-secret-external-mongodb.yamldeclaresgraylog:twice (lines 43 and 77) and last-key-wins parsing silently drops the first block. Ayamllintpass overexamples/catches this class, and the duplicate itself deserves a fix. examples/graylog-secret.yamlandexamples/testing/test-gelf-input.yamlare plain manifests, so kubeconform can check them directly in the same step.- kubeconform needs network access to fetch schemas, or a pre-populated cache.
- Lingua principale
- Go Template
- Stelle
- 12
- Fork
- 4
- Merge medio
- 6g 2h
- PR unite (30g)
- 3
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Graylog2/graylog-helm
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
Graylog2/graylog-helm#186 ·
-
Invalid nodeSelectorAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
Graylog2/graylog-helm#97 ·
-
feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Graylog2/graylog-helm#61 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
Graylog2/graylog-helm#190 · 1 commento ·
-
feature improvement infrastructure
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
Graylog2/graylog-helm#172 ·
Tutte le issue di Graylog2/graylog-helm
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 7 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
Flagsmith/flagsmith-charts#603 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
lightpanda-io/browser#3708 ·
I maintainer di solito rispondono entro 1 giorno
-
area:build enhancement good first issue P2
Difficoltà 2/5 1-3 ore Idoneità per principianti 92/100
uttrflow/uttrflow-swift#3212 ·
I maintainer di solito rispondono entro 1 giorno
-
area: ci type: chore
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
eknowledger/toolbench#140 ·
I maintainer di solito rispondono entro 1 giorno