Repository navigation
ci: share the GCP deploy manifest validation with the PR gate - #2486
Merged
Merged
Conversation
The GCP deploy Validate job never runs on pull requests, and the PR-tier Lint (k8s schemas) job validates with -ignore-missing-schemas, so it silently passes schema-less kinds. A GKE CRD in the kustomize base (#2475) therefore passed review and then failed every GCP tenant deploy at Validate. Move the deploy gate's exact validation (pinned kubectl and kubeconform, the overlay plus committed edge manifest render, -strict) into one local composite action. The deploy Validate job calls it for its tenant and the PR gate calls it for every GCP tenant, so a PR is rejected for exactly what a deploy rejects.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Problem
The two GCP manifest gates were separate, divergent definitions:
Lint (k8s schemas)GCP Dev / Validategithub.event_name != 'pull_request')-ignore-missing-schemas-strictonly-ignore-missing-schemassilently passes any schema-less kind, so the GKEBackendConfigadded to the kustomize base in #2475 passed review and then failed every GCP tenant deploy at Validate.Fix
One local composite action,
.github/actions/validate-gcp-manifests, owns the deploy gate's exact validation: pinnedkubectl(v1.34.1) and checksum-verifiedkubeconform(v0.7.0), the overlay + committed edge manifest render, and-strict._gcp-dev.ymlValidate calls it for its tenant (replaces the inline steps; behavior unchanged)._quality.ymlLint (k8s schemas)calls it withenvironments: allfor every GCP tenant, in addition to its existing roots check..github/actions/**is registered inforce_full_matrix(CI control plane), so changing the action reruns everything.Verification
BackendConfigto the base fails with the samecould not find schema for BackendConfigerror the deploy gate produced; an unknown or traversal overlay name is rejected.adr_guard --all --level cipass (including workflow-action-sha-pinning, deploy-workflow-runner-exposure, quality-path-ownership).