Skip to content

ci: share the GCP deploy manifest validation with the PR gate - #2486

Merged
Brad-Edwards merged 2 commits into
devfrom
ci/gcp-manifest-validation-parity
Oct 5, 2026
Merged

Brad-Edwards merged 2 commits into
devfrom
ci/gcp-manifest-validation-parity

Conversation

@Brad-Edwards

Copy link
Copy Markdown
Owner

Merge after #2484. This branch is stacked on it: until #2484 removes the base BackendConfig, dev's GCP overlays fail this (correctly stricter) PR check. Once #2484 merges, this PR's diff is just the CI change.

Problem

The two GCP manifest gates were separate, divergent definitions:

PR tier: Lint (k8s schemas) Deploy tier: GCP Dev / Validate
Runs on PRs yes no (github.event_name != 'pull_request')
kubeconform v0.6.7, -ignore-missing-schemas v0.7.0, -strict only
Renders each kustomize root tenant overlay + committed edge manifest

-ignore-missing-schemas silently passes any schema-less kind, so the GKE BackendConfig added to the kustomize base in #2475 passed review and then failed every GCP tenant deploy at Validate.

Fix

One local composite action, .github/actions/validate-gcp-manifests, owns the deploy gate's exact validation: pinned kubectl (v1.34.1) and checksum-verified kubeconform (v0.7.0), the overlay + committed edge manifest render, and -strict.

  • _gcp-dev.yml Validate calls it for its tenant (replaces the inline steps; behavior unchanged).
  • _quality.yml Lint (k8s schemas) calls it with environments: all for every GCP tenant, in addition to its existing roots check.
  • .github/actions/** is registered in force_full_matrix (CI control plane), so changing the action reruns everything.

Verification

  • Ran the action's validation logic locally against the tree: all five GCP tenants pass (54/54).
  • Negative: re-adding a BackendConfig to the base fails with the same could not find schema for BackendConfig error the deploy gate produced; an unknown or traversal overlay name is rejected.
  • actionlint (pre-commit v1.7.12) and adr_guard --all --level ci pass (including workflow-action-sha-pinning, deploy-workflow-runner-exposure, quality-path-ownership).

The GCP deploy Validate job never runs on pull requests, and the PR-tier
Lint (k8s schemas) job validates with -ignore-missing-schemas, so it silently
passes schema-less kinds. A GKE CRD in the kustomize base (#2475) therefore
passed review and then failed every GCP tenant deploy at Validate.

Move the deploy gate's exact validation (pinned kubectl and kubeconform, the
overlay plus committed edge manifest render, -strict) into one local composite
action. The deploy Validate job calls it for its tenant and the PR gate calls it
for every GCP tenant, so a PR is rejected for exactly what a deploy rejects.
@Brad-Edwards
Brad-Edwards merged commit 384b931 into dev Oct 5, 2026
5 checks passed
@Brad-Edwards
Brad-Edwards deleted the ci/gcp-manifest-validation-parity branch October 5, 2026 05:47
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant