Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 0 additions & 9 deletions .dev/ko-build-faucet.sh

This file was deleted.

4 changes: 2 additions & 2 deletions .dev/scripts/check.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
set -euo pipefail

echo "== go format =="
go_roots=(charts cli cmd containers/cardano-testnet containers/cardano-tools services test)
for optional_dir in api internal; do
go_roots=(charts cli cmd containers/cardano-testnet containers/cardano-tools test)
for optional_dir in api internal services; do
if [ -d "$optional_dir" ]; then
go_roots+=("$optional_dir")
fi
Expand Down
19 changes: 0 additions & 19 deletions .dev/scripts/deploy.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@ set -euo pipefail
release="${HELM_RELEASE:-yacd}"
namespace="${HELM_NAMESPACE:-yacd-system}"
image="${IMG:-}"
faucet_image="${FAUCET_IMG:-}"

shopt -s nullglob
crds=(charts/yacd/crds/*.yaml)
Expand Down Expand Up @@ -40,24 +39,6 @@ if [ -n "$image" ]; then
fi
fi

if [ -n "$faucet_image" ]; then
if [[ "$faucet_image" == *@* ]]; then
args+=(--set-string "faucet.image.repository=${faucet_image%@*}")
args+=(--set-string "faucet.image.digest=${faucet_image#*@}")
args+=(--set-string "faucet.image.tag=")
else
last_segment="${faucet_image##*/}"
if [[ "$last_segment" == *:* ]]; then
args+=(--set-string "faucet.image.repository=${faucet_image%:*}")
args+=(--set-string "faucet.image.tag=${faucet_image##*:}")
else
args+=(--set-string "faucet.image.repository=$faucet_image")
args+=(--set-string "faucet.image.tag=")
fi
args+=(--set-string "faucet.image.digest=")
fi
fi

if [ "${LOCAL_IMAGE:-false}" = "true" ]; then
args+=(--set "image.pullPolicy=IfNotPresent")
fi
Expand Down
13 changes: 5 additions & 8 deletions .dev/scripts/test-e2e.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,6 @@ command -v "$kind_bin" >/dev/null

cluster="${KIND_CLUSTER:-yacd-test-e2e}"
manager_image="${IMG:-example.com/yacd:v0.0.1}"
faucet_image="${FAUCET_IMG:-example.com/yacd-faucet:v0.0.1}"
kubeconfig_dir="$(mktemp -d)"
kubeconfig="$kubeconfig_dir/kubeconfig"
created=0
Expand All @@ -31,14 +30,12 @@ fi
"$kind_bin" export kubeconfig --name "$cluster" --kubeconfig "$kubeconfig"
export KUBECONFIG="$kubeconfig"

# The manager and faucet images are the code under test, so they are built from
# source and loaded into Kind. The cardano-testnet and cardano-tools images are
# published, digest-pinned manager defaults, so Kind pulls them at pod-creation
# time rather than building them here.
# The manager image is the code under test, so it is built from source and
# loaded into Kind. The cardano-testnet and cardano-tools images are published,
# digest-pinned manager defaults, so Kind pulls them at pod-creation time rather
# than building them here.
docker build -t "$manager_image" .
docker build -f services/faucet/Dockerfile -t "$faucet_image" .
"$kind_bin" load docker-image "$manager_image" --name "$cluster"
"$kind_bin" load docker-image "$faucet_image" --name "$cluster"

KIND="$kind_bin" KIND_CLUSTER="$cluster" IMG="$manager_image" FAUCET_IMG="$faucet_image" KUBECTL_KUBERC="${KUBECTL_KUBERC:-false}" \
KIND="$kind_bin" KIND_CLUSTER="$cluster" IMG="$manager_image" KUBECTL_KUBERC="${KUBECTL_KUBERC:-false}" \
chainsaw test --config test/chainsaw/chainsaw-config.yaml test/chainsaw
226 changes: 0 additions & 226 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,6 @@ permissions: {}

env:
IMAGE_NAME: ghcr.io/meigma/yacd
FAUCET_IMAGE_NAME: ghcr.io/meigma/yacd/faucet
CHART_NAME: ghcr.io/meigma/yacd/chart
CHART_REF: oci://ghcr.io/meigma/yacd/chart
CHART_REPOSITORY: oci://ghcr.io/meigma/yacd
Expand Down Expand Up @@ -405,224 +404,12 @@ jobs:
subject-digest: ${{ steps.manifest.outputs.digest }}
push-to-registry: true

faucet-container-image-build:
name: Faucet Container Image Build (${{ matrix.platform }})
runs-on: ${{ matrix.runner }}
needs:
- resolve-release
- binary-release-assets
permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
strategy:
fail-fast: false
matrix:
include:
- platform: linux/amd64
runner: ubuntu-24.04
arch: amd64
- platform: linux/arm64
runner: ubuntu-24.04-arm
arch: arm64
steps:
- name: Check out repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
fetch-depth: 0

- name: Check out requested tag
if: ${{ github.event_name == 'workflow_dispatch' }}
env:
RELEASE_TAG: ${{ needs.resolve-release.outputs.tag }}
run: git checkout --detach "$RELEASE_TAG"

- name: Resolve image metadata
id: image
env:
RELEASE_TAG: ${{ needs.resolve-release.outputs.tag }}
RELEASE_VERSION: ${{ needs.resolve-release.outputs.version }}
run: |
set -euo pipefail

echo "name=${FAUCET_IMAGE_NAME}" >> "$GITHUB_OUTPUT"
echo "commit=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT"
echo "date=$(git show -s --format=%cI HEAD)" >> "$GITHUB_OUTPUT"
echo "tag=${FAUCET_IMAGE_NAME}:${RELEASE_TAG}" >> "$GITHUB_OUTPUT"
echo "version=${RELEASE_VERSION}" >> "$GITHUB_OUTPUT"

- name: Log in to GitHub Container Registry
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ github.token }}

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4

- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@030e881283bb7a6894de51c315a6bfe6a94e05cf # v6
with:
images: ${{ steps.image.outputs.name }}
tags: |
type=raw,value=${{ needs.resolve-release.outputs.tag }}
labels: |
org.opencontainers.image.title=yacd-faucet
org.opencontainers.image.description=YACD local development faucet service
org.opencontainers.image.source=https://github.com/${{ github.repository }}
org.opencontainers.image.version=${{ needs.resolve-release.outputs.version }}
org.opencontainers.image.revision=${{ steps.image.outputs.commit }}

- name: Build and push faucet container image
id: build
uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7
with:
context: .
file: services/faucet/Dockerfile
platforms: ${{ matrix.platform }}
outputs: type=image,name=${{ steps.image.outputs.name }},push-by-digest=true,name-canonical=true,push=true
labels: ${{ steps.meta.outputs.labels }}
provenance: mode=max
sbom: true
cache-from: type=gha,scope=yacd-faucet-release-${{ matrix.arch }}
cache-to: type=gha,mode=max,scope=yacd-faucet-release-${{ matrix.arch }}
build-args: |
VERSION=${{ steps.image.outputs.version }}
COMMIT=${{ steps.image.outputs.commit }}
DATE=${{ steps.image.outputs.date }}

- name: Smoke test faucet platform image
env:
IMAGE_REF: ${{ steps.image.outputs.name }}@${{ steps.build.outputs.digest }}
run: docker run --rm --platform "${{ matrix.platform }}" "$IMAGE_REF" --version >/tmp/yacd-faucet-version.txt

- name: Export faucet platform digest
env:
DIGEST: ${{ steps.build.outputs.digest }}
run: |
set -euo pipefail

if [[ ! "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]]; then
echo "unexpected faucet image digest: $DIGEST" >&2
exit 1
fi

mkdir -p /tmp/faucet-container-digests
touch "/tmp/faucet-container-digests/${DIGEST#sha256:}"

- name: Upload faucet platform digest
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: faucet-container-digest-${{ matrix.arch }}
path: /tmp/faucet-container-digests/*
if-no-files-found: error
retention-days: 1

faucet-container-image-release:
name: Faucet Container Image Release
runs-on: ubuntu-24.04
needs:
- resolve-release
- binary-release-assets
- faucet-container-image-build
permissions:
contents: read
packages: write
id-token: write
attestations: write
artifact-metadata: write
outputs:
image-name: ${{ steps.manifest.outputs.name }}
image-digest: ${{ steps.manifest.outputs.digest }}
steps:
- name: Resolve faucet image metadata
id: image
env:
RELEASE_TAG: ${{ needs.resolve-release.outputs.tag }}
run: |
set -euo pipefail

echo "name=${FAUCET_IMAGE_NAME}" >> "$GITHUB_OUTPUT"
echo "tag=${FAUCET_IMAGE_NAME}:${RELEASE_TAG}" >> "$GITHUB_OUTPUT"

- name: Log in to GitHub Container Registry
uses: docker/login-action@4907a6ddec9925e35a0a9e82d7399ccc52663121 # v4
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ github.token }}

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4

- name: Download faucet platform digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: faucet-container-digest-*
path: /tmp/faucet-container-digests
merge-multiple: true

- name: Create faucet multi-platform manifest
id: manifest
env:
IMAGE_NAME: ${{ steps.image.outputs.name }}
IMAGE_TAG: ${{ steps.image.outputs.tag }}
run: |
set -euo pipefail

mapfile -t digest_files < <(find /tmp/faucet-container-digests -maxdepth 1 -type f -print | sort)
if [ "${#digest_files[@]}" -ne 2 ]; then
echo "expected 2 faucet platform digest files, found ${#digest_files[@]}" >&2
printf '%s\n' "${digest_files[@]}" >&2
exit 1
fi

refs=()
for digest_file in "${digest_files[@]}"; do
digest="$(basename "$digest_file")"
if [[ ! "$digest" =~ ^[0-9a-f]{64}$ ]]; then
echo "unexpected faucet digest artifact name: $digest" >&2
exit 1
fi
refs+=("${IMAGE_NAME}@sha256:${digest}")
done

docker buildx imagetools create --tag "$IMAGE_TAG" "${refs[@]}"

manifest_json="$(docker buildx imagetools inspect "$IMAGE_TAG" --format '{{json .}}')"
manifest_digest="$(jq -r '.manifest.digest' <<< "$manifest_json")"

if [[ ! "$manifest_digest" =~ ^sha256:[0-9a-f]{64}$ ]]; then
echo "unexpected faucet manifest digest: $manifest_digest" >&2
exit 1
fi

echo "name=${IMAGE_NAME}" >> "$GITHUB_OUTPUT"
echo "tag=${IMAGE_TAG}" >> "$GITHUB_OUTPUT"
echo "digest=${manifest_digest}" >> "$GITHUB_OUTPUT"

- name: Smoke test faucet release image
run: docker run --rm "${{ steps.manifest.outputs.tag }}" --version >/tmp/yacd-faucet-version.txt

- name: Attest faucet container image
uses: actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26 # v4.1.0
with:
subject-name: ${{ steps.manifest.outputs.name }}
subject-digest: ${{ steps.manifest.outputs.digest }}
push-to-registry: true

helm-chart-release:
name: Helm Chart Release
runs-on: ubuntu-24.04
needs:
- resolve-release
- container-image-release
- faucet-container-image-release
permissions:
contents: read
packages: write
Expand Down Expand Up @@ -688,7 +475,6 @@ jobs:
grep -Fq "app.kubernetes.io/name: yacd" /tmp/yacd-chart.yaml
grep -Fq "helm.sh/chart: chart-${RELEASE_VERSION}" /tmp/yacd-chart.yaml
grep -Fq "image: \"${IMAGE_NAME}:v${RELEASE_VERSION}\"" /tmp/yacd-chart.yaml
grep -Fq -- "--default-faucet-image=${FAUCET_IMAGE_NAME}:v${RELEASE_VERSION}" /tmp/yacd-chart.yaml
helm install yacd "$archive" --namespace yacd-system --dry-run=client --server-side=false >/dev/null

echo "archive=$archive" >> "$GITHUB_OUTPUT"
Expand Down Expand Up @@ -752,7 +538,6 @@ jobs:
- resolve-release
- binary-release-assets
- container-image-release
- faucet-container-image-release
- helm-chart-release
permissions: {}
steps:
Expand All @@ -762,8 +547,6 @@ jobs:
RELEASE_VERSION: ${{ needs.resolve-release.outputs.version }}
IMAGE_NAME: ${{ needs.container-image-release.outputs.image-name }}
IMAGE_DIGEST: ${{ needs.container-image-release.outputs.image-digest }}
FAUCET_IMAGE_NAME: ${{ needs.faucet-container-image-release.outputs.image-name }}
FAUCET_IMAGE_DIGEST: ${{ needs.faucet-container-image-release.outputs.image-digest }}
CHART_DIGEST: ${{ needs.helm-chart-release.outputs.chart-digest }}
run: |
{
Expand All @@ -788,15 +571,6 @@ jobs:
echo "gh attestation verify \"oci://${IMAGE_NAME}@${IMAGE_DIGEST}\" --repo \"$GITHUB_REPOSITORY\" --signer-workflow \"$GITHUB_REPOSITORY/.github/workflows/release.yml\" --source-ref \"refs/tags/$RELEASE_TAG\" --deny-self-hosted-runners"
echo '```'
echo
echo "Faucet container verification commands:"
echo
echo '```sh'
echo "docker login ghcr.io"
echo "docker pull \"${FAUCET_IMAGE_NAME}:${RELEASE_TAG}\""
echo "docker run --rm \"${FAUCET_IMAGE_NAME}:${RELEASE_TAG}\" --version"
echo "gh attestation verify \"oci://${FAUCET_IMAGE_NAME}@${FAUCET_IMAGE_DIGEST}\" --repo \"$GITHUB_REPOSITORY\" --signer-workflow \"$GITHUB_REPOSITORY/.github/workflows/release.yml\" --source-ref \"refs/tags/$RELEASE_TAG\" --deny-self-hosted-runners"
echo '```'
echo
echo "Helm chart verification commands:"
echo
echo '```sh'
Expand Down
11 changes: 1 addition & 10 deletions Tiltfile
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
EXPECTED_CONTEXT = 'kind-yacd-dev'
NAMESPACE = 'yacd-system'
IMAGE = 'ghcr.io/meigma/yacd'
FAUCET_IMAGE = 'ghcr.io/meigma/yacd/faucet'
CARDANO_TESTNET_IMAGE = 'ghcr.io/meigma/yacd/cardano-testnet'
CARDANO_TOOLS_IMAGE = 'ghcr.io/meigma/yacd/cardano-tools'
CHART = 'charts/yacd'
Expand All @@ -27,12 +26,6 @@ custom_build(
deps=['cmd', 'api', 'internal', 'go.mod', 'go.sum', '.ko.yaml', '.dev/ko-build.sh'],
)

local_resource(
name='faucet-image',
cmd='EXPECTED_REF=%s:tilt ./.dev/ko-build-faucet.sh && kind load docker-image --name yacd-dev %s:tilt' % (FAUCET_IMAGE, FAUCET_IMAGE),
deps=['services/faucet', 'go.mod', 'go.sum', '.ko.yaml', '.dev/ko-build-faucet.sh'],
)

# Build the cardano-testnet tools image from local source so the operator
# uses a publisher that includes post-release changes db-sync depends on
# (notably the genesis hash enrichment added in PR #31). The published
Expand Down Expand Up @@ -62,8 +55,6 @@ k8s_yaml(helm(
'image.repository=%s' % IMAGE,
'image.tag=tilt',
'image.pullPolicy=IfNotPresent',
'faucet.image.repository=%s' % FAUCET_IMAGE,
'faucet.image.tag=tilt',
'cardanoTestnet.image.repository=%s' % CARDANO_TESTNET_IMAGE,
'cardanoTestnet.image.tag=tilt',
'cardanoTools.image.repository=%s' % CARDANO_TOOLS_IMAGE,
Expand All @@ -76,5 +67,5 @@ k8s_yaml(helm(
k8s_resource(
workload='yacd-controller-manager',
new_name='controller',
resource_deps=['faucet-image', 'cardano-testnet-image', 'cardano-tools-image'],
resource_deps=['cardano-testnet-image', 'cardano-tools-image'],
)
Loading