ci: the digest-guard test depended on state CI itself mutates
ci / lint (push) Successful in 1m56s
ci / unit (push) Successful in 2m2s
ci / types (push) Successful in 2m4s
ci / security (push) Successful in 1m21s
ci / dockerfile (push) Successful in 1m24s
ci / chart (push) Successful in 15s
ci / integration (push) Successful in 1m58s
ci / image (reconciler) (push) Failing after 6m1s
ci / image (api) (push) Failing after 6m7s
ci / image (worker) (push) Successful in 5m33s
ci / bump (push) Has been skipped
ci / lint (push) Successful in 1m56s
ci / unit (push) Successful in 2m2s
ci / types (push) Successful in 2m4s
ci / security (push) Successful in 1m21s
ci / dockerfile (push) Successful in 1m24s
ci / chart (push) Successful in 15s
ci / integration (push) Successful in 1m58s
ci / image (reconciler) (push) Failing after 6m1s
ci / image (api) (push) Failing after 6m7s
ci / image (worker) (push) Successful in 5m33s
ci / bump (push) Has been skipped
The chart job asserted that a bare `helm template` FAILS, on the assumption that values.yaml always holds all-zeros placeholder digests. That assumption dies the first time the bump job runs: bump commits real digests into values.yaml, so the bare render then succeeds and the assertion reports 'the guard is not guarding' about a guard that is fine. A test whose expected result flips depending on whether CI has run before is not a test. Now it feeds the guard four distinct bad digests explicitly with --set — all-zeros, a bare tag, right-prefix-wrong-length, and empty — and requires each to be rejected. Verified locally: all four rejected, and a well-formed digest still renders.
This commit is contained in:
@@ -255,18 +255,34 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
helm lint deploy/chart
|
helm lint deploy/chart
|
||||||
|
|
||||||
- name: helm template (rejects unbumped digests)
|
- name: helm template (the digest guard rejects bad digests)
|
||||||
# values.yaml ships all-zeros placeholders, so a bare `helm template` MUST fail.
|
# Feed the guard bad digests explicitly with --set. The earlier version of this
|
||||||
# That is the guard working, not a broken chart — asserting the failure here is
|
# step ran a bare `helm template` and asserted it FAILED, on the assumption that
|
||||||
# what stops the guard silently regressing into a prefix check again.
|
# values.yaml always holds all-zeros placeholders. That assumption dies the first
|
||||||
|
# time the `bump` job runs: bump commits real digests into values.yaml, so the bare
|
||||||
|
# render then succeeds and the assertion reports "the guard is not guarding" about
|
||||||
|
# a guard that is fine. A test whose expected result flips depending on whether CI
|
||||||
|
# has run before is not a test.
|
||||||
|
#
|
||||||
|
# Each case below is a distinct way to get a digest wrong, and each must be
|
||||||
|
# rejected on its own.
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
if helm template svcforge deploy/chart >/dev/null 2>&1; then
|
ZEROS="sha256:$(printf '0%.0s' $(seq 64))"
|
||||||
echo "FAIL: chart rendered against the placeholder digests in values.yaml." >&2
|
for bad_desc in \
|
||||||
|
"all-zeros placeholder|${ZEROS}" \
|
||||||
|
"not a digest at all|latest" \
|
||||||
|
"right prefix, wrong length|sha256:abc123" \
|
||||||
|
"empty|"; do
|
||||||
|
desc="${bad_desc%%|*}"; bad="${bad_desc#*|}"
|
||||||
|
if helm template svcforge deploy/chart \
|
||||||
|
--set image.api.digest="${bad}" >/dev/null 2>&1; then
|
||||||
|
echo "FAIL: the chart rendered with a ${desc} digest (${bad@Q})." >&2
|
||||||
echo "The digest guard in _helpers.tpl is not guarding." >&2
|
echo "The digest guard in _helpers.tpl is not guarding." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
echo "ok: placeholder digests rejected"
|
echo "ok: rejected ${desc}"
|
||||||
|
done
|
||||||
|
|
||||||
- name: helm template (renders with real digests)
|
- name: helm template (renders with real digests)
|
||||||
# Dummy but well-formed digests: this checks the templates themselves render, with
|
# Dummy but well-formed digests: this checks the templates themselves render, with
|
||||||
|
|||||||
Reference in New Issue
Block a user