Merge pull request #3735 from Infisical/misc/add-checks-for-helm-verification

misc: add verification pipelines for helm charts
This commit is contained in:
Maidul Islam
2025-06-12 22:29:44 -04:00
committed by GitHub
9 changed files with 340 additions and 42 deletions
@@ -3,7 +3,62 @@ name: Release Infisical Core Helm chart
on: [workflow_dispatch] on: [workflow_dispatch]
jobs: jobs:
test-helm:
name: Test Helm Chart
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Set up Helm
uses: azure/[email protected]
with:
version: v3.17.0
- uses: actions/[email protected]
with:
python-version: "3.x"
check-latest: true
- name: Add Helm repositories
run: |
helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo update
- name: Set up chart-testing
uses: helm/[email protected]
- name: Run chart-testing (lint)
run: ct lint --config ct.yaml --charts helm-charts/infisical-standalone-postgres
- name: Create kind cluster
uses: helm/[email protected]
- name: Create namespace
run: kubectl create namespace infisical-standalone-postgres
- name: Create Infisical secrets
run: |
kubectl create secret generic infisical-secrets \
--namespace infisical-standalone-postgres \
--from-literal=AUTH_SECRET=6c1fe4e407b8911c104518103505b218 \
--from-literal=ENCRYPTION_KEY=6c1fe4e407b8911c104518103505b218 \
--from-literal=SITE_URL=http://localhost:8080
- name: Run chart-testing (install)
run: |
ct install \
--config ct.yaml \
--charts helm-charts/infisical-standalone-postgres \
--helm-extra-args="--timeout=300s" \
--helm-extra-set-args="--set ingress.nginx.enabled=false --set infisical.autoDatabaseSchemaMigration=false --set infisical.replicaCount=1 --set infisical.image.tag=v0.132.2-postgres" \
--namespace infisical-standalone-postgres
release: release:
needs: test-helm
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
@@ -19,4 +74,4 @@ jobs:
- name: Build and push helm package to Cloudsmith - name: Build and push helm package to Cloudsmith
run: cd helm-charts && sh upload-infisical-core-helm-cloudsmith.sh run: cd helm-charts && sh upload-infisical-core-helm-cloudsmith.sh
env: env:
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }} CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }}
+51 -19
View File
@@ -1,27 +1,59 @@
name: Release K8 Operator Helm Chart name: Release K8 Operator Helm Chart
on: on:
workflow_dispatch: workflow_dispatch:
jobs: jobs:
release-helm: test-helm:
name: Release Helm Chart name: Test Helm Chart
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v2 uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Install Helm - name: Set up Helm
uses: azure/setup-helm@v3 uses: azure/setup-helm@v4.2.0
with: with:
version: v3.10.0 version: v3.17.0
- name: Install python - uses: actions/[email protected]
uses: actions/setup-python@v4 with:
python-version: "3.x"
check-latest: true
- name: Install Cloudsmith CLI - name: Set up chart-testing
run: pip install --upgrade cloudsmith-cli uses: helm/[email protected]
- name: Build and push helm package to CloudSmith - name: Run chart-testing (lint)
run: cd helm-charts && sh upload-k8s-operator-cloudsmith.sh run: ct lint --config ct.yaml --charts helm-charts/secrets-operator
env:
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }} - name: Create kind cluster
uses: helm/[email protected]
- name: Run chart-testing (install)
run: ct install --config ct.yaml --charts helm-charts/secrets-operator
release-helm:
name: Release Helm Chart
needs: test-helm
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v2
- name: Install Helm
uses: azure/setup-helm@v3
with:
version: v3.10.0
- name: Install python
uses: actions/setup-python@v4
- name: Install Cloudsmith CLI
run: pip install --upgrade cloudsmith-cli
- name: Build and push helm package to CloudSmith
run: cd helm-charts && sh upload-k8s-operator-cloudsmith.sh
env:
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }}
+62 -19
View File
@@ -1,27 +1,70 @@
name: Release Gateway Helm Chart name: Release Gateway Helm Chart
on: on:
workflow_dispatch: workflow_dispatch:
jobs: jobs:
release-helm: test-helm:
name: Release Helm Chart name: Test Helm Chart
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Install Helm - name: Set up Helm
uses: azure/setup-helm@v3 uses: azure/setup-helm@v4.2.0
with: with:
version: v3.10.0 version: v3.17.0
- name: Install python - uses: actions/[email protected]
uses: actions/setup-python@v4 with:
python-version: "3.x"
check-latest: true
- name: Install Cloudsmith CLI - name: Set up chart-testing
run: pip install --upgrade cloudsmith-cli uses: helm/[email protected]
- name: Build and push helm package to CloudSmith - name: Run chart-testing (lint)
run: cd helm-charts && sh upload-gateway-cloudsmith.sh run: ct lint --config ct.yaml --charts helm-charts/infisical-gateway
env:
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }} - name: Create kind cluster
uses: helm/[email protected]
- name: Create namespace
run: kubectl create namespace infisical-gateway
- name: Create gateway secret
run: kubectl create secret generic infisical-gateway-environment --from-literal=TOKEN=my-test-token -n infisical-gateway
- name: Run chart-testing (install)
run: |
ct install \
--config ct.yaml \
--charts helm-charts/infisical-gateway \
--helm-extra-args="--timeout=300s" \
--namespace infisical-gateway
release-helm:
name: Release Helm Chart
needs: test-helm
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install Helm
uses: azure/setup-helm@v3
with:
version: v3.10.0
- name: Install python
uses: actions/setup-python@v4
- name: Install Cloudsmith CLI
run: pip install --upgrade cloudsmith-cli
- name: Build and push helm package to CloudSmith
run: cd helm-charts && sh upload-gateway-cloudsmith.sh
env:
CLOUDSMITH_API_KEY: ${{ secrets.CLOUDSMITH_API_KEY }}
@@ -0,0 +1,49 @@
name: Run Helm Chart Tests for Gateway
on:
pull_request:
paths:
- "helm-charts/infisical-gateway/**"
- ".github/workflows/run-helm-chart-tests-infisical-gateway.yml"
jobs:
test-helm:
name: Test Helm Chart
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Set up Helm
uses: azure/[email protected]
with:
version: v3.17.0
- uses: actions/[email protected]
with:
python-version: "3.x"
check-latest: true
- name: Set up chart-testing
uses: helm/[email protected]
- name: Run chart-testing (lint)
run: ct lint --config ct.yaml --charts helm-charts/infisical-gateway
- name: Create kind cluster
uses: helm/[email protected]
- name: Create namespace
run: kubectl create namespace infisical-gateway
- name: Create gateway secret
run: kubectl create secret generic infisical-gateway-environment --from-literal=TOKEN=my-test-token -n infisical-gateway
- name: Run chart-testing (install)
run: |
ct install \
--config ct.yaml \
--charts helm-charts/infisical-gateway \
--helm-extra-args="--timeout=300s" \
--namespace infisical-gateway
@@ -0,0 +1,61 @@
name: Run Helm Chart Tests for Infisical Standalone Postgres
on:
pull_request:
paths:
- "helm-charts/infisical-standalone-postgres/**"
- ".github/workflows/run-helm-chart-tests-infisical-standalone-postgres.yml"
jobs:
test-helm:
name: Test Helm Chart
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Set up Helm
uses: azure/[email protected]
with:
version: v3.17.0
- uses: actions/[email protected]
with:
python-version: "3.x"
check-latest: true
- name: Add Helm repositories
run: |
helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo update
- name: Set up chart-testing
uses: helm/[email protected]
- name: Run chart-testing (lint)
run: ct lint --config ct.yaml --charts helm-charts/infisical-standalone-postgres
- name: Create kind cluster
uses: helm/[email protected]
- name: Create namespace
run: kubectl create namespace infisical-standalone-postgres
- name: Create Infisical secrets
run: |
kubectl create secret generic infisical-secrets \
--namespace infisical-standalone-postgres \
--from-literal=AUTH_SECRET=6c1fe4e407b8911c104518103505b218 \
--from-literal=ENCRYPTION_KEY=6c1fe4e407b8911c104518103505b218 \
--from-literal=SITE_URL=http://localhost:8080
- name: Run chart-testing (install)
run: |
ct install \
--config ct.yaml \
--charts helm-charts/infisical-standalone-postgres \
--helm-extra-args="--timeout=300s" \
--helm-extra-set-args="--set ingress.nginx.enabled=false --set infisical.autoDatabaseSchemaMigration=false --set infisical.replicaCount=1 --set infisical.image.tag=v0.132.2-postgres" \
--namespace infisical-standalone-postgres
@@ -0,0 +1,38 @@
name: Run Helm Chart Tests for Secret Operator
on:
pull_request:
paths:
- "helm-charts/secrets-operator/**"
- ".github/workflows/run-helm-chart-tests-secret-operator.yml"
jobs:
test-helm:
name: Test Helm Chart
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
with:
fetch-depth: 0
- name: Set up Helm
uses: azure/[email protected]
with:
version: v3.17.0
- uses: actions/[email protected]
with:
python-version: "3.x"
check-latest: true
- name: Set up chart-testing
uses: helm/[email protected]
- name: Run chart-testing (lint)
run: ct lint --config ct.yaml --charts helm-charts/secrets-operator
- name: Create kind cluster
uses: helm/[email protected]
- name: Run chart-testing (install)
run: ct install --config ct.yaml --charts helm-charts/secrets-operator
+4
View File
@@ -40,4 +40,8 @@ cli/detect/config/gitleaks.toml:gcp-api-key:578
cli/detect/config/gitleaks.toml:gcp-api-key:579 cli/detect/config/gitleaks.toml:gcp-api-key:579
cli/detect/config/gitleaks.toml:gcp-api-key:581 cli/detect/config/gitleaks.toml:gcp-api-key:581
cli/detect/config/gitleaks.toml:gcp-api-key:582 cli/detect/config/gitleaks.toml:gcp-api-key:582
.github/workflows/run-helm-chart-tests-infisical-standalone-postgres.yml:generic-api-key:51
.github/workflows/run-helm-chart-tests-infisical-standalone-postgres.yml:generic-api-key:50
.github/workflows/helm-release-infisical-core.yml:generic-api-key:48
.github/workflows/helm-release-infisical-core.yml:generic-api-key:47
backend/src/services/smtp/smtp-service.ts:generic-api-key:79 backend/src/services/smtp/smtp-service.ts:generic-api-key:79
+14
View File
@@ -0,0 +1,14 @@
# Chart testing configuration
chart-dirs:
- helm-charts
# Test against these Kubernetes versions
kube-versions:
- v1.30.0
- v1.31.0
- v1.32.0
- v1.33.0
validate-maintainers: false
kubectl-timeout: 300s
@@ -5,8 +5,10 @@ nameOverride: ""
fullnameOverride: "" fullnameOverride: ""
infisical: infisical:
enabled: true # -- Enable Infisical chart deployment # -- Enable Infisical chart deployment
name: infisical # -- Sets the name of the deployment within this chart enabled: true
# -- Sets the name of the deployment within this chart
name: infisical
# -- Automatically migrates new database schema when deploying # -- Automatically migrates new database schema when deploying
autoDatabaseSchemaMigration: true autoDatabaseSchemaMigration: true
@@ -67,7 +69,7 @@ infisical:
resources: resources:
limits: limits:
# -- Memory limit for Infisical container # -- Memory limit for Infisical container
memory: 600Mi memory: 1000Mi
requests: requests:
# -- CPU request for Infisical container # -- CPU request for Infisical container
cpu: 350m cpu: 350m