-
Notifications
You must be signed in to change notification settings - Fork 0
377 lines (336 loc) · 16.3 KB
/
Copy pathpr-diff.yml
File metadata and controls
377 lines (336 loc) · 16.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
name: PR Helm Diff
on:
pull_request:
types: [opened, synchronize, reopened]
paths:
- '03_apps/apps/**'
- '02_bootstrap/**'
# Callable from other repositories that follow the same app-directory
# convention (app.yaml / <prefix>-app.yaml plus values files per app dir).
workflow_call:
inputs:
app-roots:
description: >-
Space-separated directories whose immediate subdirectories are apps,
relative to the repository root.
type: string
default: '03_apps/apps 02_bootstrap'
environment:
description: Environment to render, i.e. which values-<env>.yaml is used.
type: string
default: prod
scripts-ref:
description: >-
When set, scripts/install.sh is taken from lunarys/gitops at this ref
for both sides of the diff, instead of from the calling repository.
type: string
default: ''
wrapper-chart:
description: >-
Helm chart that renders the Argo Applications, used to reconcile the diff's
view of the repo against what is actually deployed. Empty disables the check.
type: string
default: '03_apps'
permissions:
contents: read
pull-requests: write
packages: read
jobs:
helm-diff:
runs-on: ubuntu-latest
steps:
- name: Checkout PR branch
uses: actions/checkout@v7
with:
path: pr
fetch-depth: 0
- name: Checkout base branch
uses: actions/checkout@v7
with:
ref: ${{ github.base_ref }}
path: base
- name: Checkout install script
if: inputs.scripts-ref != ''
uses: actions/checkout@v7
with:
repository: lunarys/gitops
ref: ${{ inputs.scripts-ref }}
path: tools
- name: Install helm
uses: azure/setup-helm@v5
- name: Install yq
run: |
wget -qO /usr/local/bin/yq https://github.com/mikefarah/yq/releases/latest/download/yq_linux_amd64 \
&& chmod +x /usr/local/bin/yq || true
- name: Login to GHCR
run: echo "${{ secrets.GITHUB_TOKEN }}" | helm registry login ghcr.io -u ${{ github.actor }} --password-stdin
# The diff below discovers apps from filename conventions, which restate what the
# Argo Applications already declare. This reconciles the two, so that a unit the
# workflow cannot see fails the build rather than silently going undiffed.
- name: Check Argo coverage
env:
WRAPPER_CHART: ${{ inputs.wrapper-chart == '' && '' || (inputs.wrapper-chart || '03_apps') }}
APP_ROOTS: ${{ inputs.app-roots || '03_apps/apps 02_bootstrap' }}
ENVIRONMENT: ${{ inputs.environment || 'prod' }}
SCRIPTS_REF: ${{ inputs.scripts-ref }}
run: |
if [ -z "$WRAPPER_CHART" ] || [ ! -d "pr/$WRAPPER_CHART" ]; then
echo "No wrapper chart at 'pr/$WRAPPER_CHART' -- nothing to reconcile."
exit 0
fi
if [ -n "$SCRIPTS_REF" ]; then
install_script="$(realpath tools/scripts/install.sh)"
checker=tools/scripts/check-argo-coverage.py
else
install_script=scripts/install.sh
checker=pr/scripts/check-argo-coverage.py
fi
python3 "$checker" \
--repo pr \
--wrapper-chart "$WRAPPER_CHART" \
--env "$ENVIRONMENT" \
--app-roots "$APP_ROOTS" \
--install-script "$install_script"
- name: Detect changed apps
id: changed-apps
env:
APP_ROOTS: ${{ inputs.app-roots || '03_apps/apps 02_bootstrap' }}
run: |
base_sha=$(git -C base rev-parse HEAD)
# Path filter for the diff: any file below one of the app roots.
roots_re=$(printf '%s\n' $APP_ROOTS | sed 's|/*$|/|' | paste -sd'|' -)
# For each changed file, map it to a (dir, prefix) pair.
# A file belongs to a prefix if its name starts with "<prefix>-", where the prefix
# is identified by a <prefix>-app.yaml file on either side of the diff.
# Files that don't match any prefix belong to the unprefixed app (empty prefix).
#
# A third kind of unit exists: an overlay, i.e. a subdirectory declaring a second
# release of the same chart with its values layered on top of the parent's (see
# AGENTS.md). Units are emitted as dir|prefix|overlay, with at most one of the
# latter two set. '|' rather than a space, because 'read' collapses runs of
# whitespace and would shift an overlay into the prefix field.
apps=""
while IFS= read -r changed_file; do
[ -z "$changed_file" ] && continue
# An app dir is exactly one level below a root, so loose files
# directly inside a root (e.g. 02_bootstrap/bootstrap.sh) are skipped.
dir=""
rel=""
for root in $APP_ROOTS; do
root="${root%/}"
case "$changed_file" in
"$root"/*)
rest="${changed_file#"$root"/}"
case "$rest" in
*/*)
dir="$root/${rest%%/*}"
rel="${rest#*/}" # path within the app dir
;;
esac
break
;;
esac
done
[ -z "$dir" ] && continue
# A change inside a declared overlay affects that overlay alone: the parent
# release does not read the overlay's files. Globbed with a literal dot,
# since the marker is hidden and '*' would not match it.
overlay=""
case "$rel" in
*/*)
candidate="${rel%%/*}"
if [ -f "pr/$dir/$candidate/.overlay.yaml" ] || [ -f "base/$dir/$candidate/.overlay.yaml" ]; then
overlay="$candidate"
fi
;;
esac
if [ -n "$overlay" ]; then
apps+="$dir||$overlay"$'\n'
continue
fi
filename=$(basename "$changed_file")
# Find the longest matching prefix from *-app.yaml files on both sides
matched_prefix=""
for app_file in pr/$dir/*-app.yaml base/$dir/*-app.yaml; do
[ -f "$app_file" ] || continue
candidate=$(basename "$app_file" -app.yaml)
if [[ "$filename" == "${candidate}-"* ]] && [ ${#candidate} -gt ${#matched_prefix} ]; then
matched_prefix="$candidate"
fi
done
apps+="$dir|$matched_prefix|"$'\n'
# A change to the app's own values also changes every overlay of it, because
# overlays layer on top of these values. Prefixed files are exempt: an overlay
# layers on the unprefixed base only, so <prefix>-values.yaml cannot affect it.
if [ -z "$matched_prefix" ]; then
for marker in pr/$dir/*/.overlay.yaml base/$dir/*/.overlay.yaml; do
[ -f "$marker" ] || continue
o=$(basename "$(dirname "$marker")")
apps+="$dir||$o"$'\n'
done
fi
done < <(git -C pr diff --name-only "${base_sha}...HEAD" \
| grep -E "^($roots_re)" || true)
# Deduplicate while preserving insertion order
apps="$(echo "$apps" | awk 'NF && !seen[$0]++')"
echo "apps<<EOF" >> "$GITHUB_OUTPUT"
echo "$apps" >> "$GITHUB_OUTPUT"
echo "EOF" >> "$GITHUB_OUTPUT"
echo "Changed apps (dir|prefix|overlay):"
echo "$apps"
- name: Generate diffs
id: diffs
env:
CHANGED_APPS: ${{ steps.changed-apps.outputs.apps }}
ENVIRONMENT: ${{ inputs.environment || 'prod' }}
SCRIPTS_REF: ${{ inputs.scripts-ref }}
run: |
# One comment file per affected app under /tmp/comments/<slug>.md.
# The post step upserts one PR comment per file and deletes stale ones.
rm -rf /tmp/comments && mkdir -p /tmp/comments
has_diff=false
# With an external script both sides render through the same install.sh,
# so the diff shows app changes only; in-repo, each side uses its own.
if [ -n "$SCRIPTS_REF" ]; then
new_script=tools/scripts/install.sh
old_script=tools/scripts/install.sh
else
new_script=pr/scripts/install.sh
old_script=base/scripts/install.sh
fi
# Per-app diff caps. GitHub rejects a comment body over 65536 chars, so
# each app's diff is bounded to stay well under that on its own.
MAX_DIFF_LINES=1000
MAX_DIFF_CHARS=60000
while IFS='|' read -r app_dir prefix overlay; do
[ -z "$app_dir" ] && continue
prefix_flag="${prefix:+--prefix $prefix}"
overlay_flag="${overlay:+--overlay $overlay}"
app_file="${prefix:+${prefix}-}app.yaml"
# An overlay's name is declared, never derived from its directory name, so that
# it can be checked against the Argo Application that deploys it.
if [ -n "$overlay" ]; then
marker="pr/$app_dir/$overlay/.overlay.yaml"
[ -f "$marker" ] || marker="base/$app_dir/$overlay/.overlay.yaml"
app_name=$(yq -r '.name' "$marker")
else
app_name="${prefix:-$(basename "$app_dir")}"
fi
# Stable per-app slug (also the comment marker key). Non-alphanumerics
# collapse to '-'; the dir keeps it unique across the two source trees.
# Keyed off the declared name, so renaming the overlay directory does not
# orphan its comment. Unchanged for non-overlay units.
slug_key="$app_dir${prefix:+-$prefix}${overlay:+-$app_name}"
slug=$(printf '%s' "$slug_key" | tr -c 'a-zA-Z0-9' '-' | tr -s '-' | sed 's/^-//; s/-$//')
# Render both sides; if stdout is empty (e.g. helm failed), fall back to stderr so
# the error message shows up in the diff rather than silently producing no content.
bash "$new_script" --template --env "$ENVIRONMENT" --include-all -d "pr/$app_dir" $prefix_flag $overlay_flag > /tmp/new.yaml 2>/tmp/new-err.txt || true
[ -s /tmp/new.yaml ] || cat /tmp/new-err.txt > /tmp/new.yaml
bash "$old_script" --template --env "$ENVIRONMENT" --include-all -d "base/$app_dir" $prefix_flag $overlay_flag > /tmp/old.yaml 2>/tmp/old-err.txt || true
[ -s /tmp/old.yaml ] || cat /tmp/old-err.txt > /tmp/old.yaml
diff_output=$(diff -u /tmp/old.yaml /tmp/new.yaml || true)
[ -z "$diff_output" ] && continue
has_diff=true
changed_lines=$(echo "$diff_output" | grep -c '^[+-]' || true)
# Extract version change from app.yaml if available (Chart.yaml apps have no single version to show)
version_hint=""
if [ -f "base/$app_dir/$app_file" ] && [ -f "pr/$app_dir/$app_file" ]; then
old_version=$(yq '.helm.version' "base/$app_dir/$app_file" 2>/dev/null || echo "")
new_version=$(yq '.helm.version' "pr/$app_dir/$app_file" 2>/dev/null || echo "")
if [ -n "$old_version" ] && [ "$old_version" != "null" ] && [ "$old_version" != "$new_version" ]; then
version_hint=" — \`$old_version\` → \`$new_version\`"
fi
fi
# Bound the diff by line count, then by byte count, so a single huge
# app can never push its comment past GitHub's hard limit.
diff_display="$diff_output"
if [ "$(printf '%s\n' "$diff_output" | wc -l)" -gt "$MAX_DIFF_LINES" ]; then
diff_display="$(printf '%s\n' "$diff_output" | head -n "$MAX_DIFF_LINES")"$'\n'"... (truncated, diff exceeds $MAX_DIFF_LINES lines)"
fi
if [ "${#diff_display}" -gt "$MAX_DIFF_CHARS" ]; then
diff_display="$(printf '%s' "$diff_display" | head -c "$MAX_DIFF_CHARS")"$'\n'"... (truncated, diff exceeds $MAX_DIFF_CHARS chars)"
fi
# Build with real newlines (no printf %b) so backslashes/percent signs
# in the diff are never reinterpreted.
{
printf '%s\n\n' "## Helm Template Diff — \`$app_name\`$version_hint"
printf '%s\n\n' "<details><summary>$changed_lines changed lines</summary>"
printf '%s\n' '```diff'
printf '%s\n' "$diff_display"
printf '%s\n\n' '```'
printf '%s\n' '</details>'
} > "/tmp/comments/$slug.md"
done <<< "$CHANGED_APPS"
if [ "$has_diff" = false ]; then
printf '%s\n\n%s\n' "## Helm Template Diff" "_No rendered resource changes detected._" > /tmp/comments/__no_diff__.md
fi
- name: Post or update PR comment
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
REPO: ${{ github.repository }}
API_URL: ${{ github.api_url }}
COMMENTS_DIR: /tmp/comments
run: |
python3 - <<'PY'
import json, os, glob, urllib.request, urllib.error
api = os.environ["API_URL"].rstrip("/")
repo = os.environ["REPO"]
pr = os.environ["PR_NUMBER"]
token = os.environ["GH_TOKEN"]
cdir = os.environ["COMMENTS_DIR"]
MARKER_PREFIX = "<!-- pr-diff-comment" # matches new per-app and legacy markers
def marker(slug): return f"<!-- pr-diff-comment:{slug} -->"
def call(method, url, payload=None):
data = json.dumps(payload).encode() if payload is not None else None
req = urllib.request.Request(url, data=data, method=method)
req.add_header("Authorization", f"token {token}")
req.add_header("Accept", "application/vnd.github+json")
if data is not None:
req.add_header("Content-Type", "application/json")
with urllib.request.urlopen(req) as resp:
raw = resp.read()
return json.loads(raw) if raw else None
# Desired comments: one per file, keyed by slug (filename without .md).
desired = {}
for path in sorted(glob.glob(os.path.join(cdir, "*.md"))):
slug = os.path.splitext(os.path.basename(path))[0]
with open(path) as f:
desired[slug] = f"{marker(slug)}\n{f.read()}"
# Existing pr-diff comments on the PR, keyed by slug ("" = legacy no-slug marker).
existing = {}
page = 1
while True:
batch = call("GET", f"{api}/repos/{repo}/issues/{pr}/comments?per_page=100&page={page}")
if not batch:
break
for c in batch:
body = c.get("body", "")
if MARKER_PREFIX not in body:
continue
slug = ""
m = body.split("<!-- pr-diff-comment:", 1)
if len(m) == 2:
slug = m[1].split(" -->", 1)[0].strip()
existing.setdefault(slug, []).append(c["id"])
page += 1
# Upsert each desired comment; reuse one existing id per slug if present.
for slug, body in desired.items():
ids = existing.get(slug, [])
if ids:
cid = ids.pop(0)
call("PATCH", f"{api}/repos/{repo}/issues/comments/{cid}", {"body": body})
print(f"updated {slug} (#{cid})")
else:
new = call("POST", f"{api}/repos/{repo}/issues/{pr}/comments", {"body": body})
print(f"created {slug} (#{new['id']})")
# Whatever ids remain are orphans: legacy comments, slugs no longer
# present, and duplicates (the reused id was popped during upsert).
for slug, ids in existing.items():
for cid in ids:
try:
call("DELETE", f"{api}/repos/{repo}/issues/comments/{cid}")
print(f"deleted {slug or '(legacy)'} (#{cid})")
except urllib.error.HTTPError as e:
print(f"skip delete #{cid}: {e}")
PY