mirror of
https://github.com/actions/actions-runner-controller.git
synced 2026-01-19 02:25:02 +08:00
Compare commits
1 Commits
nikola-jok
...
dependabot
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
09bd24d095 |
2
.github/workflows/gha-publish-chart.yaml
vendored
2
.github/workflows/gha-publish-chart.yaml
vendored
@@ -75,7 +75,7 @@ jobs:
|
|||||||
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
|
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
|
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f
|
||||||
with:
|
with:
|
||||||
# Pinning v0.9.1 for Buildx and BuildKit v0.10.6
|
# Pinning v0.9.1 for Buildx and BuildKit v0.10.6
|
||||||
# BuildKit v0.11 which has a bug causing intermittent
|
# BuildKit v0.11 which has a bug causing intermittent
|
||||||
|
|||||||
2
.github/workflows/gha-validate-chart.yaml
vendored
2
.github/workflows/gha-validate-chart.yaml
vendored
@@ -67,7 +67,7 @@ jobs:
|
|||||||
ct lint --config charts/.ci/ct-config-gha.yaml
|
ct lint --config charts/.ci/ct-config-gha.yaml
|
||||||
|
|
||||||
- name: Set up docker buildx
|
- name: Set up docker buildx
|
||||||
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
|
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f
|
||||||
if: steps.list-changed.outputs.changed == 'true'
|
if: steps.list-changed.outputs.changed == 'true'
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|||||||
2
.github/workflows/global-publish-canary.yaml
vendored
2
.github/workflows/global-publish-canary.yaml
vendored
@@ -113,7 +113,7 @@ jobs:
|
|||||||
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
|
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130
|
||||||
|
|
||||||
- name: Set up Docker Buildx
|
- name: Set up Docker Buildx
|
||||||
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435
|
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f
|
||||||
with:
|
with:
|
||||||
version: latest
|
version: latest
|
||||||
|
|
||||||
|
|||||||
@@ -1,24 +0,0 @@
|
|||||||
# Patterns to ignore when building packages.
|
|
||||||
# This supports shell glob matching, relative path matching, and
|
|
||||||
# negation (prefixed with !). Only one pattern per line.
|
|
||||||
.DS_Store
|
|
||||||
# Common VCS dirs
|
|
||||||
.git/
|
|
||||||
.gitignore
|
|
||||||
.bzr/
|
|
||||||
.bzrignore
|
|
||||||
.hg/
|
|
||||||
.hgignore
|
|
||||||
.svn/
|
|
||||||
# Common backup files
|
|
||||||
*.swp
|
|
||||||
*.bak
|
|
||||||
*.tmp
|
|
||||||
*.orig
|
|
||||||
*~
|
|
||||||
# Various IDEs
|
|
||||||
.project
|
|
||||||
.idea/
|
|
||||||
*.tmproj
|
|
||||||
.vscode/
|
|
||||||
tests/
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
apiVersion: v2
|
|
||||||
name: gha-runner-scale-set
|
|
||||||
description: A Helm chart for deploying an AutoScalingRunnerSet
|
|
||||||
|
|
||||||
# A chart can be either an 'application' or a 'library' chart.
|
|
||||||
#
|
|
||||||
# Application charts are a collection of templates that can be packaged into versioned archives
|
|
||||||
# to be deployed.
|
|
||||||
#
|
|
||||||
# Library charts provide useful utilities or functions for the chart developer. They're included as
|
|
||||||
# a dependency of application charts to inject those utilities and functions into the rendering
|
|
||||||
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
|
|
||||||
type: application
|
|
||||||
|
|
||||||
# This is the chart version. This version number should be incremented each time you make changes
|
|
||||||
# to the chart and its templates, including the app version.
|
|
||||||
# Versions are expected to follow Semantic Versioning (https://semver.org/)
|
|
||||||
version: "0.14.0"
|
|
||||||
|
|
||||||
# This is the version number of the application being deployed. This version number should be
|
|
||||||
# incremented each time you make changes to the application. Versions are not expected to
|
|
||||||
# follow Semantic Versioning. They should reflect the version the application is using.
|
|
||||||
# It is recommended to use it with quotes.
|
|
||||||
appVersion: "0.14.0"
|
|
||||||
|
|
||||||
home: https://github.com/actions/actions-runner-controller
|
|
||||||
|
|
||||||
sources:
|
|
||||||
- "https://github.com/actions/actions-runner-controller"
|
|
||||||
|
|
||||||
maintainers:
|
|
||||||
- name: actions
|
|
||||||
url: https://github.com/actions
|
|
||||||
@@ -1,168 +0,0 @@
|
|||||||
|
|
||||||
{{- define "autoscaling-runner-set.name" -}}
|
|
||||||
{{- $name := .Values.runnerScaleSetName | default .Release.Name | replace "_" "-" | trimSuffix "-" }}
|
|
||||||
{{- if or (empty $name) (gt (len $name) 45) }}
|
|
||||||
{{ fail "Autoscaling runner set name must have up to 45 characters" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- $name }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- define "autoscaling-runner-set.namespace" -}}
|
|
||||||
{{- .Values.namespaceOverride | default .Release.Namespace -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
The name of the manager Role.
|
|
||||||
*/}}
|
|
||||||
{{- define "manager-role.name" -}}
|
|
||||||
{{- printf "%s-manager-role" (include "autoscaling-runner-set.name" .) -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the labels for the manager Role.
|
|
||||||
*/}}
|
|
||||||
{{- define "manager-role.labels" -}}
|
|
||||||
{{- $resourceLabels := dict "app.kubernetes.io/component" "manager-role" -}}
|
|
||||||
{{- $commonLabels := include "gha-common-labels" . | fromYaml -}}
|
|
||||||
{{- $userLabels := include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.managerRole.metadata.labels | default (dict)) | fromYaml -}}
|
|
||||||
{{- $global := include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.all.metadata.labels | default (dict)) | fromYaml -}}
|
|
||||||
{{- toYaml (mergeOverwrite $global $userLabels $resourceLabels $commonLabels) }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the annotations for the manager Role.
|
|
||||||
|
|
||||||
Order of precedence:
|
|
||||||
1) resource.all.metadata.annotations
|
|
||||||
2) resource.managerRole.metadata.annotations
|
|
||||||
Reserved annotations are excluded from both levels.
|
|
||||||
*/}}
|
|
||||||
{{- define "manager-role.annotations" -}}
|
|
||||||
{{- $global := (include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.all.metadata.annotations | default (dict))) | fromYaml -}}
|
|
||||||
{{- $resource := (include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.managerRole.metadata.annotations | default (dict))) | fromYaml -}}
|
|
||||||
{{- $annotations := mergeOverwrite $global $resource -}}
|
|
||||||
{{- if not (empty $annotations) -}}
|
|
||||||
{{- toYaml $annotations }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
The name of the GitHub secret used for authentication.
|
|
||||||
*/}}
|
|
||||||
{{- define "github-secret.name" -}}
|
|
||||||
{{- if not (empty .Values.auth.secretName) -}}
|
|
||||||
{{- .Values.auth.secretName -}}
|
|
||||||
{{- else -}}
|
|
||||||
{{- include "autoscaling-runner-set.name" . }}-github-secret
|
|
||||||
{{- end -}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the labels for the GitHub auth secret.
|
|
||||||
*/}}
|
|
||||||
{{- define "github-secret.labels" -}}
|
|
||||||
{{- $resourceLabels := dict "app.kubernetes.io/component" "github-secret" -}}
|
|
||||||
{{- $commonLabels := include "gha-common-labels" . | fromYaml -}}
|
|
||||||
{{- $global := include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.all.metadata.labels | default (dict)) | fromYaml -}}
|
|
||||||
{{- toYaml (mergeOverwrite $global $resourceLabels $commonLabels) }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the annotations for the GitHub auth secret.
|
|
||||||
|
|
||||||
Only global annotations are applied.
|
|
||||||
Reserved annotations are excluded.
|
|
||||||
*/}}
|
|
||||||
{{- define "github-secret.annotations" -}}
|
|
||||||
{{- $annotations := (include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.all.metadata.annotations | default (dict))) | fromYaml -}}
|
|
||||||
{{- if not (empty $annotations) -}}
|
|
||||||
{{- toYaml $annotations }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the labels for the autoscaling runner set.
|
|
||||||
*/}}
|
|
||||||
{{- define "autoscaling-runner-set.labels" -}}
|
|
||||||
{{- $resourceLabels := dict "app.kubernetes.io/component" "autoscaling-runner-set" -}}
|
|
||||||
{{- $commonLabels := include "gha-common-labels" . | fromYaml -}}
|
|
||||||
{{- $userLabels := include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.autoscalingRunnerSet.metadata.labels | default (dict)) | fromYaml -}}
|
|
||||||
{{- $global := include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.all.metadata.labels | default (dict)) | fromYaml -}}
|
|
||||||
{{- toYaml (mergeOverwrite $global $userLabels $resourceLabels $commonLabels) }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the common labels used across all resources.
|
|
||||||
*/}}
|
|
||||||
{{- define "gha-common-labels" -}}
|
|
||||||
helm.sh/chart: {{ include "gha-runner-scale-set.chart" . }}
|
|
||||||
app.kubernetes.io/name: {{ include "autoscaling-runner-set.name" . }}
|
|
||||||
app.kubernetes.io/instance: {{ include "autoscaling-runner-set.name" . }}
|
|
||||||
app.kubernetes.io/version: {{ .Chart.AppVersion }}
|
|
||||||
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
|
||||||
app.kubernetes.io/part-of: "gha-rs"
|
|
||||||
actions.github.com/scale-set-name: {{ include "autoscaling-runner-set.name" . }}
|
|
||||||
actions.github.com/scale-set-namespace: {{ include "autoscaling-runner-set.namespace" . }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Takes a map of user labels and removes the ones with "actions.github.com/" prefix
|
|
||||||
*/}}
|
|
||||||
{{- define "apply-non-reserved-gha-labels-and-annotations" -}}
|
|
||||||
{{- $userLabels := . -}}
|
|
||||||
{{- $processed := dict -}}
|
|
||||||
{{- range $key, $value := $userLabels -}}
|
|
||||||
{{- if not (hasPrefix "actions.github.com/" $key) -}}
|
|
||||||
{{- $_ := set $processed $key $value -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- end -}}
|
|
||||||
{{- if not (empty $processed) -}}
|
|
||||||
{{- $processed | toYaml }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create the annotations for the autoscaling runner set.
|
|
||||||
|
|
||||||
Order of precedence:
|
|
||||||
1) resource.all.metadata.annotations
|
|
||||||
2) resource.autoscalingRunnerSet.metadata.annotations
|
|
||||||
Reserved annotations are excluded from both levels.
|
|
||||||
*/}}
|
|
||||||
{{- define "autoscaling-runner-set.annotations" -}}
|
|
||||||
{{- $global := (include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.all.metadata.annotations | default (dict))) | fromYaml -}}
|
|
||||||
{{- $resource := (include "apply-non-reserved-gha-labels-and-annotations" (.Values.resource.autoscalingRunnerSet.metadata.annotations | default (dict))) | fromYaml -}}
|
|
||||||
{{- $annotations := mergeOverwrite $global $resource -}}
|
|
||||||
{{- if not (empty $annotations) -}}
|
|
||||||
{{- toYaml $annotations }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Create chart name and version as used by the chart label.
|
|
||||||
*/}}
|
|
||||||
{{- define "gha-runner-scale-set.chart" -}}
|
|
||||||
{{- printf "gha-rs-%s" .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{/*
|
|
||||||
Container spec that is expanded for the runner container
|
|
||||||
*/}}
|
|
||||||
{{- define "container-spec.runner" -}}
|
|
||||||
|
|
||||||
{{- if not .Values.runner.container }}
|
|
||||||
{{ fail "You must provide a runner container specification in values.runner.container" }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- $tlsConfig := (default (dict) .Values.githubServerTLS) -}}
|
|
||||||
name: runner
|
|
||||||
image: {{ .Values.runner.container.image | default "ghcr.io/actions/runner:latest" }}
|
|
||||||
command: {{ toJson (default (list "/home/runner/run.sh") .Values.runner.container.command) }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
@@ -1,102 +0,0 @@
|
|||||||
apiVersion: actions.github.com/v1alpha1
|
|
||||||
kind: AutoscalingRunnerSet
|
|
||||||
metadata:
|
|
||||||
name: {{ include "autoscaling-runner-set.name" . | quote }}
|
|
||||||
namespace: {{ include "autoscaling-runner-set.namespace" . | quote }}
|
|
||||||
labels:
|
|
||||||
{{- include "autoscaling-runner-set.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
{{- include "autoscaling-runner-set.annotations" . | nindent 4 }}
|
|
||||||
actions.github.com/values-hash: {{ toJson .Values | sha256sum | trunc 63 }}
|
|
||||||
|
|
||||||
spec:
|
|
||||||
githubConfigUrl: {{ required ".Values.auth.url is required" (trimSuffix "/" .Values.auth.url) | quote }}
|
|
||||||
githubConfigSecret: {{ include "github-secret.name" . | quote }}
|
|
||||||
runnerGroup: {{ .Values.scaleset.runnerGroup | quote }}
|
|
||||||
runnerScaleSetName: {{ .Values.scaleset.name | quote }}
|
|
||||||
|
|
||||||
{{- if .Values.githubServerTLS }}
|
|
||||||
githubServerTLS:
|
|
||||||
{{- with .Values.githubServerTLS.certificateFrom }}
|
|
||||||
certificateFrom:
|
|
||||||
configMapKeyRef:
|
|
||||||
name: {{ .configMapKeyRef.name }}
|
|
||||||
key: {{ .configMapKeyRef.key }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- if and .Values.secretResolution (ne .Values.secretResolution.type "kubernetes") }}
|
|
||||||
vaultConfig:
|
|
||||||
type: {{ .Values.secretResolution.type }}
|
|
||||||
{{- if .Values.secretResolution.proxy }}
|
|
||||||
proxy: {{- toYaml .Values.secretResolution.proxy | nindent 6 }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if eq .Values.secretResolution.type "azureKeyVault" }}
|
|
||||||
azureKeyVault:
|
|
||||||
url: {{ .Values.secretResolution.azureKeyVault.url }}
|
|
||||||
tenantId: {{ .Values.secretResolution.azureKeyVault.tenantId }}
|
|
||||||
clientId: {{ .Values.secretResolution.azureKeyVault.clientId }}
|
|
||||||
certificatePath: {{ .Values.secretResolution.azureKeyVault.certificatePath }}
|
|
||||||
secretKey: {{ .Values.secretResolution.azureKeyVault.secretKey }}
|
|
||||||
{{- else }}
|
|
||||||
{{- fail (printf "Unsupported keyVault type: %s" .Values.secretResolution.type) }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- if .Values.proxy }}
|
|
||||||
proxy:
|
|
||||||
{{- if .Values.proxy.http }}
|
|
||||||
http:
|
|
||||||
url: {{ .Values.proxy.http.url }}
|
|
||||||
{{- if .Values.proxy.http.credentialSecretRef }}
|
|
||||||
credentialSecretRef: {{ .Values.proxy.http.credentialSecretRef }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if .Values.proxy.https }}
|
|
||||||
https:
|
|
||||||
url: {{ .Values.proxy.https.url }}
|
|
||||||
{{- if .Values.proxy.https.credentialSecretRef }}
|
|
||||||
credentialSecretRef: {{ .Values.proxy.https.credentialSecretRef }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
{{- if and .Values.proxy.noProxy (kindIs "slice" .Values.proxy.noProxy) }}
|
|
||||||
noProxy: {{ .Values.proxy.noProxy | toYaml | nindent 6}}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- if and (or (kindIs "int64" .Values.scaleset.minRunners) (kindIs "float64" .Values.scaleset.minRunners)) (or (kindIs "int64" .Values.scaleset.maxRunners) (kindIs "float64" .Values.scaleset.maxRunners)) }}
|
|
||||||
{{- if gt .Values.scaleset.minRunners .Values.scaleset.maxRunners }}
|
|
||||||
{{- fail "maxRunners has to be greater or equal to minRunners" }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- if or (kindIs "int64" .Values.scaleset.maxRunners) (kindIs "float64" .Values.scaleset.maxRunners)}}
|
|
||||||
{{- if lt (.Values.scaleset.maxRunners | int) 0 }}
|
|
||||||
{{- fail "maxRunners has to be greater or equal to 0" }}
|
|
||||||
{{- end }}
|
|
||||||
maxRunners: {{ .Values.scaleset.maxRunners | int }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- if or (kindIs "int64" .Values.scaleset.minRunners) (kindIs "float64" .Values.scaleset.minRunners) }}
|
|
||||||
{{- if lt (.Values.scaleset.minRunners | int) 0 }}
|
|
||||||
{{- fail "minRunners has to be greater or equal to 0" }}
|
|
||||||
{{- end }}
|
|
||||||
minRunners: {{ .Values.scaleset.minRunners | int }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- with .Values.listenerPodTemplate }}
|
|
||||||
listenerTemplate:
|
|
||||||
{{- toYaml . | nindent 4}}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- with .Values.listenerMetrics }}
|
|
||||||
listenerMetrics:
|
|
||||||
{{- toYaml . | nindent 4 }}
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
template:
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: runner
|
|
||||||
image: {{ .Values.runner.container.image | default "ghcr.io/actions/actions-runner:latest" | quote }}
|
|
||||||
command: {{ toJson (default (list "/home/runner/run.sh") .Values.runner.container.command) }}
|
|
||||||
@@ -1,28 +0,0 @@
|
|||||||
{{- $usesKubernetesSecrets := or (not .Values.secretResolution) (eq .Values.secretResolution.type "kubernetes") -}}
|
|
||||||
|
|
||||||
{{- if and (not $usesKubernetesSecrets) (empty .Values.auth.secretName) -}}
|
|
||||||
{{- fail ".Values.auth.secretName is required when .Values.secretResolution.type is not \"kubernetes\"" -}}
|
|
||||||
{{- end -}}
|
|
||||||
|
|
||||||
{{- if and $usesKubernetesSecrets (empty .Values.auth.secretName) -}}
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: {{ include "github-secret.name" . | quote }}
|
|
||||||
namespace: {{ include "autoscaling-runner-set.namespace" . | quote }}
|
|
||||||
labels:
|
|
||||||
{{- include "github-secret.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
{{- include "github-secret.annotations" . | nindent 4 }}
|
|
||||||
finalizers:
|
|
||||||
- actions.github.com/cleanup-protection
|
|
||||||
type: Opaque
|
|
||||||
data:
|
|
||||||
{{- if not (empty .Values.auth.app.clientId) }}
|
|
||||||
github_app_id: {{ .Values.auth.app.clientId | toString | b64enc }}
|
|
||||||
github_app_installation_id: {{ required ".Values.auth.app.installationId is required when using GitHub App auth" .Values.auth.app.installationId | toString | b64enc }}
|
|
||||||
github_app_private_key: {{ required ".Values.auth.app.privateKey is required when using GitHub App auth" .Values.auth.app.privateKey | toString | b64enc }}
|
|
||||||
{{- else }}
|
|
||||||
github_token: {{ required ".Values.auth.githubToken is required when auth.secretName and auth.app.clientId are not set" .Values.auth.githubToken | toString | b64enc }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
apiVersion: rbac.authorization.k8s.io/v1
|
|
||||||
kind: Role
|
|
||||||
metadata:
|
|
||||||
name: {{ include "manager-role.name" . | quote }}
|
|
||||||
namespace: {{ include "autoscaling-runner-set.namespace" . | quote }}
|
|
||||||
labels:
|
|
||||||
{{- include "manager-role.labels" . | nindent 4 }}
|
|
||||||
annotations:
|
|
||||||
{{- include "manager-role.annotations" . | nindent 4 }}
|
|
||||||
finalizers:
|
|
||||||
- actions.github.com/cleanup-protection
|
|
||||||
rules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- pods/status
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- secrets
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- serviceaccounts
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- list
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- rbac.authorization.k8s.io
|
|
||||||
resources:
|
|
||||||
- rolebindings
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
- apiGroups:
|
|
||||||
- rbac.authorization.k8s.io
|
|
||||||
resources:
|
|
||||||
- roles
|
|
||||||
verbs:
|
|
||||||
- create
|
|
||||||
- delete
|
|
||||||
- get
|
|
||||||
- patch
|
|
||||||
- update
|
|
||||||
{{- if .Values.githubServerTLS }}
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- configmaps
|
|
||||||
verbs:
|
|
||||||
- get
|
|
||||||
{{- end }}
|
|
||||||
|
|
||||||
{{- with .Values.resource.managerRole.extraRules }}
|
|
||||||
{{- if not (empty .) }}
|
|
||||||
{{- if not (kindIs "slice" .) -}}
|
|
||||||
{{- fail ".Values.resource.managerRole.extraRules must be a list of RBAC policy rules" -}}
|
|
||||||
{{- end }}
|
|
||||||
{{ toYaml . }}
|
|
||||||
{{- end }}
|
|
||||||
{{- end }}
|
|
||||||
@@ -1,79 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet Annotations"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should render values-hash annotation
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- exists:
|
|
||||||
path: metadata.annotations["actions.github.com/values-hash"]
|
|
||||||
|
|
||||||
- it: should merge global and resource annotations (resource overrides global)
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
a: "global"
|
|
||||||
shared: "global"
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
b: "resource"
|
|
||||||
shared: "resource"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.a
|
|
||||||
value: "global"
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.b
|
|
||||||
value: "resource"
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.shared
|
|
||||||
value: "resource"
|
|
||||||
|
|
||||||
- it: should not allow overriding reserved values-hash annotation
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
actions.github.com/values-hash: "user-value"
|
|
||||||
ok: "ok"
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
actions.github.com/cleanup-something: "should-not-render"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.ok
|
|
||||||
value: "ok"
|
|
||||||
- notEqual:
|
|
||||||
path: metadata.annotations["actions.github.com/values-hash"]
|
|
||||||
value: "user-value"
|
|
||||||
- notExists:
|
|
||||||
path: metadata.annotations["actions.github.com/cleanup-something"]
|
|
||||||
@@ -1,245 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet Authentication & Configuration"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should require githubConfigUrl
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate:
|
|
||||||
errorMessage: ".Values.auth.url is required"
|
|
||||||
|
|
||||||
- it: should render githubConfigUrl from auth.url
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigUrl
|
|
||||||
value: "https://github.com/org"
|
|
||||||
|
|
||||||
- it: should trim trailing slash from githubConfigUrl
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org/"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigUrl
|
|
||||||
value: "https://github.com/org"
|
|
||||||
|
|
||||||
- it: should render default githubConfigSecret from release name
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigSecret
|
|
||||||
value: "test-name-github-secret"
|
|
||||||
|
|
||||||
- it: should render custom githubConfigSecret when auth.secretName is provided
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
auth.secretName: "custom-github-secret"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigSecret
|
|
||||||
value: "custom-github-secret"
|
|
||||||
|
|
||||||
- it: should render default runnerGroup when not configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerGroup
|
|
||||||
value: "default"
|
|
||||||
|
|
||||||
- it: should render custom runnerGroup when configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
scaleset.runnerGroup: "custom-group"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerGroup
|
|
||||||
value: "custom-group"
|
|
||||||
|
|
||||||
- it: should render runnerGroup with special characters
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
scaleset.runnerGroup: "my-custom-runner-group-123"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerGroup
|
|
||||||
value: "my-custom-runner-group-123"
|
|
||||||
|
|
||||||
- it: should render runnerScaleSetName from scaleset.name
|
|
||||||
set:
|
|
||||||
scaleset.name: "my-runner-set"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerScaleSetName
|
|
||||||
value: "my-runner-set"
|
|
||||||
|
|
||||||
- it: should use release name as metadata name when runnerScaleSetName not provided
|
|
||||||
set:
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "release-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.name
|
|
||||||
value: "release-name"
|
|
||||||
|
|
||||||
- it: should use scaleset.name for spec.runnerScaleSetName when provided
|
|
||||||
set:
|
|
||||||
scaleset.name: "spec-runner-name"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "release-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerScaleSetName
|
|
||||||
value: "spec-runner-name"
|
|
||||||
|
|
||||||
- it: should not normalize underscores in runnerScaleSetName (underscores are preserved)
|
|
||||||
set:
|
|
||||||
scaleset.name: "my_runner_set"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerScaleSetName
|
|
||||||
value: "my_runner_set"
|
|
||||||
|
|
||||||
- it: should reject metadata name exceeding 45 characters
|
|
||||||
set:
|
|
||||||
runnerScaleSetName: "this-is-a-very-long-name-that-exceeds-forty-five-characters-long"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate:
|
|
||||||
errorMessage: "Autoscaling runner set name must have up to 45 characters"
|
|
||||||
|
|
||||||
- it: should handle githubConfigUrl with enterprise GitHub instance
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.enterprise.com/api/v3"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigUrl
|
|
||||||
value: "https://github.enterprise.com/api/v3"
|
|
||||||
|
|
||||||
- it: should render all configuration together
|
|
||||||
set:
|
|
||||||
runnerScaleSetName: "prod-runners"
|
|
||||||
scaleset.name: "prod-spec-name"
|
|
||||||
auth.url: "https://github.com/myorg"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
auth.secretName: "gh-token-secret"
|
|
||||||
scaleset.runnerGroup: "prod-group"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "prod-scale-set"
|
|
||||||
namespace: "arc"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigUrl
|
|
||||||
value: "https://github.com/myorg"
|
|
||||||
- equal:
|
|
||||||
path: spec.githubConfigSecret
|
|
||||||
value: "gh-token-secret"
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerGroup
|
|
||||||
value: "prod-group"
|
|
||||||
- equal:
|
|
||||||
path: spec.runnerScaleSetName
|
|
||||||
value: "prod-spec-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.name
|
|
||||||
value: "prod-runners"
|
|
||||||
- equal:
|
|
||||||
path: metadata.namespace
|
|
||||||
value: "arc"
|
|
||||||
@@ -1,293 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet Labels"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should render base labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
chart:
|
|
||||||
appVersion: "0.14.0"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["helm.sh/chart"]
|
|
||||||
value: "gha-rs-0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/instance"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "autoscaling-runner-set"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/managed-by"]
|
|
||||||
value: "Helm"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/part-of"]
|
|
||||||
value: "gha-rs"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/version"]
|
|
||||||
value: "0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
|
|
||||||
- it: should include user-defined labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
team: "backend"
|
|
||||||
environment: "production"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["team"]
|
|
||||||
value: "backend"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["environment"]
|
|
||||||
value: "production"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["helm.sh/chart"]
|
|
||||||
value: "gha-rs-0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/instance"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "autoscaling-runner-set"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/managed-by"]
|
|
||||||
value: "Helm"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/part-of"]
|
|
||||||
value: "gha-rs"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/version"]
|
|
||||||
value: "0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
|
|
||||||
- it: should include global labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
global-team: "platform"
|
|
||||||
owner: "devops"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["global-team"]
|
|
||||||
value: "platform"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["owner"]
|
|
||||||
value: "devops"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["helm.sh/chart"]
|
|
||||||
value: "gha-rs-0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/instance"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "autoscaling-runner-set"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/managed-by"]
|
|
||||||
value: "Helm"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/part-of"]
|
|
||||||
value: "gha-rs"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/version"]
|
|
||||||
value: "0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
|
|
||||||
- it: should merge both user and global labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
team: "backend"
|
|
||||||
environment: "staging"
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
global-team: "platform"
|
|
||||||
environment: "production"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["team"]
|
|
||||||
value: "backend"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["global-team"]
|
|
||||||
value: "platform"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["environment"]
|
|
||||||
value: "staging"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["helm.sh/chart"]
|
|
||||||
value: "gha-rs-0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/instance"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "autoscaling-runner-set"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/managed-by"]
|
|
||||||
value: "Helm"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/part-of"]
|
|
||||||
value: "gha-rs"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/version"]
|
|
||||||
value: "0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
|
|
||||||
- it: should allow user labels to override global labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
tier: "frontend"
|
|
||||||
cost-center: "100"
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
tier: "backend"
|
|
||||||
environment: "staging"
|
|
||||||
cost-center: "200"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["tier"]
|
|
||||||
value: "frontend"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["cost-center"]
|
|
||||||
value: "100"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["environment"]
|
|
||||||
value: "staging"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
|
|
||||||
- it: should preserve actions.github.com custom labels from user config
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
team: "backend"
|
|
||||||
actions.github.com/custom-label: "user-value"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["team"]
|
|
||||||
value: "backend"
|
|
||||||
- notExists:
|
|
||||||
path: metadata.labels["actions.github.com/custom-label"]
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
|
|
||||||
- it: should preserve actions.github.com custom labels from global config
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
owner: "devops"
|
|
||||||
actions.github.com/global-custom: "global-value"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["owner"]
|
|
||||||
value: "devops"
|
|
||||||
- notExists:
|
|
||||||
path: metadata.labels["actions.github.com/global-custom"]
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
@@ -1,55 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet Listener Metrics"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should not render listenerMetrics when not configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- notExists:
|
|
||||||
path: spec.listenerMetrics
|
|
||||||
|
|
||||||
- it: should render listenerMetrics when configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
listenerMetrics:
|
|
||||||
counters:
|
|
||||||
gha_started_jobs_total:
|
|
||||||
labels:
|
|
||||||
- repository
|
|
||||||
- organization
|
|
||||||
histograms:
|
|
||||||
gha_job_startup_duration_seconds:
|
|
||||||
buckets:
|
|
||||||
- 0.1
|
|
||||||
- 1
|
|
||||||
- 2.5
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- exists:
|
|
||||||
path: spec.listenerMetrics
|
|
||||||
- equal:
|
|
||||||
path: spec.listenerMetrics.counters.gha_started_jobs_total.labels[0]
|
|
||||||
value: repository
|
|
||||||
- equal:
|
|
||||||
path: spec.listenerMetrics.counters.gha_started_jobs_total.labels[1]
|
|
||||||
value: organization
|
|
||||||
- contains:
|
|
||||||
path: spec.listenerMetrics.histograms.gha_job_startup_duration_seconds.buckets
|
|
||||||
content: 0.1
|
|
||||||
- contains:
|
|
||||||
path: spec.listenerMetrics.histograms.gha_job_startup_duration_seconds.buckets
|
|
||||||
content: 2.5
|
|
||||||
@@ -1,71 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet MinMax Runners"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should set minRunners and maxRunners correctly
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
scaleset.minRunners: 2
|
|
||||||
scaleset.maxRunners: 5
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.minRunners
|
|
||||||
value: 2
|
|
||||||
- equal:
|
|
||||||
path: spec.maxRunners
|
|
||||||
value: 5
|
|
||||||
- it: should fail when minRunners is greater than maxRunners
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
scaleset.minRunners: 6
|
|
||||||
scaleset.maxRunners: 5
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate: {}
|
|
||||||
- it: should work when minRunners equals maxRunners
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
scaleset.minRunners: 5
|
|
||||||
scaleset.maxRunners: 5
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.minRunners
|
|
||||||
value: 5
|
|
||||||
- equal:
|
|
||||||
path: spec.maxRunners
|
|
||||||
value: 5
|
|
||||||
- it: should not set minRunners and maxRunners when not provided
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- notExists:
|
|
||||||
path: spec.minRunners
|
|
||||||
- notExists:
|
|
||||||
path: spec.maxRunners
|
|
||||||
@@ -1,290 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet Proxy Configuration"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should not render proxy section when not configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy
|
|
||||||
|
|
||||||
- it: should render http proxy configuration
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy.https
|
|
||||||
|
|
||||||
- it: should render https proxy configuration
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
https:
|
|
||||||
url: "https://secure-proxy.example.com:3128"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.url
|
|
||||||
value: "https://secure-proxy.example.com:3128"
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy.http
|
|
||||||
|
|
||||||
- it: should render both http and https proxy configuration
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
https:
|
|
||||||
url: "https://secure-proxy.example.com:3128"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.url
|
|
||||||
value: "https://secure-proxy.example.com:3128"
|
|
||||||
|
|
||||||
- it: should render http proxy with credential secret reference
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
credentialSecretRef: "proxy-credentials"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.credentialSecretRef
|
|
||||||
value: "proxy-credentials"
|
|
||||||
|
|
||||||
- it: should render https proxy with credential secret reference
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
https:
|
|
||||||
url: "https://secure-proxy.example.com:3128"
|
|
||||||
credentialSecretRef: "secure-proxy-creds"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.url
|
|
||||||
value: "https://secure-proxy.example.com:3128"
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.credentialSecretRef
|
|
||||||
value: "secure-proxy-creds"
|
|
||||||
|
|
||||||
- it: should render proxy with noProxy list
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
noProxy:
|
|
||||||
- "localhost"
|
|
||||||
- "127.0.0.1"
|
|
||||||
- ".example.local"
|
|
||||||
- "10.0.0.0/8"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "localhost"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "127.0.0.1"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: ".example.local"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "10.0.0.0/8"
|
|
||||||
|
|
||||||
- it: should render complete proxy configuration with all options
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
credentialSecretRef: "proxy-credentials"
|
|
||||||
https:
|
|
||||||
url: "https://secure-proxy.example.com:3128"
|
|
||||||
credentialSecretRef: "secure-proxy-creds"
|
|
||||||
noProxy:
|
|
||||||
- "localhost"
|
|
||||||
- "127.0.0.1"
|
|
||||||
- ".local"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.credentialSecretRef
|
|
||||||
value: "proxy-credentials"
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.url
|
|
||||||
value: "https://secure-proxy.example.com:3128"
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.credentialSecretRef
|
|
||||||
value: "secure-proxy-creds"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "localhost"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "127.0.0.1"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: ".local"
|
|
||||||
|
|
||||||
- it: should render proxy configuration with empty noProxy list
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
noProxy: []
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
|
|
||||||
- it: should not render proxy when configured as empty object
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy: {}
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy
|
|
||||||
|
|
||||||
- it: should render proxy with only http without credentials
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://unauthenticated-proxy.example.com:8080"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.http.url
|
|
||||||
value: "http://unauthenticated-proxy.example.com:8080"
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy.http.credentialSecretRef
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy.https
|
|
||||||
|
|
||||||
- it: should render proxy with https and noProxy without http
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
proxy:
|
|
||||||
https:
|
|
||||||
url: "https://secure-proxy.example.com:3128"
|
|
||||||
noProxy:
|
|
||||||
- "internal.example.com"
|
|
||||||
- "*.local"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.proxy.https.url
|
|
||||||
value: "https://secure-proxy.example.com:3128"
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy.http
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "internal.example.com"
|
|
||||||
- contains:
|
|
||||||
path: spec.proxy.noProxy
|
|
||||||
content: "*.local"
|
|
||||||
@@ -1,110 +0,0 @@
|
|||||||
suite: "Test AutoscalingRunnerSet Vault Config"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should not render vaultConfig when secretResolution.type is kubernetes
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
secretResolution:
|
|
||||||
type: kubernetes
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- notExists:
|
|
||||||
path: spec.vaultConfig
|
|
||||||
|
|
||||||
- it: should render azureKeyVault vaultConfig when configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
secretResolution:
|
|
||||||
type: azureKeyVault
|
|
||||||
azureKeyVault:
|
|
||||||
url: "https://myvault.vault.azure.net"
|
|
||||||
tenantId: "tenant-123"
|
|
||||||
clientId: "client-456"
|
|
||||||
certificatePath: "/etc/certs/akv.pem"
|
|
||||||
secretKey: "secret-key-name"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.type
|
|
||||||
value: azureKeyVault
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.azureKeyVault.url
|
|
||||||
value: "https://myvault.vault.azure.net"
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.azureKeyVault.tenantId
|
|
||||||
value: "tenant-123"
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.azureKeyVault.clientId
|
|
||||||
value: "client-456"
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.azureKeyVault.certificatePath
|
|
||||||
value: "/etc/certs/akv.pem"
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.azureKeyVault.secretKey
|
|
||||||
value: "secret-key-name"
|
|
||||||
|
|
||||||
- it: should render vaultConfig proxy when configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
secretResolution:
|
|
||||||
type: azureKeyVault
|
|
||||||
proxy:
|
|
||||||
http:
|
|
||||||
url: "http://proxy.example.com:3128"
|
|
||||||
credentialSecretRef: "proxy-credentials"
|
|
||||||
noProxy:
|
|
||||||
- "localhost"
|
|
||||||
azureKeyVault:
|
|
||||||
url: "https://myvault.vault.azure.net"
|
|
||||||
tenantId: "tenant-123"
|
|
||||||
clientId: "client-456"
|
|
||||||
certificatePath: "/etc/certs/akv.pem"
|
|
||||||
secretKey: "secret-key-name"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.proxy.http.url
|
|
||||||
value: "http://proxy.example.com:3128"
|
|
||||||
- equal:
|
|
||||||
path: spec.vaultConfig.proxy.http.credentialSecretRef
|
|
||||||
value: "proxy-credentials"
|
|
||||||
- contains:
|
|
||||||
path: spec.vaultConfig.proxy.noProxy
|
|
||||||
content: "localhost"
|
|
||||||
- notExists:
|
|
||||||
path: spec.proxy
|
|
||||||
|
|
||||||
- it: should fail for unsupported secretResolution.type
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
controllerServiceAccount.name: "arc"
|
|
||||||
controllerServiceAccount.namespace: "arc-system"
|
|
||||||
secretResolution:
|
|
||||||
type: "hashicorpVault"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate:
|
|
||||||
errorMessage: "Unsupported keyVault type: hashicorpVault"
|
|
||||||
@@ -1,49 +0,0 @@
|
|||||||
suite: "Test GitHub Secret Annotations"
|
|
||||||
templates:
|
|
||||||
- githubsecret.yaml
|
|
||||||
tests:
|
|
||||||
- it: should include global annotations
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
a: "global"
|
|
||||||
shared: "global"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.a
|
|
||||||
value: "global"
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.shared
|
|
||||||
value: "global"
|
|
||||||
|
|
||||||
- it: should drop actions.github.com annotations from global config
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
annotations:
|
|
||||||
ok: "ok"
|
|
||||||
actions.github.com/values-hash: "user-value"
|
|
||||||
actions.github.com/cleanup-something: "should-not-render"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.annotations.ok
|
|
||||||
value: "ok"
|
|
||||||
- notExists:
|
|
||||||
path: metadata.annotations["actions.github.com/values-hash"]
|
|
||||||
- notExists:
|
|
||||||
path: metadata.annotations["actions.github.com/cleanup-something"]
|
|
||||||
@@ -1,70 +0,0 @@
|
|||||||
suite: "Test GitHub Secret Data"
|
|
||||||
templates:
|
|
||||||
- githubsecret.yaml
|
|
||||||
tests:
|
|
||||||
- it: should render PAT token when configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- exists:
|
|
||||||
path: data.github_token
|
|
||||||
- equal:
|
|
||||||
path: data.github_token
|
|
||||||
value: "Z2hfdG9rZW4xMjM0NQ=="
|
|
||||||
- notExists:
|
|
||||||
path: data.github_app_id
|
|
||||||
- notExists:
|
|
||||||
path: data.github_app_installation_id
|
|
||||||
- notExists:
|
|
||||||
path: data.github_app_private_key
|
|
||||||
|
|
||||||
- it: should render GitHub App keys when app is configured
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.app:
|
|
||||||
clientId: "123"
|
|
||||||
installationId: "456"
|
|
||||||
privateKey: "mykey"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- notExists:
|
|
||||||
path: data.github_token
|
|
||||||
- equal:
|
|
||||||
path: data.github_app_id
|
|
||||||
value: "MTIz"
|
|
||||||
- equal:
|
|
||||||
path: data.github_app_installation_id
|
|
||||||
value: "NDU2"
|
|
||||||
- equal:
|
|
||||||
path: data.github_app_private_key
|
|
||||||
value: "bXlrZXk="
|
|
||||||
|
|
||||||
- it: should fail if app is configured without installationId
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.app:
|
|
||||||
clientId: "123"
|
|
||||||
privateKey: "mykey"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate:
|
|
||||||
errorMessage: ".Values.auth.app.installationId is required when using GitHub App auth"
|
|
||||||
|
|
||||||
- it: should fail if app is configured without privateKey
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.app:
|
|
||||||
clientId: "123"
|
|
||||||
installationId: "456"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate:
|
|
||||||
errorMessage: ".Values.auth.app.privateKey is required when using GitHub App auth"
|
|
||||||
@@ -1,129 +0,0 @@
|
|||||||
suite: "Test GitHub Secret Labels"
|
|
||||||
templates:
|
|
||||||
- githubsecret.yaml
|
|
||||||
tests:
|
|
||||||
- it: should render base labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
chart:
|
|
||||||
appVersion: "0.14.0"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["helm.sh/chart"]
|
|
||||||
value: "gha-rs-0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/instance"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "github-secret"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/managed-by"]
|
|
||||||
value: "Helm"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/part-of"]
|
|
||||||
value: "gha-rs"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/version"]
|
|
||||||
value: "0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
|
|
||||||
- it: should include global labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
global-team: "platform"
|
|
||||||
owner: "devops"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["global-team"]
|
|
||||||
value: "platform"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["owner"]
|
|
||||||
value: "devops"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "github-secret"
|
|
||||||
|
|
||||||
- it: should drop actions.github.com custom labels from global config
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
owner: "devops"
|
|
||||||
actions.github.com/global-custom: "global-value"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["owner"]
|
|
||||||
value: "devops"
|
|
||||||
- notExists:
|
|
||||||
path: metadata.labels["actions.github.com/global-custom"]
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
|
|
||||||
- it: should not allow global labels to override reserved labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_token12345"
|
|
||||||
resource:
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
helm.sh/chart: "bad"
|
|
||||||
app.kubernetes.io/name: "bad"
|
|
||||||
app.kubernetes.io/instance: "bad"
|
|
||||||
app.kubernetes.io/component: "bad"
|
|
||||||
actions.github.com/scale-set-name: "bad"
|
|
||||||
actions.github.com/scale-set-namespace: "bad"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["helm.sh/chart"]
|
|
||||||
value: "gha-rs-0.14.0"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/instance"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "github-secret"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
suite: "Test Manager Role Extra Rules"
|
|
||||||
templates:
|
|
||||||
- manager_role.yaml
|
|
||||||
tests:
|
|
||||||
- it: should render base role metadata
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
chart:
|
|
||||||
appVersion: "0.14.0"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: apiVersion
|
|
||||||
value: "rbac.authorization.k8s.io/v1"
|
|
||||||
- equal:
|
|
||||||
path: kind
|
|
||||||
value: "Role"
|
|
||||||
- equal:
|
|
||||||
path: metadata.name
|
|
||||||
value: "test-name-manager-role"
|
|
||||||
- equal:
|
|
||||||
path: metadata.namespace
|
|
||||||
value: "test-namespace"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["app.kubernetes.io/component"]
|
|
||||||
value: "manager-role"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-name"]
|
|
||||||
value: "test-name"
|
|
||||||
- equal:
|
|
||||||
path: metadata.labels["actions.github.com/scale-set-namespace"]
|
|
||||||
value: "test-namespace"
|
|
||||||
- equal:
|
|
||||||
path: metadata.finalizers[0]
|
|
||||||
value: "actions.github.com/cleanup-protection"
|
|
||||||
|
|
||||||
- it: should append extra RBAC policy rules
|
|
||||||
set:
|
|
||||||
resource:
|
|
||||||
managerRole:
|
|
||||||
extraRules:
|
|
||||||
- apiGroups:
|
|
||||||
- ""
|
|
||||||
resources:
|
|
||||||
- "events"
|
|
||||||
verbs:
|
|
||||||
- "create"
|
|
||||||
- "patch"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- equal:
|
|
||||||
path: rules[6].apiGroups[0]
|
|
||||||
value: ""
|
|
||||||
- equal:
|
|
||||||
path: rules[6].resources[0]
|
|
||||||
value: "events"
|
|
||||||
- equal:
|
|
||||||
path: rules[6].verbs[0]
|
|
||||||
value: "create"
|
|
||||||
- equal:
|
|
||||||
path: rules[6].verbs[1]
|
|
||||||
value: "patch"
|
|
||||||
|
|
||||||
- it: should fail when extraRules is not a list
|
|
||||||
set:
|
|
||||||
resource:
|
|
||||||
managerRole:
|
|
||||||
extraRules: "not-a-list"
|
|
||||||
release:
|
|
||||||
name: "test-name"
|
|
||||||
namespace: "test-namespace"
|
|
||||||
asserts:
|
|
||||||
- failedTemplate:
|
|
||||||
errorMessage: ".Values.resource.managerRole.extraRules must be a list of RBAC policy rules"
|
|
||||||
@@ -1,318 +0,0 @@
|
|||||||
## By default .Release.namespace is used
|
|
||||||
namespaceOverride: ""
|
|
||||||
|
|
||||||
scaleset:
|
|
||||||
# Name of the scaleset
|
|
||||||
name: ""
|
|
||||||
runnerGroup: "default"
|
|
||||||
## minRunners is the min number of idle runners. The target number of runners created will be
|
|
||||||
## calculated as a sum of minRunners and the number of jobs assigned to the scale set.
|
|
||||||
# minRunners: 0
|
|
||||||
## maxRunners is the max number of runners the autoscaling runner set will scale up to.
|
|
||||||
# maxRunners: 5
|
|
||||||
|
|
||||||
# Auth object provides authorization parameters.
|
|
||||||
# You should apply either:
|
|
||||||
# 1) secretName referencing the secret containing authorization parameters in the same namespace where the scale set is being installed in
|
|
||||||
# 2) app object parameters
|
|
||||||
# 3) github_tokne
|
|
||||||
#
|
|
||||||
# If multiple of them are set, only single one will be applied based on the above mentioned order.
|
|
||||||
auth:
|
|
||||||
url: "" # Required
|
|
||||||
githubToken: ""
|
|
||||||
secretName: ""
|
|
||||||
app:
|
|
||||||
clientId: ""
|
|
||||||
installationId: ""
|
|
||||||
privateKey: ""
|
|
||||||
|
|
||||||
# secretResolution configures how secrets are resolved for this scale set.
|
|
||||||
# By default, secrets are resolved using Kubernetes secrets. When Kubernetes
|
|
||||||
# secrets are used, no proxy config will be applied.
|
|
||||||
#
|
|
||||||
# If you decide to use secret integrations with vaults, you can configure
|
|
||||||
# proxy settings for the vault communication here.
|
|
||||||
secretResolution:
|
|
||||||
# Name of the secret resolver to use.
|
|
||||||
# Available values:
|
|
||||||
# - "kubernetes" - use Kubernetes secrets
|
|
||||||
# - "azureKeyVault" - use Azure Key Vault
|
|
||||||
type: "kubernetes"
|
|
||||||
|
|
||||||
## Proxy settings when type is NOT "kubernetes"
|
|
||||||
# proxy:
|
|
||||||
# http:
|
|
||||||
# url: http://proxy.com:1234
|
|
||||||
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
||||||
# https:
|
|
||||||
# url: http://proxy.com:1234
|
|
||||||
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
||||||
# noProxy:
|
|
||||||
# - example.com
|
|
||||||
# - example.org
|
|
||||||
|
|
||||||
## Configuration for Azure Key Vault integration
|
|
||||||
# azureKeyVault:
|
|
||||||
# url: ""
|
|
||||||
# client_id: ""
|
|
||||||
# tenant_id: ""
|
|
||||||
# certificate_path: ""
|
|
||||||
|
|
||||||
## Proxy can be used to define proxy settings that will be used by the
|
|
||||||
## controller, the listener and the runner of this scale set.
|
|
||||||
# proxy:
|
|
||||||
# http:
|
|
||||||
# url: http://proxy.com:1234
|
|
||||||
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
||||||
# https:
|
|
||||||
# url: http://proxy.com:1234
|
|
||||||
# credentialSecretRef: proxy-auth # a secret with `username` and `password` keys
|
|
||||||
# noProxy:
|
|
||||||
# - example.com
|
|
||||||
# - example.org
|
|
||||||
|
|
||||||
## listenerTemplate is the PodSpec for each listener Pod
|
|
||||||
## For reference: https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/pod-v1/#PodSpec
|
|
||||||
# listenerPodTemplate:
|
|
||||||
# spec:
|
|
||||||
# containers:
|
|
||||||
# # Use this section to append additional configuration to the listener container.
|
|
||||||
# # If you change the name of the container, the configuration will not be applied to the listener,
|
|
||||||
# # and it will be treated as a side-car container.
|
|
||||||
# - name: listener
|
|
||||||
# securityContext:
|
|
||||||
# runAsUser: 1000
|
|
||||||
# # Use this section to add the configuration of a side-car container.
|
|
||||||
# # Comment it out or remove it if you don't need it.
|
|
||||||
# # Spec for this container will be applied as is without any modifications.
|
|
||||||
# - name: side-car
|
|
||||||
# image: example-sidecar
|
|
||||||
|
|
||||||
## Resource object allows modifying resources created by the chart itself
|
|
||||||
resource:
|
|
||||||
# Specifies metadata that will be applied to all resources managed by ARC
|
|
||||||
all:
|
|
||||||
metadata:
|
|
||||||
labels: {}
|
|
||||||
annotations: {}
|
|
||||||
|
|
||||||
# Specifies metadata that will be applied to the AutoscalingRunnerSet resource
|
|
||||||
autoscalingRunnerSet:
|
|
||||||
metadata:
|
|
||||||
labels: {}
|
|
||||||
annotations: {}
|
|
||||||
|
|
||||||
# Specifies metadata that will be applied to the manager Role resource
|
|
||||||
managerRole:
|
|
||||||
metadata:
|
|
||||||
labels: {}
|
|
||||||
annotations: {}
|
|
||||||
extraRules: []
|
|
||||||
|
|
||||||
# TODO: Add more resource customizations when needed
|
|
||||||
|
|
||||||
# Template applied for the runner container
|
|
||||||
runner:
|
|
||||||
# metadata:
|
|
||||||
# labels: []
|
|
||||||
# annotations: []
|
|
||||||
|
|
||||||
# Mode can be used to automatically add required configuration for the selected mode
|
|
||||||
mode: "" # Available modes: "", "kubernetes", "dind"
|
|
||||||
|
|
||||||
# container field is applied to the container named "runner". You cannot override the name of the runner container
|
|
||||||
container:
|
|
||||||
image: "ghcr.io/actions/actions-runner:latest"
|
|
||||||
command: ["/home/runner/run.sh"]
|
|
||||||
|
|
||||||
dind:
|
|
||||||
# If default is set to true, we will expand the default spec for the `dind` container, and you can provide fields to override them
|
|
||||||
default: true
|
|
||||||
|
|
||||||
kubernetesMode:
|
|
||||||
default: true
|
|
||||||
serviceAccountName: ""
|
|
||||||
extraPermissions: []
|
|
||||||
extension: {}
|
|
||||||
## A self-signed CA certificate for communication with the GitHub server can be
|
|
||||||
## provided using a config map key selector. If `runnerMountPath` is set, for
|
|
||||||
## each runner pod ARC will:
|
|
||||||
## - create a `github-server-tls-cert` volume containing the certificate
|
|
||||||
## specified in `certificateFrom`
|
|
||||||
## - mount that volume on path `runnerMountPath`/{certificate name}
|
|
||||||
## - set NODE_EXTRA_CA_CERTS environment variable to that same path
|
|
||||||
## - set RUNNER_UPDATE_CA_CERTS environment variable to "1" (as of version
|
|
||||||
## 2.303.0 this will instruct the runner to reload certificates on the host)
|
|
||||||
##
|
|
||||||
## If any of the above had already been set by the user in the runner pod
|
|
||||||
## template, ARC will observe those and not overwrite them.
|
|
||||||
## Example configuration:
|
|
||||||
#
|
|
||||||
# githubServerTLS:
|
|
||||||
# certificateFrom:
|
|
||||||
# configMapKeyRef:
|
|
||||||
# name: config-map-name
|
|
||||||
# key: ca.crt
|
|
||||||
# runnerMountPath: /usr/local/share/ca-certificates/
|
|
||||||
|
|
||||||
## controllerServiceAccount is the service account of the controller
|
|
||||||
controllerServiceAccount:
|
|
||||||
namespace: ""
|
|
||||||
name: ""
|
|
||||||
|
|
||||||
## listenerMetrics are configurable metrics applied to the listener.
|
|
||||||
## In order to avoid helm merging these fields, we left the metrics commented out.
|
|
||||||
## When configuring metrics, please uncomment the listenerMetrics object below.
|
|
||||||
## You can modify the configuration to remove the label or specify custom buckets for histogram.
|
|
||||||
##
|
|
||||||
## If the buckets field is not specified, the default buckets will be applied. Default buckets are
|
|
||||||
## provided here for documentation purposes
|
|
||||||
# listenerMetrics:
|
|
||||||
# counters:
|
|
||||||
# gha_started_jobs_total:
|
|
||||||
# labels:
|
|
||||||
# ["repository", "organization", "enterprise", "job_name", "event_name", "job_workflow_ref", "job_workflow_name", "job_workflow_target"]
|
|
||||||
# gha_completed_jobs_total:
|
|
||||||
# labels:
|
|
||||||
# [
|
|
||||||
# "repository",
|
|
||||||
# "organization",
|
|
||||||
# "enterprise",
|
|
||||||
# "job_name",
|
|
||||||
# "event_name",
|
|
||||||
# "job_result",
|
|
||||||
# "job_workflow_ref",
|
|
||||||
# "job_workflow_name",
|
|
||||||
# "job_workflow_target",
|
|
||||||
# ]
|
|
||||||
# gauges:
|
|
||||||
# gha_assigned_jobs:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_running_jobs:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_registered_runners:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_busy_runners:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_min_runners:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_max_runners:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_desired_runners:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# gha_idle_runners:
|
|
||||||
# labels: ["name", "namespace", "repository", "organization", "enterprise"]
|
|
||||||
# histograms:
|
|
||||||
# gha_job_startup_duration_seconds:
|
|
||||||
# labels:
|
|
||||||
# ["repository", "organization", "enterprise", "job_name", "event_name","job_workflow_ref", "job_workflow_name", "job_workflow_target"]
|
|
||||||
# buckets:
|
|
||||||
# [
|
|
||||||
# 0.01,
|
|
||||||
# 0.05,
|
|
||||||
# 0.1,
|
|
||||||
# 0.5,
|
|
||||||
# 1.0,
|
|
||||||
# 2.0,
|
|
||||||
# 3.0,
|
|
||||||
# 4.0,
|
|
||||||
# 5.0,
|
|
||||||
# 6.0,
|
|
||||||
# 7.0,
|
|
||||||
# 8.0,
|
|
||||||
# 9.0,
|
|
||||||
# 10.0,
|
|
||||||
# 12.0,
|
|
||||||
# 15.0,
|
|
||||||
# 18.0,
|
|
||||||
# 20.0,
|
|
||||||
# 25.0,
|
|
||||||
# 30.0,
|
|
||||||
# 40.0,
|
|
||||||
# 50.0,
|
|
||||||
# 60.0,
|
|
||||||
# 70.0,
|
|
||||||
# 80.0,
|
|
||||||
# 90.0,
|
|
||||||
# 100.0,
|
|
||||||
# 110.0,
|
|
||||||
# 120.0,
|
|
||||||
# 150.0,
|
|
||||||
# 180.0,
|
|
||||||
# 210.0,
|
|
||||||
# 240.0,
|
|
||||||
# 300.0,
|
|
||||||
# 360.0,
|
|
||||||
# 420.0,
|
|
||||||
# 480.0,
|
|
||||||
# 540.0,
|
|
||||||
# 600.0,
|
|
||||||
# 900.0,
|
|
||||||
# 1200.0,
|
|
||||||
# 1800.0,
|
|
||||||
# 2400.0,
|
|
||||||
# 3000.0,
|
|
||||||
# 3600.0,
|
|
||||||
# ]
|
|
||||||
# gha_job_execution_duration_seconds:
|
|
||||||
# labels:
|
|
||||||
# [
|
|
||||||
# "repository",
|
|
||||||
# "organization",
|
|
||||||
# "enterprise",
|
|
||||||
# "job_name",
|
|
||||||
# "event_name",
|
|
||||||
# "job_result",
|
|
||||||
# "job_workflow_ref",
|
|
||||||
# "job_workflow_name",
|
|
||||||
# "job_workflow_target"
|
|
||||||
# ]
|
|
||||||
# buckets:
|
|
||||||
# [
|
|
||||||
# 0.01,
|
|
||||||
# 0.05,
|
|
||||||
# 0.1,
|
|
||||||
# 0.5,
|
|
||||||
# 1.0,
|
|
||||||
# 2.0,
|
|
||||||
# 3.0,
|
|
||||||
# 4.0,
|
|
||||||
# 5.0,
|
|
||||||
# 6.0,
|
|
||||||
# 7.0,
|
|
||||||
# 8.0,
|
|
||||||
# 9.0,
|
|
||||||
# 10.0,
|
|
||||||
# 12.0,
|
|
||||||
# 15.0,
|
|
||||||
# 18.0,
|
|
||||||
# 20.0,
|
|
||||||
# 25.0,
|
|
||||||
# 30.0,
|
|
||||||
# 40.0,
|
|
||||||
# 50.0,
|
|
||||||
# 60.0,
|
|
||||||
# 70.0,
|
|
||||||
# 80.0,
|
|
||||||
# 90.0,
|
|
||||||
# 100.0,
|
|
||||||
# 110.0,
|
|
||||||
# 120.0,
|
|
||||||
# 150.0,
|
|
||||||
# 180.0,
|
|
||||||
# 210.0,
|
|
||||||
# 240.0,
|
|
||||||
# 300.0,
|
|
||||||
# 360.0,
|
|
||||||
# 420.0,
|
|
||||||
# 480.0,
|
|
||||||
# 540.0,
|
|
||||||
# 600.0,
|
|
||||||
# 900.0,
|
|
||||||
# 1200.0,
|
|
||||||
# 1800.0,
|
|
||||||
# 2400.0,
|
|
||||||
# 3000.0,
|
|
||||||
# 3600.0,
|
|
||||||
# ]
|
|
||||||
@@ -21,4 +21,3 @@
|
|||||||
.idea/
|
.idea/
|
||||||
*.tmproj
|
*.tmproj
|
||||||
.vscode/
|
.vscode/
|
||||||
tests/
|
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
suite: "AutoscalingRunnerSet"
|
|
||||||
templates:
|
|
||||||
- autoscalingrunnserset.yaml
|
|
||||||
tests:
|
|
||||||
- it: should render base labels
|
|
||||||
set:
|
|
||||||
scaleset.name: "test"
|
|
||||||
auth.url: "https://github.com/org"
|
|
||||||
auth.githubToken: "gh_"
|
|
||||||
Reference in New Issue
Block a user