Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 64 additions & 0 deletions .github/workflows/image.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
name: Image

# Replaces the Prow job post-plantbuild-image-build.
on:
push:
branches:
- master
# GitHub does not apply the paths filter to tag pushes.
tags:
- 'v*'
paths:
- 'jsonnetlib/**'
- 'entry.sh'
- 'Dockerfile'
- 'fmt-check.sh'
- 'fmt-update.sh'
- '.github/workflows/image.yaml'

permissions:
contents: read
packages: write

concurrency:
group: image-${{ github.ref }}
cancel-in-progress: false

jobs:
push:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# The same tags that `plantbuild push` gave: the short commit hash,
# latest for master, and the git tag name for a tag push.
- id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: ghcr.io/theplant/plantbuild
tags: |
type=sha,prefix=,format=short
type=raw,value=latest,enable={{is_default_branch}}
type=ref,event=tag

# GITHUB_TOKEN can push when the package gives this repository write
# access.
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
# We do not verify attestations, and they make a new image index
# for the same content. plantbuild disables them for this reason.
provenance: false
cache-from: type=gha
cache-to: type=gha,mode=max
34 changes: 34 additions & 0 deletions .github/workflows/jsonnet-verify.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
name: Jsonnet verify

# Replaces the Prow jobs pull-plantbuild-jsonnet-verify and
# post-plantbuild-jsonnet-verify.
on:
pull_request:
paths:
- '**.jsonnet'
push:
branches:
- master
paths:
- '**.jsonnet'

permissions:
contents: read

env:
# Keep this version the same as JSONNET_VERSION in the Dockerfile, so
# that the check and the jsonnetfmt in the image agree on the format.
JSONNET_VERSION: 0.22.0

jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- run: |
curl -fsSL "https://github.com/google/go-jsonnet/releases/download/v${JSONNET_VERSION}/go-jsonnet_${JSONNET_VERSION}_linux_amd64.tar.gz" |
tar -xz -C "$RUNNER_TEMP" jsonnetfmt
echo "$RUNNER_TEMP" >>"$GITHUB_PATH"

- run: hack/verify-jsonnet.sh
29 changes: 29 additions & 0 deletions .github/workflows/test.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
name: Test

# Replaces the Prow jobs pull-plantbuild-test and post-plantbuild-test.
on:
pull_request:
push:
branches:
- master

permissions:
contents: read

env:
# Keep this version the same as JSONNET_VERSION in the Dockerfile, so
# that the tests use the jsonnet of the image.
JSONNET_VERSION: 0.22.0

jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- run: |
curl -fsSL "https://github.com/google/go-jsonnet/releases/download/v${JSONNET_VERSION}/go-jsonnet_${JSONNET_VERSION}_linux_amd64.tar.gz" |
tar -xz -C "$RUNNER_TEMP" jsonnet
echo "$RUNNER_TEMP" >>"$GITHUB_PATH"

- run: ./test.sh
28 changes: 14 additions & 14 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,20 +1,20 @@
ARG GO_VERSION=1.24
ARG JSONNET_VERSION=v0.18.0
ARG JSONNET_VERSION=v0.22.0

# ---- builder: compile jsonnet + jsonnetfmt ----
FROM golang:${GO_VERSION}-alpine AS jsonnet-builder
ARG JSONNET_VERSION
RUN apk add --no-cache git
RUN --mount=type=cache,target=/go/pkg/mod \
--mount=type=cache,target=/root/.cache/go-build \
go install github.com/google/go-jsonnet/cmd/jsonnet@${JSONNET_VERSION} && \
go install github.com/google/go-jsonnet/cmd/jsonnetfmt@${JSONNET_VERSION}

# ---- runtime: Alpine ----
FROM alpine:3.22
ARG JSONNET_VERSION
# Set by BuildKit to the architecture of the image, for example amd64.
ARG TARGETARCH
RUN apk add --no-cache ca-certificates
COPY --from=jsonnet-builder /go/bin/jsonnet /usr/local/bin/jsonnet
COPY --from=jsonnet-builder /go/bin/jsonnetfmt /usr/local/bin/jsonnetfmt
# The go-jsonnet release binaries are statically linked, so they run on
# Alpine. Download them in place of a compile with Go to build faster.
RUN set -eu; \
url=https://github.com/google/go-jsonnet/releases/download/${JSONNET_VERSION}; \
file=go-jsonnet_${JSONNET_VERSION#v}_linux_${TARGETARCH}.tar.gz; \
cd /tmp; \
wget -q "$url/$file" "$url/checksums.txt"; \
grep " $file\$" checksums.txt | sha256sum -c -; \
tar -xzof "$file" -C /usr/local/bin jsonnet jsonnetfmt; \
rm "$file" checksums.txt

ENV JSONNET_PATH=/jsonnetlib
ADD ./jsonnetlib /jsonnetlib
Expand Down
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -231,6 +231,8 @@ Checkout [Examples](https://github.com/theplant/plantbuild/tree/master/example)

### Testing

`test.sh` needs [`jsonnet`](https://github.com/google/go-jsonnet/releases) on `PATH`.

```
bash test.sh
bash test_with_kubectl.sh
Expand Down
5 changes: 0 additions & 5 deletions build.jsonnet

This file was deleted.

5 changes: 0 additions & 5 deletions build.sh

This file was deleted.

2 changes: 1 addition & 1 deletion hack/update-jsonnet.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/usr/bin/env sh
#!/usr/bin/env bash

set -o errexit
set -o nounset
Expand Down
2 changes: 1 addition & 1 deletion hack/verify-jsonnet.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/usr/bin/env sh
#!/usr/bin/env bash

set -o errexit
set -o nounset
Expand Down
37 changes: 25 additions & 12 deletions test.sh
Original file line number Diff line number Diff line change
@@ -1,27 +1,40 @@
#!/bin/bash

if which jsonnet; then
printf "Formatting code"
if find . -name '*.jsonnet' | xargs jsonnetfmt -i; then
echo ", Done"
fi
# Run the test cases with jsonnet against ./jsonnetlib, with the same
# arguments that entry.sh gives in the plantbuild image. Put jsonnet on
# PATH first.

if ! command -v jsonnet >/dev/null; then
echo "jsonnet not found, install it from https://github.com/google/go-jsonnet/releases"
exit 1
fi

githash7=$(git rev-parse HEAD | cut -c 1-7)

# show <jsonnet file> [-v <version>], the same as `plantbuild show`
show() {
local file=$1 version=$githash7 opt OPTIND=1
shift
while getopts "v:" opt; do
case $opt in
v) version=$OPTARG ;;
*) return 1 ;;
esac
done
jsonnet -J jsonnetlib -V VERSION="$version" "$file"
}

fail() {
echo "FAILED:" $1
exit 1
}

## Build
echo "Building"
./plantbuild build ./build.jsonnet

## Tests
for c in $(cat ./test_cases.json | jq -r '.[] | @base64'); do
show_args=$(echo $c | base64 --decode | jq -r '.show_args')
printf "\n\n"
echo "Testing ./plantbuild show $show_args"
result=$(./plantbuild show $show_args)
echo "Testing show $show_args"
result=$(show $show_args)
for assert in $(echo $c | base64 --decode | jq -r '.asserts[] | @base64'); do
jq_path=$(echo $assert | base64 --decode | jq -r '.jq_path')
expected=$(echo $assert | base64 --decode | jq -r '.expected')
Expand All @@ -35,7 +48,7 @@ for c in $(cat ./test_cases.json | jq -r '.[] | @base64'); do
printf "\n==expected==\n$expected\n"
printf "\n==actual==\n$actual\n"
diff -B <(printf "$actual\n") <(printf "$expected\n")
fail "./plantbuild show $show_args"
fail "show $show_args"
fi
done
done
Expand Down
Loading