Compare commits

...
6 Commits
Author SHA1 Message Date
Stephen KittandMike Kolesnik 4d54dd283e Add contents write permission on release
When releasing, since the job pushes to the git repository, it needs
to have write permission on "contents".

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2022-09-06 14:39:08 +03:00
Mike Kolesnik 5be04f2906 Adjust LH image overrides to use component names
Operator expects the component name, use it in the Submariner CR and not
the image name.

Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-09-06 14:25:30 +03:00
Stephen KittandThomas Pantelis 3eec2f8474 Check GHA updates weekly
The release frequency of some GHAs means we end up with daily
dependabot PRs, which results in lots of not-particularly-useful
review work. Reducing the update cadence to weekly shouldn't expose us
to much risk and will reduce PR churn.

Signed-off-by: Stephen Kitt <skitt@redhat.com>
2022-08-26 16:04:16 -04:00
Daniel FarrellandStephen Kitt e16a2c36df Minimize GHA permissions
Set the GitHub Actions token permission to null in most workflows.

This results in:

GITHUB_TOKEN Permissions
  Metadata: read

The default permissions, used without the null override, are either

GITHUB_TOKEN Permissions
  Actions: write
  Checks: write
  Contents: write
  Deployments: write
  Discussions: write
  Issues: write
  Metadata: read
  Packages: write
  Pages: write
  PullRequests: write
  RepositoryProjects: write
  SecurityEvents: write
  Statuses: write

or

GITHUB_TOKEN Permissions
  Actions: read
  Checks: read
  Contents: read
  Deployments: read
  Discussions: read
  Issues: read
  Metadata: read
  Packages: read
  Pages: read
  PullRequests: read
  RepositoryProjects: read
  SecurityEvents: read
  Statuses: read

Jobs triggered by PRs get read permissions, other jobs get write.

One job requires non-null permissions to function.

The dependent issues GHA needs PR/issues write permissions to add/remove
`dependent` labels. It needs status write permission to block/unblock
PRs when dependencies are missing/met. Fails with HttpError otherwise.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
2022-08-25 10:47:32 +02:00
Mike KolesnikandThomas Pantelis 01599cbb65 Add support for image overrides
Add support to override specific images (already supported by
submariner) to the helm chart.

Signed-off-by: Mike Kolesnik <mkolesni@redhat.com>
2022-08-22 08:07:25 -04:00
dependabot[bot]andThomas Pantelis a5401e6df0 Bump azure/setup-helm from 2.1 to 3.3
Bumps [azure/setup-helm](https://github.com/azure/setup-helm) from 2.1 to 3.3.
- [Release notes](https://github.com/azure/setup-helm/releases)
- [Commits](https://github.com/azure/setup-helm/compare/217bf70cbd2e930ba2e81ba7e1de2f7faecc42ba...b5b231a831f96336bbfeccc1329990f0005c5bb1)

---
updated-dependencies:
- dependency-name: azure/setup-helm
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-08-19 08:07:00 -04:00
11 changed files with 51 additions and 4 deletions
+3 -3
View File
@@ -4,14 +4,14 @@ updates:
- package-ecosystem: github-actions
directory: '/'
schedule:
interval: daily
interval: weekly
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.12"
schedule:
interval: daily
interval: weekly
- package-ecosystem: github-actions
directory: '/'
target-branch: "release-0.13"
schedule:
interval: daily
interval: weekly
+2
View File
@@ -4,6 +4,8 @@ name: Branch Checks
on:
pull_request:
permissions: {}
jobs:
target_branch:
name: PR targets branch
+5
View File
@@ -19,6 +19,11 @@ on:
schedule:
- cron: '0 0/6 * * *' # every 6 hours
permissions:
issues: write
pull-requests: write
statuses: write
jobs:
check:
name: Check Dependencies
+2
View File
@@ -5,6 +5,8 @@ on:
pull_request:
types: [labeled, opened, synchronize, reopened]
permissions: {}
jobs:
e2e:
name: E2E
+2
View File
@@ -4,6 +4,8 @@ name: End to End Default
on:
pull_request:
permissions: {}
jobs:
e2e:
name: E2E
+2
View File
@@ -5,6 +5,8 @@ on:
schedule:
- cron: "0 0 * * *"
permissions: {}
jobs:
e2e:
name: E2E
+3 -1
View File
@@ -4,6 +4,8 @@ name: Linting
on:
pull_request:
permissions: {}
jobs:
apply-suggestions-commits:
name: 'No "Apply suggestions from code review" Commits'
@@ -39,7 +41,7 @@ jobs:
uses: actions/checkout@2541b1294d2704b0964813337f33b291d3f8596b
- name: Set up Helm
uses: azure/setup-helm@217bf70cbd2e930ba2e81ba7e1de2f7faecc42ba
uses: azure/setup-helm@b5b231a831f96336bbfeccc1329990f0005c5bb1
with:
version: v3.6.0
+2
View File
@@ -5,6 +5,8 @@ on:
schedule:
- cron: "0 0 * * 0"
permissions: {}
jobs:
markdown-link-check-periodic:
name: Markdown Links (all files)
+3
View File
@@ -6,6 +6,9 @@ on:
branches:
- devel
permissions:
contents: write
jobs:
release:
name: Release
@@ -23,6 +23,32 @@ spec:
natEnabled: {{ .Values.submariner.natEnabled }}
repository: {{ .Values.submariner.images.repository }}
version: {{ .Values.submariner.images.tag }}
{{- with .Values.images }}
{{- if . }}
imageOverrides:
{{- if index . "submariner-operator" }}
submariner-operator: {{ index . "submariner-operator" }}
{{- end }}
{{- if index . "submariner-gateway" }}
submariner-gateway: {{ index . "submariner-gateway" }}
{{- end }}
{{- if index . "submariner-route-agent" }}
submariner-routeagent: {{ index . "submariner-route-agent" }}
{{- end }}
{{- if index . "submariner-globalnet" }}
submariner-globalnet: {{ index . "submariner-globalnet" }}
{{- end }}
{{- if index . "submariner-networkplugin-syncer" }}
submariner-networkplugin-syncer: {{ index . "submariner-networkplugin-syncer" }}
{{- end }}
{{- if index . "lighthouse-agent" }}
submariner-lighthouse-agent: {{ index . "lighthouse-agent" }}
{{- end }}
{{- if index . "lighthouse-coredns" }}
submariner-lighthouse-coredns: {{ index . "lighthouse-coredns" }}
{{- end }}
{{- end }}
{{- end }}
serviceCIDR: "{{ .Values.submariner.serviceCidr }}"
globalCIDR: "{{ .Values.submariner.globalCidr }}"
serviceDiscoveryEnabled: {{ .Values.submariner.serviceDiscovery }}
+1
View File
@@ -24,6 +24,7 @@ broker:
globalnet: false
rbac:
create: true
images: {}
ipsec:
psk: ""
debug: false