9b3fa83dac
Container entrypoints were rendered as `fmt.Sprintf` shell strings in Go, so every entrypoint fix needed a full operator release, nothing was shellcheckable, and the escaping was a hazard. How: - Add a `kea-init` initContainer that finalises the per-pod config and bounded-waits for HA peer DNS, replacing the in-entrypoint retry. It hardens the shared run dir to 0750, substitutes `this-server-name` from the pod ordinal (`POD_NAME` via the downward API), stages both configs into the shared emptyDir, and gates on `kea-dhcp4 -t` (60x2s) — failing loud after the cap so the kubelet restarts it instead of starting a doomed server. - Run the main kea-dhcp4 / kea-ctrl-agent containers with kea exec'd directly, dropping both wrapper shells. - Replace the two `fmt.Sprintf` entrypoints with a single committed `internal/kea/scripts/init.sh` embedded via `go:embed` and parameterised entirely by env vars — no Go string interpolation. - Add a shellcheck step to the pre-commit pipeline. Test: - Assert the pod shape: one kea-init initContainer, POD_NAME from the downward API, main containers exec kea directly, and the ConfigMap carries init.sh (not the old per-container entrypoints). - Assert init.sh hardens the socket dir, gates on `kea-dhcp4 -t`, fails loud after the cap, and is free of fmt verbs. - shellcheck the embedded script.
35 lines
755 B
YAML
35 lines
755 B
YAML
when:
|
|
- event: pull_request
|
|
|
|
steps:
|
|
- name: pre-commit
|
|
image: golang:1.25
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: kea-operator-ci
|
|
resources:
|
|
requests:
|
|
memory: 512Mi
|
|
cpu: "1"
|
|
limits:
|
|
memory: 2Gi
|
|
cpu: "2"
|
|
commands:
|
|
- test -z "$(gofmt -l .)"
|
|
- go vet ./...
|
|
|
|
- name: shellcheck
|
|
image: koalaman/shellcheck-alpine:stable
|
|
backend_options:
|
|
kubernetes:
|
|
serviceAccountName: kea-operator-ci
|
|
resources:
|
|
requests:
|
|
memory: 256Mi
|
|
cpu: "500m"
|
|
limits:
|
|
memory: 512Mi
|
|
cpu: "1"
|
|
commands:
|
|
- shellcheck --shell=sh internal/kea/scripts/*.sh
|