25 Commits

Author SHA1 Message Date
Aarnav Tale
3ed17e8ff6 chore: v1.0.8 2023-01-25 01:00:21 -05:00
Aarnav Tale
4e7c8bb981 fix: use correct post file 2023-01-25 01:00:12 -05:00
Aarnav Tale
c6e917eb5e fix: parse the latest flag properly 2023-01-25 01:00:04 -05:00
Aarnav Tale
7446d29d60 feat: implement github actions for testing 2023-01-25 00:58:09 -05:00
Aarnav Tale
22ac3ce88d chore: add license and update readme 2023-01-25 00:51:07 -05:00
Aarnav Tale
8a18fa720b fix: actually push tags 2023-01-25 00:45:20 -05:00
Aarnav Tale
11bbbb9207 chore: v1.0.7 2023-01-25 00:45:01 -05:00
Aarnav Tale
574fbc2143 fix: make action run using node16 2023-01-25 00:44:53 -05:00
Aarnav Tale
b284f0ba18 fix: add tagging on the push command 2023-01-25 00:43:59 -05:00
Aarnav Tale
558e44eea4 chore: v1.0.6 2023-01-25 00:41:12 -05:00
Aarnav Tale
29d331ef6a feat: add new tag pushing 2023-01-25 00:41:05 -05:00
Aarnav Tale
28eb8b8850 chore: switch default version of kubectl to 'latest' 2023-01-25 00:33:55 -05:00
Aarnav Tale
692ba3e286 feat: implement version lifecycle hook to build dist 2023-01-25 00:33:03 -05:00
Aarnav Tale
c368992ffb feat: implement the action in typescript 2023-01-25 00:30:36 -05:00
Aarnav Tale
880d48e290 chore: create npm project 2023-01-25 00:28:53 -05:00
Aarnav Tale
1b27c62a93 chore: add initial project files for typescript conversion 2023-01-25 00:28:40 -05:00
Aarnav Tale
25403f865e fix: move to /tmp/bin for kubectl location 2023-01-06 12:31:02 -05:00
Aarnav Tale
f6e83f6681 chore: bump default version to 1.26 2023-01-06 12:25:02 -05:00
Aarnav Tale
b88fbf4ad6 chore: bump default kubectl version to 1.25.0 2022-09-04 11:54:55 -04:00
Aarnav Tale
fe5edd2387 feat: revert back to original system 2022-06-27 03:13:27 -04:00
Aarnav Tale
50d08134cc fix: use printf instead of cat 2022-06-27 03:09:11 -04:00
Aarnav Tale
1c88fc9f2b fix: actually write to file on b64 2022-06-27 03:04:28 -04:00
Aarnav Tale
16b4bea4f4 fix: workaround github actions not decoding properly 2022-06-27 02:50:47 -04:00
Aarnav Tale
34de7de05e fix: kubectl version is now properly set 2022-06-27 02:34:59 -04:00
Aarnav Tale
f326ba7d79 fix: add scripts to github actions path 2022-05-14 22:50:16 -04:00
20 changed files with 4053 additions and 29 deletions

3
.eslintrc Normal file
View File

@@ -0,0 +1,3 @@
{
"extends": "tale"
}

16
.github/workflows/test.yaml vendored Normal file
View File

@@ -0,0 +1,16 @@
name: Kubectl Action
on:
push:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Setup tale/kubectl-action
uses: tale/kubectl-action@v1
with:
base64-kube-config: ${{ secrets.KUBE_CONFIG }}
- name: Test the output of `kubectl cluster-info`
run: kubectl cluster-info

1
.gitignore vendored Normal file
View File

@@ -0,0 +1 @@
node_modules/

5
.vscode/settings.json vendored Normal file
View File

@@ -0,0 +1,5 @@
{
"editor.codeActionsOnSave": {
"source.fixAll.eslint": true
}
}

21
LICENSE Normal file
View File

@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2023 Aarnav Tale
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

View File

@@ -1,8 +1,11 @@
# kubectl-action
GitHub Action to manage a K8s (Kubernetes) cluster using kubectl.
# Usage
## Usage
To use this action, add the following step to your GitHub Action workflow:
```yaml
- uses: tale/kubectl-action@v1
with:
@@ -11,7 +14,8 @@ To use this action, add the following step to your GitHub Action workflow:
Keep in mind that the action expects a base64 encoded string of your Kubernetes configuration. The simplest way to do that is to run `cat $HOME/.kube/config | base64` and save that output as an action secret.
It's also possible to specify the version of the [kubectl](https://kubernetes.io/docs/reference/kubectl/) CLI to use. The current default release used by this action is `v1.23.0`.
It's also possible to specify the version of the [kubectl](https://kubernetes.io/docs/reference/kubectl/) CLI to use. The current default release used by this action is the latest version.
```yaml
- uses: tale/kubectl-action@v1
with:
@@ -20,6 +24,7 @@ It's also possible to specify the version of the [kubectl](https://kubernetes.io
```
Once you've completed this setup, you have direct access to the `kubectl` binary and command in the rest of your actions. Here's a full example to give you some inspiration:
```yaml
name: Kubectl Action

View File

@@ -8,18 +8,11 @@ inputs:
kubectl-version:
description: Version of the kubectl CLI to use
required: false
default: v1.23.0
default: latest
base64-kube-config:
description: A base64 encoded reference to your authorization file (~/.kube/config)
required: true
runs:
using: composite
steps:
- name: Configure kubectl CLI
run: setup-kubectl.sh
shell: bash
- name: Authorize kubectl to the cluster
run: login-kubectl.sh
shell: bash
env:
BASE64_KUBE_CONFIG: ${{ inputs.base64-kube-config }}
using: node16
main: dist/index.js
post: dist/index.js

4
dist/index.js vendored Normal file

File diff suppressed because one or more lines are too long

1
dist/index.js.map vendored Normal file

File diff suppressed because one or more lines are too long

142
dist/licenses.txt vendored Normal file
View File

@@ -0,0 +1,142 @@
@actions/core
MIT
The MIT License (MIT)
Copyright 2019 GitHub
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
@actions/http-client
MIT
Actions Http Client for Node.js
Copyright (c) GitHub, Inc.
All rights reserved.
MIT License
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and
associated documentation files (the "Software"), to deal in the Software without restriction,
including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense,
and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so,
subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED *AS IS*, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT
LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
busboy
MIT
Copyright Brian White. All rights reserved.
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to
deal in the Software without restriction, including without limitation the
rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
sell copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
IN THE SOFTWARE.
streamsearch
MIT
Copyright Brian White. All rights reserved.
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to
deal in the Software without restriction, including without limitation the
rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
sell copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
IN THE SOFTWARE.
tunnel
MIT
The MIT License (MIT)
Copyright (c) 2012 Koichi Kobayashi
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in
all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
THE SOFTWARE.
undici
MIT
MIT License
Copyright (c) Matteo Collina and Undici contributors
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
uuid
MIT
The MIT License (MIT)
Copyright (c) 2010-2020 Robert Kieffer and other contributors
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

1
dist/sourcemap-register.js vendored Normal file

File diff suppressed because one or more lines are too long

View File

@@ -1,7 +0,0 @@
#!/usr/bin/env bash
if [ ! -d "$HOME/.kube" ]; then
mkdir -p $HOME/.kube
fi
echo "$BASE64_KUBE_CONFIG" | base64 -d > $HOME/.kube/config

22
package.json Normal file
View File

@@ -0,0 +1,22 @@
{
"name": "kubectl-action",
"version": "1.0.8",
"scripts": {
"dev": "ncc -smw --license licenses.txt build src/main.ts",
"build": "ncc -sm --license licenses.txt build src/main.ts",
"push": "np --no-cleanup --no-publish --no-tests --message 'chore: v%s' && git tag --force v1 && git push -f --tags",
"version": "pnpm run build && git add dist"
},
"dependencies": {
"@actions/core": "^1.10.0",
"undici": "^5.16.0"
},
"devDependencies": {
"@types/node": "^18.11.18",
"@vercel/ncc": "^0.36.0",
"eslint": "^8.32.0",
"eslint-config-tale": "^1.0.15",
"np": "^7.6.3",
"typescript": "^4.9.4"
}
}

3630
pnpm-lock.yaml generated Normal file

File diff suppressed because it is too large Load Diff

View File

@@ -1,9 +0,0 @@
#!/usr/bin/env bash
curl -LO "https://dl.k8s.io/release/${{ inputs.kubectl-version }}/bin/linux/amd64/kubectl"
curl -LO "https://dl.k8s.io/${{ inputs.kubectl-version }}/bin/linux/amd64/kubectl.sha256"
echo "$(cat kubectl.sha256) kubectl" | sha256sum --check
mkdir $GITHUB_WORKSPACE/bin
mv kubectl $GITHUB_WORKSPACE/bin
echo "$GITHUB_WORKSPACE/bin" >> $GITHUB_PATH

28
src/login.ts Normal file
View File

@@ -0,0 +1,28 @@
import { mkdir, writeFile } from 'node:fs/promises'
import { join } from 'node:path'
import { env } from 'node:process'
import { debug, getInput, saveState, setFailed } from '@actions/core'
export async function setupKubeconfig() {
debug('Running kubectl-action setupKubeconfig()')
if (env.HOME === undefined) {
setFailed('$HOME is not defined')
return
}
const config = getInput('base64-kube-config', {
required: true,
trimWhitespace: true
})
const decoded = Buffer.from(config, 'base64')
.toString('utf8')
const path = join(env.HOME, '.kube')
saveState('kubeconfig-path', path)
await mkdir(path, { recursive: true })
await writeFile(join(path, 'config'), decoded, 'utf8')
}

14
src/main.ts Normal file
View File

@@ -0,0 +1,14 @@
/* eslint-disable unicorn/prefer-top-level-await */
import { debug, getState, setFailed } from '@actions/core'
import { installKubectl } from 'setup'
const post = Boolean(getState('isPost'))
if (!post) {
debug('Running kubectl-action setup')
installKubectl()
.catch(error => {
setFailed('Failed to install kubectl (this is a bug in kubectl-action): ')
debug(JSON.stringify(error))
})
}

126
src/setup.ts Normal file
View File

@@ -0,0 +1,126 @@
import { createHash, randomUUID } from 'node:crypto'
import { createWriteStream } from 'node:fs'
import { mkdir } from 'node:fs/promises'
import { join } from 'node:path'
import { env, stdout } from 'node:process'
import { Readable } from 'node:stream'
import { addPath, debug, getInput, saveState, setFailed, warning } from '@actions/core'
import { fetch } from 'undici'
export async function installKubectl() {
debug('Running kubectl-action installKubectl()')
if (env.RUNNER_TEMP === undefined) {
setFailed('$RUNNER_TEMP is not defined')
return
}
const input = getInput('kubectl-version', {
required: false,
trimWhitespace: true
})
const version = input === 'latest' ? await fetchLatestVersion() : input
if (!version?.startsWith('v')) {
setFailed('Unable to determine the `kubectl` version to install')
return
}
console.log(`Installing kubectl version ${version}`)
const kubectl = await downloadKubectl(version)
if (!kubectl) {
return
}
const path = join(env.RUNNER_TEMP, randomUUID())
await mkdir(path, { recursive: true })
saveState('kubectl-path', path)
const stream = createWriteStream(join(path, 'kubectl'))
kubectl.pipe(stream)
console.log(`Installing kubectl to ${path}`)
await new Promise<void>((resolve, reject) => {
stream.on('finish', resolve)
stream.on('error', reject)
})
addPath(path)
}
// Fetches the latest kubectl version from the Kubernetes release server
async function fetchLatestVersion() {
const response = await fetch('https://dl.k8s.io/release/stable.txt')
if (!response.ok) {
setFailed(`Failed to fetch latest kubectl version with status ${response.status}`)
return
}
const version = await response.text()
return version.trim()
}
// Downloads the kubectl binary from the Kubernetes release server
// Also runs a checksum verification on the downloaded binary
async function downloadKubectl(version: string) {
const url = `https://dl.k8s.io/release/${version}/bin/linux/amd64/kubectl`
const hashUrl = `${url}.sha256`
console.log(`Downloading kubectl (${url})`)
const hashResponse = await fetch(hashUrl)
if (!hashResponse.ok) {
warning(`Skipping checksum verification for kubectl ${version}`)
}
const hash = hashResponse.ok ? await hashResponse.text() : ''
const response = await fetch(url)
if (!response.ok || !response.body) {
setFailed(`Failed to download kubectl with status ${response.status}`)
return
}
const hashStream = createHash('sha256')
const body = Readable.fromWeb(response.body)
const size = Number(response.headers.get('content-length'))
return new Promise<Readable | void>((resolve, reject) => {
let downloaded = 0
let progressed = 0
body.on('data', (chunk: Buffer) => {
hashStream.update(chunk)
downloaded += chunk.length
if (Math.floor((downloaded / size) * 80) > progressed) {
stdout.clearLine(0)
stdout.cursorTo(0)
progressed++
stdout.write(`[${'='.repeat(progressed)}>${' '.repeat(80 - progressed)}]`)
}
})
body.on('end', () => {
stdout.clearLine(0)
stdout.cursorTo(0)
console.log(`[${'='.repeat(80)}]`)
const hashSum = hashStream.digest('hex')
if (hashResponse.ok && hashSum !== hash) {
setFailed(`Checksum verification failed for kubectl ${version}`)
resolve()
}
resolve(body)
})
body.on('error', reject)
})
}

14
src/teardown.ts Normal file
View File

@@ -0,0 +1,14 @@
import { rm } from 'node:fs/promises'
import { debug, getState } from '@actions/core'
export async function teardown() {
debug('Running kubectl-action teardown()')
console.log('Removing kubectl and kubeconfig')
const path = getState('kubectl-path')
await rm(path, { recursive: true, force: true })
const configPath = getState('kubeconfig-path')
await rm(configPath, { recursive: true, force: true })
}

14
tsconfig.json Normal file
View File

@@ -0,0 +1,14 @@
{
"exclude": ["dist"],
"compilerOptions": {
"baseUrl": "./src",
"rootDir": "./src",
"outDir": "./dist",
"target": "ESNext",
"module": "CommonJS",
"moduleResolution": "Node",
"skipLibCheck": true,
"strict": true,
"noEmit": true
}
}