63 Commits
v1.0.4 ... main

Author SHA1 Message Date
Aarnav Tale
91f29e07f4 fix: aws example was incorrect 2024-06-05 22:46:34 -04:00
Aarnav Tale
efb34d6cb2 fix: use npm in ci 2024-03-19 20:51:30 -04:00
Aarnav Tale
767276df48 chore: v1.4.0 2024-03-19 20:49:56 -04:00
Aarnav Tale
2b874f780f chore: switch to npm 2024-03-19 20:47:55 -04:00
Aarnav Tale
716cfe229d feat: clobber the actual tag releases 2024-03-19 20:44:49 -04:00
Aarnav Tale
e93dd2d865 chore: turns out i cant indent 2024-02-06 01:38:40 -05:00
Aarnav Tale
9c4bb5002a chore: fix readme typo 2024-02-02 14:31:45 -05:00
Aarnav Tale
560e7ff9e2 chore: v1.3.0 2024-02-02 14:25:00 -05:00
Aarnav Tale
9685b6d613 chore: add aws example to readme 2024-02-02 14:16:41 -05:00
Aarnav Tale
c83ced7ece feat: update to node 20 and remove undici 2024-02-02 14:03:31 -05:00
Aarnav Tale
6e8a90cd56 fix: explicitly exit on windows runners 2024-02-02 14:03:09 -05:00
Aarnav Tale
5aa0d1bacd chore: v1.2.0 2023-06-28 22:16:04 -04:00
Aarnav Tale
93d421ead9 feat: use github actions env for windows check for extra resiliency 2023-06-28 22:15:24 -04:00
Aarnav Tale
e49d06518c feat: support arch and darwin/linux properly 2023-06-28 22:14:43 -04:00
Aarnav Tale
69c8dc994c chore: add better failure message for version resolving failures on kubectl 2023-06-28 22:09:13 -04:00
Aarnav Tale
e70828b58c fix: typo in teardown error message 2023-06-28 22:07:52 -04:00
Aarnav Tale
d7c0fa7a71 chore: update packages 2023-06-28 22:06:56 -04:00
Aarnav Tale
9d3c93f137 chore: v1.1.3 2023-02-15 14:56:50 -05:00
Aarnav Tale
ce29488755 feat: use actions tool-cache 2023-02-15 14:50:20 -05:00
Aarnav Tale
f08750dda0 fix: set permission to 775 not 755 2023-02-15 14:15:14 -05:00
Aarnav Tale
a3a1ddb586 revert: "fix: chmod with 775 after install (closes #4)"
This reverts commit b413e7e15e.
2023-02-15 13:45:10 -05:00
Aarnav Tale
b413e7e15e fix: chmod with 775 after install (closes #4) 2023-02-15 13:43:16 -05:00
Aarnav Tale
43525325f3 feat: block running on win32 2023-02-15 13:33:52 -05:00
Aarnav Tale
8c4badf72a chore: v1.1.2 2023-01-25 11:18:36 -05:00
Aarnav Tale
ff8bf47b42 feat: actually execute post action 2023-01-25 11:17:31 -05:00
Aarnav Tale
4933a15eb6 chore: v1.1.1 2023-01-25 11:10:14 -05:00
Aarnav Tale
c2bec5ff29 fix: deploy branch instead of v1 branch 2023-01-25 11:10:00 -05:00
Aarnav Tale
443c3cc7e1 chore: v1.1.0 2023-01-25 11:08:31 -05:00
Aarnav Tale
7eb54a9e39 fix: remove unnecessary lifecycle hook 2023-01-25 11:08:25 -05:00
Aarnav Tale
22c5cc3864 chore: reflect fixes in deploy task 2023-01-25 10:58:44 -05:00
Aarnav Tale
a0fc1ed3bf fix: maybe it works now 2023-01-25 10:56:26 -05:00
Aarnav Tale
9814a57069 feat: use actions/checkout to create push branch 2023-01-25 10:54:49 -05:00
Aarnav Tale
0597b11a08 fix: don't remove ignored directories 2023-01-25 10:49:49 -05:00
Aarnav Tale
0c2bcc2bf3 fix: resolve issues with actions 2023-01-25 10:44:34 -05:00
Aarnav Tale
aa17f278e9 feat: add dist to gitignore 2023-01-25 10:39:48 -05:00
Aarnav Tale
641b6b74db feat: create deploy ci 2023-01-25 10:39:31 -05:00
Aarnav Tale
c370e32093 fix: orphan branch to push 2023-01-25 10:31:06 -05:00
Aarnav Tale
d9fb2b8307 fix: use readline methods from node:readline to support node 16 2023-01-25 10:28:39 -05:00
Aarnav Tale
b061303a52 feat: build in a separate branch for testing 2023-01-25 10:24:46 -05:00
Aarnav Tale
d37d346399 fix: remove readable references as it only works in node 18 2023-01-25 10:18:56 -05:00
Aarnav Tale
36563347fa chore: build dist 2023-01-25 10:07:57 -05:00
Aarnav Tale
6ac935ba0c fix: run all actions 2023-01-25 10:07:45 -05:00
Aarnav Tale
f7e6d667ef fix: handle blank version 2023-01-25 10:07:23 -05:00
Aarnav Tale
34e21c7e3f feat: add more debug logging 2023-01-25 01:10:58 -05:00
Aarnav Tale
5fe2f65f42 test: use the latest branch for testing 2023-01-25 01:04:23 -05:00
Aarnav Tale
3ed17e8ff6 chore: v1.0.8 2023-01-25 01:00:21 -05:00
Aarnav Tale
4e7c8bb981 fix: use correct post file 2023-01-25 01:00:12 -05:00
Aarnav Tale
c6e917eb5e fix: parse the latest flag properly 2023-01-25 01:00:04 -05:00
Aarnav Tale
7446d29d60 feat: implement github actions for testing 2023-01-25 00:58:09 -05:00
Aarnav Tale
22ac3ce88d chore: add license and update readme 2023-01-25 00:51:07 -05:00
Aarnav Tale
8a18fa720b fix: actually push tags 2023-01-25 00:45:20 -05:00
Aarnav Tale
11bbbb9207 chore: v1.0.7 2023-01-25 00:45:01 -05:00
Aarnav Tale
574fbc2143 fix: make action run using node16 2023-01-25 00:44:53 -05:00
Aarnav Tale
b284f0ba18 fix: add tagging on the push command 2023-01-25 00:43:59 -05:00
Aarnav Tale
558e44eea4 chore: v1.0.6 2023-01-25 00:41:12 -05:00
Aarnav Tale
29d331ef6a feat: add new tag pushing 2023-01-25 00:41:05 -05:00
Aarnav Tale
28eb8b8850 chore: switch default version of kubectl to 'latest' 2023-01-25 00:33:55 -05:00
Aarnav Tale
692ba3e286 feat: implement version lifecycle hook to build dist 2023-01-25 00:33:03 -05:00
Aarnav Tale
c368992ffb feat: implement the action in typescript 2023-01-25 00:30:36 -05:00
Aarnav Tale
880d48e290 chore: create npm project 2023-01-25 00:28:53 -05:00
Aarnav Tale
1b27c62a93 chore: add initial project files for typescript conversion 2023-01-25 00:28:40 -05:00
Aarnav Tale
25403f865e fix: move to /tmp/bin for kubectl location 2023-01-06 12:31:02 -05:00
Aarnav Tale
f6e83f6681 chore: bump default version to 1.26 2023-01-06 12:25:02 -05:00
17 changed files with 8897 additions and 34 deletions

3
.eslintrc Normal file
View File

@@ -0,0 +1,3 @@
{
"extends": "tale"
}

29
.github/workflows/deploy.yaml vendored Normal file
View File

@@ -0,0 +1,29 @@
name: Deploy Action
on:
push:
tags:
- '*'
- '!v1'
jobs:
deploy:
name: Deploy
runs-on: ubuntu-latest
steps:
- name: Checkout Repository
uses: actions/checkout@v3
- name: Build latest dist/ folder
run: |
npm ci
npm run build
- name: Upload dist/ folder
run: |
git config --global user.email "<41898282+github-actions[bot]@users.noreply.github.com>"
git config --global user.name "github-actions[bot]"
git checkout --orphan deploy
git add -f dist README.md LICENSE action.yaml
git commit -m "chore: create ci release ($GITHUB_SHA)"
git tag --force v1
git tag --force $GITHUB_REF_NAME
git push -f --tags origin deploy

36
.github/workflows/test.yaml vendored Normal file
View File

@@ -0,0 +1,36 @@
name: Test Action
on:
push:
branches: [ main ]
jobs:
build:
name: Build
runs-on: ubuntu-latest
steps:
- name: Checkout Repository
uses: actions/checkout@v3
- name: Build latest dist/ folder
run: |
npm ci
npm run build
- name: Upload dist/ folder
run: |
git config --global user.email "<41898282+github-actions[bot]@users.noreply.github.com>"
git config --global user.name "github-actions[bot]"
git checkout --orphan ci
git add -f dist README.md LICENSE action.yaml
git commit -m "chore: create ci release ($GITHUB_SHA)"
git push -f origin ci
test:
name: Test
runs-on: ubuntu-latest
needs: build
steps:
- name: Setup tale/kubectl-action
uses: tale/kubectl-action@ci
with:
base64-kube-config: ${{ secrets.KUBE_CONFIG }}
- name: Test the output of `kubectl cluster-info`
run: kubectl cluster-info

2
.gitignore vendored Normal file
View File

@@ -0,0 +1,2 @@
node_modules/
dist/

5
.vscode/settings.json vendored Normal file
View File

@@ -0,0 +1,5 @@
{
"editor.codeActionsOnSave": {
"source.fixAll.eslint": true
}
}

21
LICENSE Normal file
View File

@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2023 Aarnav Tale
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

View File

@@ -1,17 +1,21 @@
# kubectl-action
GitHub Action to manage a K8s (Kubernetes) cluster using kubectl.
# Usage
## Usage
To use this action, add the following step to your GitHub Action workflow:
```yaml
- uses: tale/kubectl-action@v1
with:
base64-kube-config: ${{ secrets.KUBE_CONFIG }}
```
Keep in mind that the action expects a base64 encoded string of your Kubernetes configuration. The simplest way to do that is to run `cat $HOME/.kube/config | base64` and save that output as an action secret.
Keep in mind that the action expects a base64 encoded string of your Kubernetes configuration. The simplest way to do that is to run `cat $HOME/.kube/config | base64` and save that output as an action secret. It's additionally possible to generate a config file using the `aws` CLI for EKS or any other tools with other cloud providers.
It's also possible to specify the version of the [kubectl](https://kubernetes.io/docs/reference/kubectl/) CLI to use. The current default release used by this action is the latest version.
It's also possible to specify the version of the [kubectl](https://kubernetes.io/docs/reference/kubectl/) CLI to use. The current default release used by this action is `v1.25.0`.
```yaml
- uses: tale/kubectl-action@v1
with:
@@ -20,6 +24,7 @@ It's also possible to specify the version of the [kubectl](https://kubernetes.io
```
Once you've completed this setup, you have direct access to the `kubectl` binary and command in the rest of your actions. Here's a full example to give you some inspiration:
```yaml
name: Kubectl Action
@@ -35,3 +40,33 @@ jobs:
base64-kube-config: ${{ secrets.KUBE_CONFIG }}
- run: kubectl get pods
```
Here's an example using AWS EKS:
```yaml
name: Kubectl Action
on:
workflow_dispatch:
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
aws-region: us-east-2
- name: Generate kubeconfig
run: |
{
echo 'EKS_CREDS<<EOF'
aws eks update-kubeconfig --region us-east-2 --name my-cluster --dry-run | base64
echo EOF
} >> $GITHUB_ENV
- uses: tale/kubectl-action@v1
with:
base64-kube-config: ${{ env.EKS_CREDS }}
- run: kubectl get pods
```

View File

@@ -8,22 +8,11 @@ inputs:
kubectl-version:
description: Version of the kubectl CLI to use
required: false
default: v1.25.0
default: latest
base64-kube-config:
description: A base64 encoded reference to your authorization file (~/.kube/config)
required: true
runs:
using: composite
steps:
- run: echo "${{ github.action_path }}" >> $GITHUB_PATH
shell: bash
- name: Configure kubectl CLI
run: setup-kubectl.sh
shell: bash
env:
KUBECTL_VERSION: ${{ inputs.kubectl-version }}
- name: Authorize kubectl to the cluster
run: login-kubectl.sh
shell: bash
env:
BASE64_KUBE_CONFIG: ${{ inputs.base64-kube-config }}
using: node20
main: dist/index.js
post: dist/index.js

View File

@@ -1,7 +0,0 @@
#!/usr/bin/env bash
if [ ! -d "$HOME/.kube" ]; then
mkdir -p $HOME/.kube
fi
echo "$BASE64_KUBE_CONFIG" | base64 -d > $HOME/.kube/config

8564
package-lock.json generated Normal file

File diff suppressed because it is too large Load Diff

21
package.json Normal file
View File

@@ -0,0 +1,21 @@
{
"name": "kubectl-action",
"version": "1.4.0",
"scripts": {
"dev": "ncc -smw --license licenses.txt build src/main.ts",
"build": "ncc -sm --license licenses.txt build src/main.ts",
"push": "np --no-cleanup --no-publish --no-tests --message 'chore: v%s'"
},
"dependencies": {
"@actions/core": "^1.10.1",
"@actions/tool-cache": "^2.0.1"
},
"devDependencies": {
"@types/node": "^20.11.30",
"@vercel/ncc": "^0.38.1",
"eslint": "^8.57.0",
"eslint-config-tale": "^1.0.16",
"np": "^9.2.0",
"typescript": "^5.4.2"
}
}

View File

@@ -1,9 +0,0 @@
#!/usr/bin/env bash
curl -LO "https://dl.k8s.io/release/$KUBECTL_VERSION/bin/linux/amd64/kubectl"
curl -LO "https://dl.k8s.io/$KUBECTL_VERSION/bin/linux/amd64/kubectl.sha256"
echo "$(cat kubectl.sha256) kubectl" | sha256sum --check
mkdir $GITHUB_WORKSPACE/bin
mv kubectl $GITHUB_WORKSPACE/bin
echo "$GITHUB_WORKSPACE/bin" >> $GITHUB_PATH

28
src/login.ts Normal file
View File

@@ -0,0 +1,28 @@
import { mkdir, writeFile } from 'node:fs/promises'
import { join } from 'node:path'
import { env } from 'node:process'
import { debug, getInput, saveState, setFailed } from '@actions/core'
export async function setupKubeconfig() {
debug('Running kubectl-action setupKubeconfig()')
if (env.HOME === undefined) {
setFailed('$HOME is not defined')
return
}
const config = getInput('base64-kube-config', {
required: true,
trimWhitespace: true
})
const decoded = Buffer.from(config, 'base64')
.toString('utf8')
const path = join(env.HOME, '.kube')
saveState('kubeconfig-path', path)
await mkdir(path, { recursive: true })
await writeFile(join(path, 'config'), decoded, 'utf8')
}

36
src/main.ts Normal file
View File

@@ -0,0 +1,36 @@
import { env, exit, platform } from 'node:process'
import { debug, getState, setFailed } from '@actions/core'
import { setupKubeconfig } from 'login'
import { installKubectl } from 'setup'
import { teardown } from 'teardown'
if (env.RUNNER_OS === 'Windows' || platform === 'win32') {
setFailed('kubectl-action does not support Windows')
exit(1)
}
if (getState('kubectl-path')) {
debug('Running post kubectl-action setup')
teardown()
// eslint-disable-next-line unicorn/prefer-top-level-await
.catch(error => {
setFailed('Failed to teardown kubectl (this is a bug in kubectl-action): ')
debug(JSON.stringify(error))
})
} else {
debug('Running kubectl-action setup')
// eslint-disable-next-line no-async-promise-executor
new Promise(async () => {
await installKubectl()
debug('kubectl-action setup complete')
await setupKubeconfig()
debug('kubectl-action kubeconfig setup complete')
})
// eslint-disable-next-line unicorn/prefer-top-level-await
.catch(error => {
setFailed('Failed to install kubectl (this is a bug in kubectl-action): ')
debug(JSON.stringify(error))
})
}

85
src/setup.ts Normal file
View File

@@ -0,0 +1,85 @@
import { chmod } from 'node:fs/promises'
import { dirname, join } from 'node:path'
import { env } from 'node:process'
import { addPath, debug, getInput, setFailed } from '@actions/core'
import { cacheFile, downloadTool, find } from '@actions/tool-cache'
export async function installKubectl() {
debug('Running kubectl-action installKubectl()')
if (env.RUNNER_TEMP === undefined) {
setFailed('$RUNNER_TEMP is not defined')
return
}
const input = getInput('kubectl-version', {
required: false,
trimWhitespace: true
})
const version = input === 'latest' || input === '' ? await fetchLatestVersion() : input
debug(`kubectl-version: ${version ?? 'undefined'}`)
if (!version?.startsWith('v')) {
setFailed('Unable to determine the `kubectl` version to install')
return
}
console.log(`Installing kubectl version ${version}`)
try {
const path = await fetchKubectl(version)
await chmod(path, '775')
addPath(dirname(path))
debug(`kubectl ${version} installed and cached at ${path}`)
} catch {
debug('Failed to download kubectl from dl.k8s.io')
setFailed('Failed to download kubectl from dl.k8s.io\nPlease check the version you specified is valid')
}
}
// Fetches the latest kubectl version from the Kubernetes release server
async function fetchLatestVersion() {
const response = await fetch('https://dl.k8s.io/release/stable.txt')
if (!response.ok) {
setFailed(`Failed to fetch latest kubectl version with status ${response.status}`)
return
}
const version = await response.text()
return version.trim()
}
// Downloads the kubectl binary from the Kubernetes release server
// If already downloaded, returns the path to the cached binary
async function fetchKubectl(version: string) {
const cachedPath = find('kubectl', version)
// Cached path is a directory containing the kubectl binary
if (cachedPath) {
debug(`kubectl ${version} already installed`)
return join(cachedPath, 'kubectl')
}
const url = `https://dl.k8s.io/release/${version}/bin/${retrieveRunnerMetadata()}/kubectl`
console.log(`Downloading kubectl (${url})`)
const downloadPath = await downloadTool(url)
const toolPath = await cacheFile(downloadPath, 'kubectl', 'kubectl', version)
return join(toolPath, 'kubectl')
}
// Gets the proper architecture and OS for the current platform
// This doesn't use node functions, but instead CI variables provided by GitHub
function retrieveRunnerMetadata() {
// Currently we don't support win32 platforms anyways
const runnerSystem = env.RUNNER_OS === 'Linux' ? 'linux' : 'darwin'
const runnerArch = env.RUNNER_ARCH?.toLowerCase()
if (runnerArch?.includes('arm')) {
return `${runnerSystem}/arm64`
}
return `${runnerSystem}/amd64`
}

11
src/teardown.ts Normal file
View File

@@ -0,0 +1,11 @@
import { rm } from 'node:fs/promises'
import { debug, getState } from '@actions/core'
export async function teardown() {
debug('Running kubectl-action teardown()')
console.log('Removing kubeconfig')
const configPath = getState('kubeconfig-path')
await rm(configPath, { recursive: true, force: true })
}

14
tsconfig.json Normal file
View File

@@ -0,0 +1,14 @@
{
"exclude": ["dist"],
"compilerOptions": {
"baseUrl": "./src",
"rootDir": "./src",
"outDir": "./dist",
"target": "ESNext",
"module": "CommonJS",
"moduleResolution": "Node",
"skipLibCheck": true,
"strict": true,
"noEmit": true
}
}