Skip to content

Commit 9b48aa9

Browse files
jeffcasavantkrosenberg-kududynRoastBeefKazenzakiskanno41bamsammich
committed
Competition API open source release
Co-authored-by: jeffcasavant <jcasavant@kududyn.com> Co-authored-by: krosenberg-kududyn <krosenberg@kududyn.com> Co-authored-by: RoastBeefKazenzakis <horatiohawk@yahoo.com> Co-authored-by: kanno41 <kanno41@gmail.com> Co-authored-by: bamsammich <thuddleston@kududyn.com> Co-authored-by: hseachrist <hunterseachrist@gmail.com> Co-authored-by: svidovich <samuel.vidovich@gmail.com> Co-authored-by: jsillimank <jsilliman@kududyn.com> Co-authored-by: authwait <igoldthwaite@kududyn.com> Co-authored-by: Kane <justinl@kududyn.com>
0 parents  commit 9b48aa9

283 files changed

Lines changed: 40890 additions & 0 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.containerignore‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
**/Makefile
2+
**/Containerfile
3+
**/.direnv
4+
**/.devenv
5+
**/.DS_Store
6+
./.git
7+
./.github
8+
./infra/kube
9+
10+
**/.containerignore
11+
**/.gitignore
12+
**/.prettierignore
13+
README.md
14+
.envrc
15+
.devenv.flake.nix
16+
devenv.lock
17+
devenv.yaml
18+
devenv.nix
19+
.sops.yaml
20+
.sops.pub.asc
21+
container.mk
22+
codebook.toml

‎.envrc‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
eval "$(devenv direnvrc)"
2+
3+
use devenv

‎.github/linters/.gitleaks.toml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
[allowlist]
2+
# note: (global) regexTarget defaults to check the _Secret_ in the finding.
3+
# if regexTarget is not specified then _Secret_ will be used.
4+
# Acceptable values for regexTarget are "match" and "line"
5+
regexTarget = "match"
6+
regexes = [
7+
'''main-[0-9]{8}T[0-9]{6}Z''',
8+
]
9+
# note: stopwords targets the extracted secret, not the entire regex match
10+
# like 'regexes' does. (stopwords introduced in 8.8.0)
11+
stopwords = [
12+
'''client''',
13+
'''endpoint''',
14+
]

‎.github/workflows/images.yaml‎

Lines changed: 124 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,124 @@
1+
---
2+
name: Images
3+
on:
4+
push:
5+
branches:
6+
- main
7+
tags:
8+
- "*"
9+
10+
permissions:
11+
packages: write
12+
contents: read
13+
14+
env:
15+
REGISTRY_USER: ${{ github.actor }}
16+
REGISTRY_PASSWORD: ${{ github.token }}
17+
IMAGE_REGISTRY: ghcr.io/${{ github.repository_owner }}
18+
IMAGE_TAG: ${{ github.ref_name }}
19+
20+
jobs:
21+
lowercase:
22+
runs-on: ubuntu-latest
23+
outputs:
24+
image_registry: ${{ steps.lowercase.outputs.image_registry }}
25+
steps:
26+
- name: Lowercase image registry name
27+
id: lowercase
28+
run: |
29+
echo "image_registry=${IMAGE_REGISTRY,,}" >> "$GITHUB_OUTPUT"
30+
31+
compute-dir-matrix:
32+
runs-on: ubuntu-latest
33+
outputs:
34+
matrix: ${{ steps.compute-matrix.outputs.matrix }}
35+
steps:
36+
- name: Checkout
37+
uses: actions/checkout@v4
38+
with:
39+
fetch-depth: 0
40+
- name: Compute Matrix
41+
id: compute-matrix
42+
run: |
43+
dirs=$(make container-dirs | xargs -n 1 | jq -R . | jq -cs .)
44+
echo "matrix=${dirs}" >> "$GITHUB_OUTPUT"
45+
46+
compute-tags:
47+
runs-on: ubuntu-latest
48+
outputs:
49+
tags: ${{ steps.tags.outputs.tags }}
50+
steps:
51+
- name: Build image tags list
52+
id: tags
53+
run: |
54+
if [[ "${{ env.IMAGE_TAG }}" == "main" ]]; then
55+
echo 'tags=latest main-'"$(date -u +%Y%m%dT%H%M%SZ)" >> "$GITHUB_OUTPUT"
56+
else
57+
echo 'tags=${{ env.IMAGE_TAG }}' >> "$GITHUB_OUTPUT"
58+
fi
59+
60+
compute-changed-files:
61+
runs-on: ubuntu-latest
62+
outputs:
63+
changed-files: ${{ steps.processed.outputs.changed-files }}
64+
steps:
65+
- name: Checkout
66+
uses: actions/checkout@v4
67+
with:
68+
fetch-depth: 0
69+
- name: Get Changed Files
70+
id: changes
71+
uses: dorny/paths-filter@v3
72+
with:
73+
filters: |
74+
repo:
75+
- '**'
76+
list-files: "json"
77+
- name: Process
78+
id: processed
79+
run: |
80+
processed=$(echo '${{ steps.changes.outputs.repo_files }}' | jq -r '.[]' | xargs realpath | jq -R | jq -cs .)
81+
echo "changed-files=${processed}" > "$GITHUB_OUTPUT"
82+
images:
83+
needs:
84+
- compute-dir-matrix
85+
- compute-tags
86+
- compute-changed-files
87+
- lowercase
88+
runs-on: ubuntu-latest
89+
strategy:
90+
fail-fast: false
91+
matrix:
92+
dir: ${{ fromJSON(needs.compute-dir-matrix.outputs.matrix) }}
93+
steps:
94+
- name: Checkout
95+
uses: actions/checkout@v4
96+
with:
97+
fetch-depth: 0
98+
99+
- name: should-build
100+
id: should-build
101+
run: |
102+
if make should-build CONTAINER_DIRS='${{ matrix.dir }}' CHANGED_FILES='${{ needs.compute-changed-files.outputs.changed-files }}'; then should_build=1; else should_build=0; fi
103+
echo "should-build=${should_build}" > "$GITHUB_OUTPUT"
104+
105+
- name: Remove extras
106+
if: ${{ (steps.should-build.outputs.should-build == '1') || startsWith(github.ref, 'refs/tags') }}
107+
run: |
108+
sudo rm -rf "$AGENT_TOOLSDIRECTORY"
109+
110+
- name: Log in to ghcr.io
111+
if: ${{ (steps.should-build.outputs.should-build == '1') || startsWith(github.ref, 'refs/tags') }}
112+
uses: redhat-actions/podman-login@v1
113+
with:
114+
username: ${{ env.REGISTRY_USER }}
115+
password: ${{ env.REGISTRY_PASSWORD }}
116+
registry: ${{ needs.lowercase.outputs.image_registry }}
117+
118+
- name: podman build
119+
if: ${{ (steps.should-build.outputs.should-build == '1') || startsWith(github.ref, 'refs/tags') }}
120+
run: make podman-build CONTAINER_DIRS='${{ matrix.dir }}' IMAGE_TAGS='${{ needs.compute-tags.outputs.tags }}' IMAGE_LABELS='org.opencontainers.image.revision=${{ github.sha }}'
121+
122+
- name: podman push
123+
if: ${{ (steps.should-build.outputs.should-build == '1') || startsWith(github.ref, 'refs/tags') }}
124+
run: make podman-push CONTAINER_DIRS='${{ matrix.dir }}' IMAGE_TAGS='${{ needs.compute-tags.outputs.tags }}'

‎.github/workflows/lint.yaml‎

Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
---
2+
name: Lint
3+
on:
4+
pull_request:
5+
branches:
6+
- main
7+
permissions: read-all
8+
jobs:
9+
lint:
10+
runs-on: ubuntu-latest
11+
permissions:
12+
contents: read
13+
statuses: write
14+
steps:
15+
- name: Checkout
16+
uses: actions/checkout@v4
17+
with:
18+
fetch-depth: 0
19+
- name: Lint
20+
uses: super-linter/super-linter/slim@v7.4.0
21+
env:
22+
DEFAULT_BRANCH: "origin/main"
23+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
24+
# Kubeconform does not know about CRDs, so we have to ignore missing schemas
25+
KUBERNETES_KUBECONFORM_OPTIONS: "--ignore-missing-schemas --ignore-filename-pattern 'patch_.*.yaml'"
26+
VALIDATE_ALL_CODEBASE: false
27+
VALIDATE_ENV: false
28+
VALIDATE_JSCPD: false
29+
VALIDATE_CHECKOV: false
30+
VALIDATE_GO: false
31+
VALIDATE_GO_MODULES: false
32+
lint_go:
33+
runs-on: ubuntu-latest
34+
permissions:
35+
contents: read
36+
statuses: write
37+
steps:
38+
- name: Checkout
39+
uses: actions/checkout@v4
40+
with:
41+
fetch-depth: 0
42+
- name: Install Nix
43+
uses: cachix/install-nix-action@v26
44+
- name: Setup devenv Cache
45+
uses: cachix/cachix-action@v14
46+
with:
47+
name: devenv
48+
- name: Install devenv.sh
49+
run: nix profile install nixpkgs#devenv
50+
- name: Lint
51+
shell: devenv shell bash -- -e {0}
52+
run: |
53+
lint_go

‎.github/workflows/test.yaml‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
name: Upload Go test results
2+
3+
on: [push]
4+
5+
jobs:
6+
build:
7+
runs-on: ubuntu-latest
8+
strategy:
9+
matrix:
10+
go-version: ["1.24.x"]
11+
12+
steps:
13+
- uses: actions/checkout@v4
14+
- name: Setup Go
15+
uses: actions/setup-go@v5
16+
with:
17+
go-version: ${{ matrix.go-version }}
18+
cache-dependency-path: competition-api/go.sum
19+
- name: Install dependencies
20+
run: |
21+
cd competition-api
22+
go mod download
23+
- name: Test with Go
24+
run: |
25+
cd competition-api
26+
go test -json -cover ./... | tee TestResults-${{ matrix.go-version }}.json && exit "${PIPESTATUS[0]}"
27+
- name: Upload Go test results
28+
if: always()
29+
uses: actions/upload-artifact@v4
30+
with:
31+
name: Go-results-${{ matrix.go-version }}
32+
path: ./competition-api/TestResults-${{ matrix.go-version }}.json

‎.gitignore‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Devenv
2+
.devenv*
3+
devenv.local.nix
4+
5+
# direnv
6+
.direnv
7+
8+
# pre-commit
9+
.pre-commit-config.yaml
10+
11+
.DS_Store
12+
13+
codebook.toml
14+
15+
competition-api/dist
16+
17+
dind/images.tar.gz
18+
19+
.kind
20+
21+
infra/kube-local/competition-api-dev-local/sops/config.yaml

0 commit comments

Comments
 (0)