Skip to content

fix(ci): kubeconform retry + skip traefik CRDs#130

Merged
laminair merged 1 commit into
devfrom
fix/kubeconform-retries
Jul 9, 2026
Merged

fix(ci): kubeconform retry + skip traefik CRDs#130
laminair merged 1 commit into
devfrom
fix/kubeconform-retries

Conversation

@laminair

@laminair laminair commented Jul 9, 2026

Copy link
Copy Markdown
Collaborator

The kubeconform schema downloads from raw.githubusercontent.com are intermittently rate-limited (HTTP 429 / connection reset), causing the Lint + unit tests CI job to fail spuriously — as seen in PR #129 where both the push-triggered and PR-triggered runs hit this.

Fixes

  1. -skip Kind=IngressRoute and -skip Kind=Middleware — pre-emptively skip traefik CRD kinds that have no stock Kubernetes schema, so kubeconform never attempts (and fails) to download their schema files. -ignore-missing-schemas was supposed to handle these, but when the download attempt fails (network), kubeconform reports an error instead of treating it as "missing".

  2. Retry loop: 3 attempts with 10s back-off — absorbs transient network failures for standard k8s resource schemas (e.g. PodDisruptionBudget) that do have schemas but fail to download.

The kubeconform schema downloads from raw.githubusercontent.com are
intermittently rate-limited (HTTP 429 / connection reset), causing the
Lint + unit tests CI job to fail spuriously.

Two fixes:
1. -skip Kind=IngressRoute,Kind=Middleware — pre-emptively skip traefik
   CRD kinds that have no stock Kubernetes schema, so kubeconform never
   attempts (and fails) to download their schema files.
2. Retry loop: 3 attempts with 10s back-off to absorb transient network
   failures for standard k8s resource schemas (e.g. PodDisruptionBudget).
@codecov

codecov Bot commented Jul 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@laminair
laminair merged commit b8c53f5 into dev Jul 9, 2026
7 checks passed
@laminair
laminair deleted the fix/kubeconform-retries branch July 9, 2026 01:28
laminair added a commit that referenced this pull request Jul 9, 2026
The retry loop from #130 was insufficient — raw.githubusercontent.com
is persistently rate-limiting, causing all 3 attempts to fail.

Instead, download the kubernetes-json-schema tarball once (a single
request via github.com/.../archive/ CDN, not subject to the same
rate limits) and point kubeconform at local files with -schema-location.
This eliminates all per-resource HTTP downloads at validation time.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant