Skip to content

Commit 71c206f

Browse files
committed
Merge remote-tracking branch 'upstream/main' into okp-integration-1
2 parents ecd3199 + 1d3a9b5 commit 71c206f

22 files changed

Lines changed: 618 additions & 157 deletions

‎.dockerignore‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,3 +2,7 @@
22
# Ignore build and test binaries.
33
bin/
44
testbin/
5+
6+
# Hermetic build artifacts
7+
hermeto-cache/
8+
Dockerfile.hermeto
Lines changed: 189 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,189 @@
1+
# Copyright Red Hat, Inc.
2+
#
3+
# Licensed under the Apache License, Version 2.0 (the "License");
4+
# you may not use this file except in compliance with the License.
5+
# You may obtain a copy of the License at
6+
#
7+
# http://www.apache.org/licenses/LICENSE-2.0
8+
#
9+
# Unless required by applicable law or agreed to in writing, software
10+
# distributed under the License is distributed on an "AS IS" BASIS,
11+
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12+
# See the License for the specific language governing permissions and
13+
# limitations under the License.
14+
15+
name: Docker Build (Hermetic)
16+
description: Build operator image hermetically using Hermeto (offline/reproducible build)
17+
inputs:
18+
imageName:
19+
description: The full image name including registry (e.g., quay.io/rhdh-community/operator)
20+
required: true
21+
imageTags:
22+
description: The tags to apply to the image
23+
required: true
24+
imageLabels:
25+
description: The labels for the Docker image
26+
required: false
27+
platform:
28+
description: "Target given CPU platform architecture (default: linux/amd64)"
29+
required: false
30+
default: linux/amd64
31+
containerfilePath:
32+
description: Path to the Dockerfile to use
33+
required: false
34+
default: 'Dockerfile'
35+
skipArtifactUpload:
36+
description: Skip uploading the built image as a GitHub artifact
37+
required: false
38+
default: 'false'
39+
40+
runs:
41+
using: composite
42+
steps:
43+
- name: Extract metadata (tags, labels) for Docker
44+
id: meta
45+
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
46+
with:
47+
images: ${{ inputs.imageName }}
48+
tags: |
49+
${{ inputs.imageTags }}
50+
labels: |
51+
${{ inputs.imageLabels }}
52+
53+
- name: Ensure podman is available
54+
shell: bash
55+
run: |
56+
if ! command -v podman &>/dev/null; then
57+
echo "podman not found, installing..."
58+
sudo apt-get -y update && sudo apt-get -y install podman
59+
fi
60+
podman --version
61+
62+
- name: Set up hermetic build variables
63+
shell: bash
64+
run: |
65+
# renovate: datasource=docker depName=quay.io/konflux-ci/hermeto
66+
echo "HERMETO_IMAGE=quay.io/konflux-ci/hermeto:0.60.1" >> "$GITHUB_ENV"
67+
echo "LOCAL_CACHE_DIR=./hermeto-cache/operator" >> "$GITHUB_ENV"
68+
69+
- name: Restore hermeto dependency cache
70+
id: cache-deps
71+
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
72+
with:
73+
path: ./hermeto-cache/operator
74+
key: hermeto-deps-${{ inputs.platform }}-${{ hashFiles('go.mod', 'go.sum', 'rpms.lock.yaml') }}
75+
76+
- name: Fetch dependencies with hermeto
77+
if: steps.cache-deps.outputs.cache-hit != 'true'
78+
shell: bash
79+
run: |
80+
set -ex
81+
82+
mkdir -p "$LOCAL_CACHE_DIR"
83+
84+
echo "::group::Fetching dependencies with hermeto"
85+
podman run --rm -v "$PWD:/source:z" -v "$LOCAL_CACHE_DIR:/cachi2:z" -w /source "$HERMETO_IMAGE" \
86+
--log-level DEBUG \
87+
fetch-deps \
88+
--source . \
89+
--output /cachi2/output \
90+
'[{"type": "rpm", "path": "."}, {"type": "gomod", "path": "."}]'
91+
echo "::endgroup::"
92+
93+
if [ ! -d "$LOCAL_CACHE_DIR/output" ]; then
94+
echo "No output directory found after fetch-deps"
95+
exit 1
96+
fi
97+
98+
echo "::group::Generating environment file"
99+
podman run --rm -v "$PWD:/source:z" -v "$LOCAL_CACHE_DIR:/cachi2:z" -w /source "$HERMETO_IMAGE" \
100+
--log-level DEBUG \
101+
generate-env --format env \
102+
--output /cachi2/cachi2.env /cachi2/output
103+
echo "::endgroup::"
104+
105+
echo "::group::Injecting files"
106+
podman run --rm -v "$PWD:/source:z" -v "$LOCAL_CACHE_DIR:/cachi2:z" -w /source "$HERMETO_IMAGE" \
107+
--log-level DEBUG \
108+
inject-files /cachi2/output
109+
echo "::endgroup::"
110+
111+
- name: Generate env and inject files (cache hit)
112+
if: steps.cache-deps.outputs.cache-hit == 'true'
113+
shell: bash
114+
run: |
115+
set -ex
116+
echo "::group::Generating environment file from cached deps"
117+
podman run --rm -v "$PWD:/source:z" -v "$LOCAL_CACHE_DIR:/cachi2:z" -w /source "$HERMETO_IMAGE" \
118+
--log-level DEBUG \
119+
generate-env --format env \
120+
--output /cachi2/cachi2.env /cachi2/output
121+
echo "::endgroup::"
122+
123+
echo "::group::Injecting files from cached deps"
124+
podman run --rm -v "$PWD:/source:z" -v "$LOCAL_CACHE_DIR:/cachi2:z" -w /source "$HERMETO_IMAGE" \
125+
--log-level DEBUG \
126+
inject-files /cachi2/output
127+
echo "::endgroup::"
128+
129+
- name: Fix cache ownership for non-root buildah
130+
shell: bash
131+
run: |
132+
set -ex
133+
echo LOCAL_CACHE_DIR_REALPATH=$(realpath "$LOCAL_CACHE_DIR") >> "$GITHUB_ENV"
134+
sudo chown -R runner "$(realpath "$LOCAL_CACHE_DIR")"
135+
136+
- name: Transform Dockerfile for hermetic build
137+
shell: bash
138+
id: transform-containerfile
139+
env:
140+
CONTAINERFILE_PATH: ${{ inputs.containerfilePath }}
141+
TRANSFORMED_CONTAINERFILE: ${{ inputs.containerfilePath }}.hermeto
142+
run: |
143+
set -x
144+
145+
cp "$CONTAINERFILE_PATH" "$TRANSFORMED_CONTAINERFILE"
146+
147+
# Insert RPM repo replacement before every dnf/microdnf install
148+
sed -i '/RUN *\(dnf\|microdnf\) install/i RUN rm -r /etc/yum.repos.d/* && cp /cachi2/output/deps/rpm/$(uname -m)/repos.d/hermeto.repo /etc/yum.repos.d/' \
149+
"$TRANSFORMED_CONTAINERFILE"
150+
151+
# Prepend cachi2 env sourcing to every RUN command
152+
sed -i 's/^\s*RUN /RUN . \/cachi2\/cachi2.env \&\& /' "$TRANSFORMED_CONTAINERFILE"
153+
154+
echo "transformed_containerfile=$TRANSFORMED_CONTAINERFILE" >> "$GITHUB_OUTPUT"
155+
156+
- name: Build Docker Image
157+
id: build
158+
uses: redhat-actions/buildah-build@719e3c40d8af9790c23eca13f7daa339f2867034 # v3.1.0
159+
with:
160+
containerfiles: ${{ steps.transform-containerfile.outputs.transformed_containerfile }}
161+
context: .
162+
platform: ${{ inputs.platform }}
163+
tags: ${{ steps.meta.outputs.tags }}
164+
labels: ${{ steps.meta.outputs.labels }}
165+
extra-args: |
166+
--network=none
167+
--volume ${{ env.LOCAL_CACHE_DIR_REALPATH }}:/cachi2:z
168+
169+
- name: Save image as artifact
170+
if: ${{ inputs.skipArtifactUpload != 'true' }}
171+
shell: bash
172+
env:
173+
TAGS_LIST: ${{ steps.meta.outputs.tags }}
174+
run: |
175+
mkdir -p ./operator-podman-artifacts
176+
echo "Saving images with tags:"
177+
echo "$TAGS_LIST"
178+
readarray -t tags <<< "$TAGS_LIST"
179+
podman save "${tags[@]}" -o ./operator-podman-artifacts/image.tar
180+
echo "$TAGS_LIST" > ./operator-podman-artifacts/tags.txt
181+
182+
- name: Upload image artifact
183+
if: ${{ inputs.skipArtifactUpload != 'true' }}
184+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
185+
with:
186+
name: podman-image-${{ github.event.number || github.ref_name }}-${{ env.SHORT_SHA }}
187+
path: ./operator-podman-artifacts/
188+
retention-days: 1
189+
if-no-files-found: error

‎.github/workflows/next-container-build.yaml‎

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -191,7 +191,15 @@ jobs:
191191
username: ${{ vars.QUAY_USERNAME }}
192192
password: ${{ secrets.QUAY_TOKEN }}
193193

194-
- name: Build and push per-arch operator and catalog images
194+
- name: Build operator image (hermetic)
195+
uses: ./.github/actions/docker-build
196+
with:
197+
imageName: ${{ env.REGISTRY }}/${{ vars.REGISTRY_ORG }}/${{ vars.OPERATOR_IMAGE_NAME || 'operator' }}
198+
imageTags: type=raw,value=${{ env.BASE_VERSION }}
199+
platform: ${{ env.PLATFORM }}
200+
skipArtifactUpload: 'true'
201+
202+
- name: Build catalog image and push per-arch images
195203
run: |
196204
set -euo pipefail
197205
sudo apt-get -y update; sudo apt-get -y install podman
@@ -200,22 +208,15 @@ jobs:
200208
export VERSION="${BASE_VERSION}"
201209
export REGISTRY_WITH_ORG="${REGISTRY}/${REGISTRY_ORG}"
202210
export IMAGE_TAG_BASE="${REGISTRY_WITH_ORG}/${OPERATOR_IMAGE_NAME}"
203-
# Point catalog-build's bundle reference at the already-published, stable bundle
204-
# tag from the dedicated `bundle` job instead of rebuilding/pushing it again here.
205211
export BUNDLE_IMGS="${REGISTRY_WITH_ORG}/${OPERATOR_IMAGE_NAME}-bundle:${VERSION}"
206212
207213
: "${PLATFORM:?PLATFORM must be set}"
208214
: "${SHORT_SHA:?SHORT_SHA must be set}"
209215
: "${LATEST_NEXT:?LATEST_NEXT must be set}"
210216
: "${OPERATOR_IMAGE_NAME:?OPERATOR_IMAGE_NAME must be set}"
211217
212-
# Build the operator image, then the catalog image. catalog-build's only other
213-
# prerequisite (besides the bundle-push we're skipping) is `opm`, which downloads
214-
# the opm CLI if needed -- that still runs normally. `-o bundle-push` tells make to
215-
# treat that phony prerequisite as already satisfied, so `opm index add` runs
216-
# directly against BUNDLE_IMGS above (a safe concurrent *read* of an already-stable
217-
# tag) instead of each matrix leg re-pushing its own bundle to a shared tag first.
218-
CONTAINER_TOOL="${CONTAINER_TOOL}" VERSION="${VERSION}" PLATFORM="${PLATFORM}" BUNDLE_IMGS="${BUNDLE_IMGS}" make -o bundle-push image-build catalog-build
218+
# Build the catalog image only (operator was built hermetically above)
219+
CONTAINER_TOOL="${CONTAINER_TOOL}" VERSION="${VERSION}" PLATFORM="${PLATFORM}" BUNDLE_IMGS="${BUNDLE_IMGS}" make -o bundle-push catalog-build
219220
220221
# Push per-arch tagged images
221222
for image in "${OPERATOR_IMAGE_NAME}" "${OPERATOR_IMAGE_NAME}-catalog"; do

‎.github/workflows/nightly-upgrade-test.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ jobs:
5353
5454
- name: Remove unnecessary files to free up disk space
5555
if: ${{ steps.upgrade-path-checker.outputs.SHOULD_BE_SKIPPED_BECAUSE_SAME_BRANCH_OR_DOWNGRADE != 'true' }}
56-
uses: endersonmenezes/free-disk-space@7901478139cff6e9d44df5972fd8ab8fcade4db1 # v3
56+
uses: endersonmenezes/free-disk-space@2a22f8c59cae9cddae7194b33e6b92d023b2b4b8 # v4
5757
with:
5858
remove_android: true
5959
remove_dotnet: true

‎.github/workflows/nightly.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ jobs:
4848
4949
- name: Remove unnecessary files to free up disk space
5050
if: ${{ steps.operator-image-existence-checker.outputs.OPERATOR_IMAGE_EXISTS == 'true' }}
51-
uses: endersonmenezes/free-disk-space@7901478139cff6e9d44df5972fd8ab8fcade4db1 # v3
51+
uses: endersonmenezes/free-disk-space@2a22f8c59cae9cddae7194b33e6b92d023b2b4b8 # v4
5252
with:
5353
remove_android: true
5454
remove_dotnet: true

‎.github/workflows/plugin-installer.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ jobs:
5959

6060
- name: Set up Docker Buildx
6161
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
62-
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4
62+
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4
6363

6464
- name: Login to registry (${{ env.REGISTRY }})
6565
if: github.event_name == 'push' && github.ref == 'refs/heads/main'

‎.github/workflows/pr-container-build.yaml‎

Lines changed: 13 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -88,15 +88,20 @@ jobs:
8888
username: ${{ vars.QUAY_USERNAME }}
8989
password: ${{ secrets.QUAY_TOKEN }}
9090

91-
- name: Build and push images
91+
- name: Build operator image (hermetic)
92+
uses: ./.github/actions/docker-build
93+
with:
94+
imageName: ${{ env.REGISTRY }}/${{ vars.REGISTRY_ORG }}/${{ vars.OPERATOR_IMAGE_NAME }}
95+
imageTags: type=raw,value=${{ env.BASE_VERSION }}-pr-${{ steps.pr.outputs.number }}-${{ env.SHORT_SHA }}
96+
platform: linux/amd64
97+
skipArtifactUpload: 'true'
98+
99+
- name: Build bundle and catalog images, then push all
92100
# We explicitly do NOT pass GH_TOKEN or RHDH_BOT_TOKEN here.
93-
# This makes running 'make' safe, even if the Makefile is malicious,
94-
# because there are no secrets in the env to steal.
95101
env:
96102
REGISTRY_ORG: ${{ vars.REGISTRY_ORG }}
97103
OPERATOR_IMAGE_NAME: ${{ vars.OPERATOR_IMAGE_NAME }}
98104
CONTAINER_TOOL: podman
99-
# Construct version safely
100105
VERSION: ${{ env.BASE_VERSION }}-pr-${{ steps.pr.outputs.number }}-${{ env.SHORT_SHA }}
101106
run: |
102107
sudo apt-get -y update; sudo apt-get -y install skopeo podman
@@ -106,11 +111,11 @@ jobs:
106111
107112
set -ex
108113
109-
# Run ONLY release-build (Lint removed)
110-
# We use 'make' here for convenience, but it is sandboxed from secrets.
111-
make release-build
114+
# Build bundle and catalog (operator was built hermetically above)
115+
make bundle bundle-build
116+
BUNDLE_IMGS="${REGISTRY_WITH_ORG}/${OPERATOR_IMAGE_NAME}-bundle:${VERSION}" make -o bundle-push catalog-build
112117
113-
# Push logic
118+
# Push all images
114119
for image in ${OPERATOR_IMAGE_NAME} ${OPERATOR_IMAGE_NAME}-bundle ${OPERATOR_IMAGE_NAME}-catalog; do
115120
podman push -q ${REGISTRY_WITH_ORG}/${image}:${VERSION} docker://${REGISTRY_WITH_ORG}/${image}:${VERSION}
116121
skopeo --insecure-policy copy --all docker://${REGISTRY_WITH_ORG}/${image}:${VERSION} docker://${REGISTRY_WITH_ORG}/${image}:${VERSION}

‎.github/workflows/pr-dockerbuild-validation.yaml‎

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
validate-dockerfile:
1616
name: Validate Dockerfile
1717
runs-on: ubuntu-latest
18-
timeout-minutes: 20
18+
timeout-minutes: 30
1919
permissions:
2020
contents: read
2121

@@ -31,6 +31,7 @@ jobs:
3131
with:
3232
files: |
3333
.github/workflows/pr-dockerbuild-validation.yaml
34+
.github/actions/docker-build/**
3435
Makefile
3536
**/*.go
3637
bundle/**
@@ -42,19 +43,20 @@ jobs:
4243
**/Containerfile
4344
**/*.Dockerfile
4445
**/.dockerignore
46+
rpms.in.yaml
47+
rpms.lock.yaml
48+
scripts/**
4549
files_ignore: |
4650
**/*.md
4751
**/*.adoc
4852
.rhdh/**
4953
tests/**
5054
51-
- name: Setup Go
55+
- name: Build operator image (hermetic)
5256
if: steps.changed-files.outputs.any_changed == 'true'
53-
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
57+
uses: ./.github/actions/docker-build
5458
with:
55-
go-version-file: 'go.mod'
56-
57-
- name: Test build Dockerfile (no push)
58-
if: steps.changed-files.outputs.any_changed == 'true'
59-
run: |
60-
make image-build IMG=localhost/operator:validate
59+
imageName: localhost/operator
60+
imageTags: type=raw,value=validate
61+
platform: linux/amd64
62+
skipArtifactUpload: 'true'

‎.github/workflows/sync-lightspeed-configs.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
go-version-file: 'go.mod'
3838

3939
- name: Set up yq
40-
uses: mikefarah/yq@1b9b4ac5187171d2e5e3129be0cfa827c7f9d53d # v4.53.3
40+
uses: mikefarah/yq@c14f446382944492701b16c1ddb48bb9dbe683e3 # v4.53.6
4141
with:
4242
cmd: yq --version
4343

‎.github/workflows/update-rpm-lockfile.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,14 +11,14 @@ on:
1111
- 'release-[0-9]+.[0-9]+'
1212
paths:
1313
- 'rpms.in.yaml'
14-
- '.rhdh/docker/Dockerfile'
14+
- 'Dockerfile'
1515
- '.github/workflows/update-rpm-lockfile.yaml'
1616

1717
permissions:
1818
contents: write
1919

2020
env:
21-
DOCKERFILE_PATH: .rhdh/docker/Dockerfile
21+
DOCKERFILE_PATH: Dockerfile
2222

2323
jobs:
2424
update-lockfile:

0 commit comments

Comments
 (0)