Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ venv
**/__pycache__
**/*.py[cod]
**/*.egg-info
**/bin
**/build
**/dist
**/.mypy_cache
Expand Down
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ body:
attributes:
value: |
Describe the problem and safety boundary, not a live environment. New source
proposals should follow docs/adding-sources.md.
proposals should follow inventory/README.md.

- type: checkboxes
id: checks
Expand Down
2 changes: 1 addition & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ updates:

- package-ecosystem: terraform
directories:
- /terraform/aws/examples/created-vpc
- /terraform/aws/deployment
- /terraform/aws/examples/existing-vpc
- /terraform/aws/examples/member-account
- /terraform/aws/examples/multi-account-central
Expand Down
2 changes: 1 addition & 1 deletion .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ Complete this section when adding or changing a snapshot/signal source.
- [ ] Metadata allowlist/redaction
- [ ] Central profile/priority/deadline policy
- [ ] IAM/Terraform registration
- [ ] Review checklist in `docs/adding-sources.md`
- [ ] Source-adapter requirements in `inventory/README.md`

## Canary

Expand Down
189 changes: 0 additions & 189 deletions .github/workflows/aws-sandbox.yml

This file was deleted.

51 changes: 0 additions & 51 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -102,57 +102,6 @@ jobs:
PORTSCANNER_TEST_PYTHON: ${{ github.workspace }}/.venv/bin/python
run: make -C operator test-envtest

schemas:
name: JSON schemas
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1

- uses: actions/setup-python@v7.0.0
with:
python-version: "3.12"

- name: Install uv
run: python -m pip install --disable-pip-version-check "uv==0.11.30"

- name: Install schema dependencies
shell: bash
run: |
set -euo pipefail
uv sync --frozen --all-packages --group dev

- name: Validate schema documents
shell: bash
run: |
set -euo pipefail
if [[ ! -d schemas ]]; then
echo "No schemas directory is present."
exit 0
fi
uv run python - <<'PY'
import json
from pathlib import Path

from jsonschema.validators import validator_for

schemas = sorted(Path("schemas").glob("*.schema.json"))
if not schemas:
raise SystemExit("schemas directory contains no *.schema.json files")
for path in schemas:
schema = json.loads(path.read_text(encoding="utf-8"))
validator_for(schema).check_schema(schema)
print(f"validated {path}")
PY

- name: Run schema contract tests
shell: bash
run: |
set -euo pipefail
if [[ -f contracts/tests/test_schemas.py ]]; then
uv run --package portscanner-contracts \
pytest contracts/tests/test_schemas.py
fi

generated-drift:
name: Generated drift
runs-on: ubuntu-latest
Expand Down
3 changes: 0 additions & 3 deletions .github/workflows/containers.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,6 @@ on:
- "**/*.dockerfile"
- ".dockerignore"
- "LICENSE"
- "NOTICE"
- "THIRD_PARTY_NOTICES.md"
- "contracts/**"
- "db/migrations/**"
Expand Down Expand Up @@ -39,7 +38,6 @@ on:
- "**/*.dockerfile"
- ".dockerignore"
- "LICENSE"
- "NOTICE"
- "THIRD_PARTY_NOTICES.md"
- "contracts/**"
- "db/migrations/**"
Expand Down Expand Up @@ -93,7 +91,6 @@ jobs:
text=True,
)
component_contexts = {
"operator/Dockerfile": "operator",
"scanner/nmap/Dockerfile": ".",
}
python_images = {
Expand Down
44 changes: 10 additions & 34 deletions .github/workflows/kubernetes.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,11 @@ name: Kubernetes manifests
on:
pull_request:
paths:
- "**/*.yaml"
- "**/*.yml"
- "**/Chart.yaml"
- "**/values.yaml"
- "**/*.tpl"
- "operator/api/**"
- "operator/chart/**"
- "operator/config/crd/**"
- "operator/config/samples/**"
- "operator/Makefile"
- "tools/export_crd_schemas.py"
- "tools/tests/test_export_crd_schemas.py"
- "generator/pyproject.toml"
Expand All @@ -21,8 +21,11 @@ on:
branches:
- main
paths:
- "operator/config/**"
- "operator/api/**"
- "operator/chart/**"
- "operator/config/crd/**"
- "operator/config/samples/**"
- "operator/Makefile"
- "tools/export_crd_schemas.py"
- "tools/tests/test_export_crd_schemas.py"
- "generator/pyproject.toml"
Expand All @@ -39,7 +42,7 @@ concurrency:

jobs:
validate:
name: Kustomize, Helm, kubeconform
name: Helm and kubeconform
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1
Expand All @@ -62,7 +65,6 @@ jobs:
shell: bash
run: |
set -euo pipefail
go install sigs.k8s.io/kustomize/kustomize/v5@v5.8.1
go install helm.sh/helm/v3/cmd/helm@v3.20.1
go install github.com/yannh/kubeconform/cmd/kubeconform@v0.8.0

Expand All @@ -77,32 +79,6 @@ jobs:
--output-directory "${RUNNER_TEMP}/crd-schemas" \
"${crds[@]}"

- name: Build and validate Kustomize roots
shell: bash
run: |
set -euo pipefail
count=0
while IFS= read -r file; do
directory="$(dirname "${file}")"
rendered="${RUNNER_TEMP}/kustomize-${count}.yaml"
echo "Building ${directory}"
kustomize build "${directory}" > "${rendered}"
for version in 1.35.0 1.36.0; do
kubeconform \
-strict \
-summary \
-skip CustomResourceDefinition \
-kubernetes-version "${version}" \
-schema-location default \
-schema-location "${RUNNER_TEMP}/crd-schemas/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json" \
"${rendered}"
done
count=$((count + 1))
done < <(git ls-files 'kustomization.yaml' '**/kustomization.yaml')
if [[ "${count}" -eq 0 ]]; then
echo "No Kustomize roots are present."
fi

- name: Validate custom resource samples
shell: bash
run: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/supply-chain.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ jobs:
python-version: "3.12"

- name: Run sanitizer unit tests
run: python -m unittest discover -s tools/tests -p 'test_*.py' -v
run: python -m unittest -v tools.tests.test_sanitize

- name: Scan tracked publication content
run: python tools/sanitize.py
Expand Down
Loading