Files
smom-dbis-138/.github/workflows/validation.yml
T
Devin AIandNakamoto, S <[email protected]> c0683a26a9 ci(validate-kubernetes): make kube-score scan informational-only
kube-score score exits 1 on any [CRITICAL] finding; the workflow's StatefulSets emit several (no resource limits, no liveness/readiness probes on init containers, etc). The prior ludovico85/kube-score-action@v1 wrapper did not propagate that exit code, mirroring how the slither scan ran. Trailing || true restores that no-block behaviour so reviewers see the findings without the job failing on them.

Switch to set -e and drop || true if findings should gate.

Co-Authored-By: Nakamoto, S <[email protected]>
2026-05-03 19:32:42 +00:00

162 lines
4.9 KiB
YAML

name: Validation
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main, develop ]
workflow_dispatch:
jobs:
validate-genesis:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install jq
run: sudo apt-get update && sudo apt-get install -y jq
- name: Validate genesis file
run: ./scripts/validation/validate-genesis.sh
validate-terraform:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Setup Terraform
uses: hashicorp/setup-terraform@v2
- name: Terraform Format Check
run: |
cd terraform
terraform fmt -check
- name: Terraform Validate
run: |
cd terraform
terraform init -backend=false
terraform validate
- name: Terraform Security Scan
uses: bridgecrewio/checkov-action@master
with:
directory: terraform
framework: terraform
validate-kubernetes:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install kubeconform
run: |
# kubeconform validates manifests against the upstream OpenAPI schema
# without needing a running kube-apiserver, which kubectl 1.34's
# apply --dry-run=client cannot do (it still hits localhost:8080 for
# API discovery and exits 1 on connection refused).
curl -sSL -o /tmp/kubeconform.tar.gz \
https://github.com/yannh/kubeconform/releases/download/v0.6.7/kubeconform-linux-amd64.tar.gz
tar -xzf /tmp/kubeconform.tar.gz -C /tmp
sudo mv /tmp/kubeconform /usr/local/bin/kubeconform
kubeconform -v
- name: Validate Kubernetes manifests
run: |
set -e
shopt -s nullglob globstar
files=(k8s/base/namespace.yaml k8s/base/**/statefulset.yaml)
if [ "${#files[@]}" -eq 0 ]; then
echo "No k8s manifests found under k8s/base/; skipping kubeconform"
exit 0
fi
kubeconform -strict -summary "${files[@]}"
- name: Install kube-score
run: |
# Latest upstream as of this commit; bump as needed.
curl -fsSL -o /tmp/kube-score.tar.gz \
https://github.com/zegl/kube-score/releases/download/v1.20.0/kube-score_1.20.0_linux_amd64.tar.gz
tar -xzf /tmp/kube-score.tar.gz -C /tmp
sudo mv /tmp/kube-score /usr/local/bin/kube-score
kube-score version
- name: Kubernetes Security Scan
run: |
set +e
shopt -s nullglob
files=(k8s/base/**/*.yaml k8s/base/*.yaml)
if [ "${#files[@]}" -eq 0 ]; then
echo "No k8s manifests found under k8s/; skipping kube-score scan"
exit 0
fi
# kube-score exits 1 on any [CRITICAL] finding; the prior
# ludovico85/kube-score-action@v1 was configured as informational
# only (the action didn't propagate the exit code, mirroring how
# slither runs above). Trailing `|| true` preserves that behaviour
# so reviewers see findings without blocking the PR. Switch to
# `set -e` and drop the `|| true` if you want findings to gate.
kube-score score "${files[@]}" || true
validate-smart-contracts:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Install Foundry
uses: foundry-rs/foundry-toolchain@v1
- name: Run tests
run: forge test
- name: Run fuzz tests
run: forge test --fuzz-runs 1000
- name: Check formatting
run: forge fmt --check
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install Slither
run: pip install --upgrade slither-analyzer
- name: Smart Contract Security Scan
run: slither contracts --print human-summary || true
validate-security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Container Security Scan
uses: aquasecurity/trivy-action@master
with:
scan-type: 'image'
image-ref: 'hyperledger/besu:23.10.0'
format: 'sarif'
output: 'trivy-results.sarif'
- name: Upload Trivy results
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: 'trivy-results.sarif'
validate-documentation:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Check documentation
run: |
# Check if all required documentation exists
test -f README.md || exit 1
test -f CONTRIBUTING.md || exit 1
test -f CHANGELOG.md || exit 1
test -f docs/DEPLOYMENT.md || exit 1
test -f docs/ARCHITECTURE.md || exit 1
test -f docs/SECURITY.md || exit 1