From c2cb2d1636c13c2e232b7f6b0046181b582c6154 Mon Sep 17 00:00:00 2001 From: Peter Pathirana Date: Thu, 17 Sep 2026 01:09:04 +0000 Subject: [PATCH] ci(internal-workflows): publish with in-cluster authentication --- .github/workflows/publish.yaml | 5 +++-- .github/workflows/test-template.yaml | 12 ++++++++++++ actions/coder-template-push/action.yaml | 11 ++--------- 3 files changed, 17 insertions(+), 11 deletions(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index f0c77061..83d8348a 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -25,6 +25,7 @@ env: template_name: homelab-workspace source_ref: ${{ github.event.release.tag_name || inputs.release_tag }} source_sha: ${{ github.event.release.tag_name || inputs.release_tag }} + template_source_ref: ${{ github.event_name == 'workflow_dispatch' && 'main' || github.event.release.tag_name }} jobs: publish-image: @@ -70,7 +71,7 @@ jobs: fetch-depth: 1 persist-credentials: false path: release - ref: ${{ env.source_ref }} + ref: ${{ env.template_source_ref }} - name: Tailscale Connect uses: tailscale/github-action@780049a30b6ff5c378a9e7b389d15ece7a204888 # v4.1.3 @@ -97,7 +98,7 @@ jobs: workspace_image: "ghcr.io/ppat/coder-workspace:${{ needs.publish-image.outputs.image_tag }}" home_pvc_storage_class: sc-longhorn-replicated tmp_pvc_storage_class: sc-longhorn-local-non-replicated-ephemeral - kubernetes_config_path: "" + kubernetes_config_path: in-cluster skip_dotfiles_scripts: "false" message: "[Release Notes](https://github.com/${{ github.repository }}/releases/tag/${{ env.source_sha }})" diff --git a/.github/workflows/test-template.yaml b/.github/workflows/test-template.yaml index f0f66ce6..8eb8ceda 100644 --- a/.github/workflows/test-template.yaml +++ b/.github/workflows/test-template.yaml @@ -108,6 +108,18 @@ jobs: RELEASE_TAG="$(gh release view --repo "${{ github.repository }}" --json tagName --jq .tagName)" echo "workspace_image=ghcr.io/ppat/coder-workspace:${RELEASE_TAG}" >> "${GITHUB_OUTPUT}" + - name: Confirm in-cluster publish input + uses: ./current/actions/coder-template-push + with: + template_dir: current/templates/kubernetes/homelab-workspace + template_name: in-cluster-test + template_version: ${{ github.sha }} + workspace_image: ${{ steps.released_image.outputs.workspace_image }} + home_pvc_storage_class: standard + tmp_pvc_storage_class: standard + kubernetes_config_path: in-cluster + skip_dotfiles_scripts: "true" + - name: Publish template uses: ./current/actions/coder-template-push with: diff --git a/actions/coder-template-push/action.yaml b/actions/coder-template-push/action.yaml index 199bc501..48a92397 100644 --- a/actions/coder-template-push/action.yaml +++ b/actions/coder-template-push/action.yaml @@ -25,9 +25,8 @@ inputs: description: Storage class used for ephemeral tmp PVCs. required: true kubernetes_config_path: - description: Provisioner-local kubeconfig path, or empty for in-cluster authentication. + description: Provisioner-local kubeconfig path, or in-cluster for in-cluster authentication. required: true - default: "" skip_dotfiles_scripts: description: Whether Chezmoi should skip repository-owned bootstrap scripts. required: true @@ -79,18 +78,12 @@ runs: "${coder_url}/api/v2/templateversions/${existing_id}" >/dev/null fi - variables_file="${RUNNER_TEMP}/coder-template-variables.yaml" - jq --null-input \ - --arg kubernetes_config_path "${KUBERNETES_CONFIG_PATH}" \ - '{kubernetes_config_path: $kubernetes_config_path}' > "${variables_file}" push_args=( --directory "${TEMPLATE_DIR}" --var "workspace_image=${WORKSPACE_IMAGE}" --var "home_pvc_storage_class=${HOME_PVC_STORAGE_CLASS}" --var "tmp_pvc_storage_class=${TMP_PVC_STORAGE_CLASS}" - # Coder discards an empty `--var name=` assignment. A variables file - # preserves the required empty string used for in-cluster auth. - --variables-file "${variables_file}" + --var "kubernetes_config_path=${KUBERNETES_CONFIG_PATH}" --var "skip_dotfiles_scripts=${SKIP_DOTFILES_SCRIPTS}" --name "${TEMPLATE_VERSION}" --yes