mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-07 03:32:00 +00:00
* feat(ci): add docker build and ECR image publish reusables Image repos need a registry-free build check and an ECR publish that stops at a mutable tag, without an ECS or Lambda update. * fix(ci): retry ECR digest checks when describe-images fails A tag that is not visible yet makes the AWS CLI exit non-zero, and set -e was aborting the retry loop on that first error.
124 lines
3.5 KiB
Bash
Executable file
124 lines
3.5 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# The verifier must retry a failed describe-images call. set -e used to abort
|
|
# the loop on the first ImageNotFoundException.
|
|
set -euo pipefail
|
|
|
|
root="$(cd "$(dirname "$0")/.." && pwd)"
|
|
verifier="${root}/.github/actions/verify-ecr-promote-digest/verify.sh"
|
|
failures=0
|
|
|
|
assert_eq() {
|
|
local name="$1"
|
|
local got="$2"
|
|
local want="$3"
|
|
if [ "${got}" != "${want}" ]; then
|
|
echo "${name}: got ${got}, want ${want}" >&2
|
|
failures=$((failures + 1))
|
|
fi
|
|
}
|
|
|
|
run_case() {
|
|
local name="$1"
|
|
local expect_status="$2"
|
|
local stub_dir
|
|
stub_dir="$(mktemp -d)"
|
|
cat > "${stub_dir}/aws" <<'EOF'
|
|
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
tag=""
|
|
for arg in "$@"; do
|
|
case "${arg}" in
|
|
imageTag=*) tag="${arg#imageTag=}" ;;
|
|
esac
|
|
done
|
|
if [ -z "${tag}" ]; then
|
|
echo "stub aws: missing image tag" >&2
|
|
exit 1
|
|
fi
|
|
dir="${AWS_STUB_DIR}"
|
|
count_file="${dir}/count-${tag}"
|
|
n=0
|
|
if [ -f "${count_file}" ]; then
|
|
n="$(cat "${count_file}")"
|
|
fi
|
|
n=$((n + 1))
|
|
printf '%s\n' "${n}" > "${count_file}"
|
|
line="$(sed -n "${n}p" "${dir}/behavior-${tag}" || true)"
|
|
if [ -z "${line}" ]; then
|
|
line="$(tail -n 1 "${dir}/behavior-${tag}")"
|
|
fi
|
|
case "${line}" in
|
|
ok\ *)
|
|
printf '%s\n' "${line#ok }"
|
|
;;
|
|
fail)
|
|
echo "ImageNotFoundException: ${tag}" >&2
|
|
exit 254
|
|
;;
|
|
*)
|
|
echo "stub aws: no behavior for ${tag} call ${n}" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
EOF
|
|
chmod +x "${stub_dir}/aws"
|
|
shift 2
|
|
while [ "$#" -gt 0 ]; do
|
|
printf '%s\n' "$2" > "${stub_dir}/behavior-$1"
|
|
shift 2
|
|
done
|
|
set +e
|
|
IMAGE_NAME=actions-runner \
|
|
SHA=0123456789abcdef0123456789abcdef01234567 \
|
|
PROMOTE_TAG=current \
|
|
DIGEST_RETRY_SLEEP=0 \
|
|
AWS_STUB_DIR="${stub_dir}" \
|
|
PATH="${stub_dir}:${PATH}" \
|
|
bash "${verifier}" >"${stub_dir}/out" 2>"${stub_dir}/err"
|
|
status=$?
|
|
set -e
|
|
if [ "${status}" -ne "${expect_status}" ]; then
|
|
echo "${name}: exit ${status}, want ${expect_status}" >&2
|
|
cat "${stub_dir}/err" >&2
|
|
failures=$((failures + 1))
|
|
fi
|
|
sha_calls=0
|
|
promote_calls=0
|
|
if [ -f "${stub_dir}/count-sha-0123456789abcdef0123456789abcdef01234567" ]; then
|
|
sha_calls="$(cat "${stub_dir}/count-sha-0123456789abcdef0123456789abcdef01234567")"
|
|
fi
|
|
if [ -f "${stub_dir}/count-current" ]; then
|
|
promote_calls="$(cat "${stub_dir}/count-current")"
|
|
fi
|
|
printf '%s\n' "${sha_calls}" > "${stub_dir}/sha_calls"
|
|
printf '%s\n' "${promote_calls}" > "${stub_dir}/promote_calls"
|
|
# shellcheck disable=SC2034
|
|
CASE_DIR="${stub_dir}"
|
|
}
|
|
|
|
run_case "match on first read" 0 \
|
|
"sha-0123456789abcdef0123456789abcdef01234567" "ok sha256:aaa" \
|
|
"current" "ok sha256:aaa"
|
|
assert_eq "match on first read sha calls" "$(cat "${CASE_DIR}/sha_calls")" "1"
|
|
assert_eq "match on first read promote calls" "$(cat "${CASE_DIR}/promote_calls")" "1"
|
|
rm -rf "${CASE_DIR}"
|
|
|
|
run_case "retry when promote tag is not visible yet" 0 \
|
|
"sha-0123456789abcdef0123456789abcdef01234567" "ok sha256:aaa" \
|
|
"current" "$(printf 'fail\nok sha256:aaa')"
|
|
assert_eq "not visible yet sha calls" "$(cat "${CASE_DIR}/sha_calls")" "2"
|
|
assert_eq "not visible yet promote calls" "$(cat "${CASE_DIR}/promote_calls")" "2"
|
|
rm -rf "${CASE_DIR}"
|
|
|
|
run_case "give up when describe-images keeps failing" 1 \
|
|
"sha-0123456789abcdef0123456789abcdef01234567" "fail" \
|
|
"current" "fail"
|
|
assert_eq "keep failing sha calls" "$(cat "${CASE_DIR}/sha_calls")" "6"
|
|
assert_eq "keep failing promote calls" "$(cat "${CASE_DIR}/promote_calls")" "6"
|
|
rm -rf "${CASE_DIR}"
|
|
|
|
if [ "${failures}" -ne 0 ]; then
|
|
echo "${failures} assertion(s) failed" >&2
|
|
exit 1
|
|
fi
|
|
echo "verify_ecr_promote_digest: ok"
|