ci(helm): fail the chart release if any index URL is off charts.kosli.com - #1219
Conversation
….com `helm repo index --merge` copies old entries forward unchanged, so stale URLs pointing at hosts we no longer own (kosli-dev/server#7024) would be republished on every release. Add a fail-closed check between index regeneration and the S3 upload. The check is a standalone script rather than an inline `! yq | grep -v` pipeline so that yq errors, a missing or malformed index, and an index with no URLs all fail the step instead of passing silently (addresses the review comment on kosli-dev/server#7025). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Claude finished @mbevc1's task in 4m 42s —— View job PR Review: ci(helm): fail the chart release if any index URL is off charts.kosli.com
Static analysis
I couldn't run the script or ReviewWorkflow ( Script: this is solid and handles the concern raised in kosli-dev/server#7025 properly:
Minor / optional
What's good
Verdict: I found no bugs. It's ready to merge; the points above are optional. |
Pull request was closed
|
|
||
| index="${1:?usage: $0 <index.yaml>}" | ||
|
|
||
| urls=$(yq '.entries[][].urls[]' "$index") || { |
There was a problem hiding this comment.
Nit (optional): In yq v4, .urls[] on an entry with no urls key (or urls: []) returns nothing, so the entry gets skipped without an error. The empty check on L16 only catches the case where the whole index has no URLs. In practice Helm always writes urls, so this is just about how strictly the script fails closed. If you want it strict, you could also fail when any entry has no URLs:
missing=$(yq '[.entries[][] | select((.urls // []) | length == 0)] | length' "$index")
[ "$missing" = "0" ] || { echo "$missing chart entries have no URLs in $index" >&2; exit 1; }
Summary
Implements the CI guard from the plan in kosli-dev/server#7025 (issue kosli-dev/server#7024).
helm repo index --mergecopies old entries forward unchanged, so stale chart URLs pointing at hosts we no longer own would be republished on every release. This adds a check between "Helm regenerate repo index" and the S3 upload that fails the workflow if any URL inpackage/index.yamlis not onhttps://charts.kosli.com/.Changes
scripts/check-helm-index-urls.sh: extracts every chart URL withyqand fails unless all start withhttps://charts.kosli.com/..github/workflows/helm-chart.yml: new step running the script before the upload.Review comment on the plan
The reviewer on kosli-dev/server#7025 pointed out that the proposed one-liner (
! yq ... | grep -v ...) discardedyq's exit status and passed silently when extraction produced no output. The script fails closed instead: it captures theyqoutput, fails ifyqerrors or is missing, fails if no URLs were found, and only then checks prefixes. No leading!, so theset -ecaveat in the plan no longer applies.Verification
Ran the script locally (yq 4.53.6, the same version preinstalled on
ubuntu-latest) against fixtures:charts.kosli.com/index.yamlmerkely-development.github.io/charts.merkely.comURLsentriesyqnot on PATHshellcheckpasses. The live index already has no non-kosli URLs, so the S3 fix the plan required before merging is in place and the next chart release will pass this check.🤖 Generated with Claude Code