Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/helm-chart.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,9 @@ jobs:
- name: Helm regenerate repo index
run: helm repo index package/. --url https://charts.kosli.com/ --merge package/old-index.yaml

- name: Check every chart URL is on charts.kosli.com
run: ./scripts/check-helm-index-urls.sh package/index.yaml

- name: Upload new chart and the update index.yaml to S3
run: |
rm package/old-index.yaml
Expand Down
28 changes: 28 additions & 0 deletions scripts/check-helm-index-urls.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
#!/usr/bin/env bash
# Fails if any chart download URL in a Helm repo index is not on charts.kosli.com.
#
# `helm repo index --merge` copies old entries forward unchanged, so a stale URL
# pointing at a host we no longer own would be republished on every release
# (kosli-dev/server#7024). Every step fails closed: an unreadable index or an
# index with no URLs is an error, not a pass.
set -euo pipefail

index="${1:?usage: $0 <index.yaml>}"

urls=$(yq '.entries[][].urls[]' "$index") || {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit (optional): In yq v4, .urls[] on an entry with no urls key (or urls: []) returns nothing, so the entry gets skipped without an error. The empty check on L16 only catches the case where the whole index has no URLs. In practice Helm always writes urls, so this is just about how strictly the script fails closed. If you want it strict, you could also fail when any entry has no URLs:

missing=$(yq '[.entries[][] | select((.urls // []) | length == 0)] | length' "$index")
[ "$missing" = "0" ] || { echo "$missing chart entries have no URLs in $index" >&2; exit 1; }

echo "failed to read chart URLs from $index" >&2
exit 1
}
if [ -z "$urls" ]; then
echo "no chart URLs found in $index" >&2
exit 1
fi

bad=$(printf '%s\n' "$urls" | grep -v '^https://charts\.kosli\.com/' || true)
if [ -n "$bad" ]; then
echo "chart URLs not on https://charts.kosli.com/:" >&2
printf '%s\n' "$bad" >&2
exit 1
fi

echo "all $(printf '%s\n' "$urls" | wc -l | tr -d ' ') chart URLs are on https://charts.kosli.com/"
Loading