diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile new file mode 100644 index 0000000..adf8dc3 --- /dev/null +++ b/.devcontainer/Dockerfile @@ -0,0 +1,82 @@ +FROM ubuntu:22.04 +RUN \ + apt-get update && \ + apt-get install -y bash ca-certificates gnupg make curl vim sudo jq && \ + curl -sL https://deb.nodesource.com/setup_18.x -o nodesource_setup.sh && \ + mkdir -p /etc/apt/keyrings && \ + curl -fsSL https://deb.nodesource.com/gpgkey/nodesource-repo.gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/nodesource.gpg && \ + echo "deb [signed-by=/etc/apt/keyrings/nodesource.gpg] https://deb.nodesource.com/node_20.x nodistro main" | sudo tee /etc/apt/sources.list.d/nodesource.list && \ + apt-get update && \ + apt-get install -y nodejs && \ + apt-get clean && \ + curl -o /usr/local/bin/yq https://github.com/mikefarah/yq/releases/download/v4.35.2/yq_linux_amd64 && \ + chmod +x /usr/local/bin/yq +RUN \ + curl -q -l -o /tmp/go.tgz "https://dl.google.com/go/go1.21.4.linux-amd64.tar.gz" && \ + cd /usr/local && \ + tar -xvf /tmp/go.tgz && \ + rm -f /tmp/go.tgz && \ + cd / +RUN \ + curl -L -o /usr/local/bin/minikube https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64 && \ + chmod +x /usr/local/bin/minikube && \ + curl -L -o /usr/local/bin/kubectl "https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" && \ + chmod +x /usr/local/bin/kubectl + +RUN \ + curl -fsSL -o /tmp/get_helm.sh https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 && \ + chmod +x /tmp/get_helm.sh && \ + /tmp/get_helm.sh && \ + rm /tmp/get_helm.sh + +RUN \ + groupadd -g 10001 dev && \ + useradd --uid 10001 -g 10001 -m dev && \ + echo 'dev ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/dev && \ + chmod 400 /etc/sudoers.d/dev + +ENV PATH /usr/local/go/bin:$PATH + +RUN \ + npm install -g "@bitnami/readme-generator-for-helm@2.6.0" + +RUN \ + go install github.com/onsi/ginkgo/v2/ginkgo@latest + +RUN \ + apt-get install -y git zsh strace lsof graphviz && \ + mv /root/go/bin/ginkgo /usr/local/bin + +RUN \ + curl -L -o /tmp/ct.tar.gz https://github.com/helm/chart-testing/releases/download/v3.8.0/chart-testing_3.8.0_linux_amd64.tar.gz && \ + cd /usr/local/bin && \ + tar -xvf /tmp/ct.tar.gz ct && \ + cd / && \ + tar -xvf /tmp/ct.tar.gz etc && \ + mkdir /etc/ct && \ + mv /etc/chart_schema.yaml /etc/ct/ && \ + mv /etc/lintconf.yaml /etc/ct/ && \ + curl -o /tmp/gh.tar.gz https://github.com/cli/cli/releases/download/v2.40.0/gh_2.40.0_linux_amd64.tar.gz -L && \ + cd && \ + cd /tmp && \ + tar -zxvf gh.tar.gz && \ + mv gh_*_linux_amd64/bin/* /usr/local/bin && \ + mkdir -p /usr/local/share/main/man1/ && \ + mv gh_*_linux_amd64/share/man/man1/* /usr/local/share/main/man1/ && \ + cd + +RUN \ + cd /tmp && \ + git clone https://github.com/devcontainers/features && \ + cd features/src/docker-in-docker && \ + export MOBY=true && \ + export INSTALLDOCKERBUILDX=false && \ + ./install.sh && \ + cd ../../../ && \ + rm -rf features + +RUN \ + usermod -a -G docker dev + +USER dev + diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json new file mode 100644 index 0000000..6371257 --- /dev/null +++ b/.devcontainer/devcontainer.json @@ -0,0 +1,30 @@ +{ + "name": "spiffe-helm-charts-hardened", + "image": "ghcr.io/spiffe/helm-charts-hardened-devcontainer:latest", + "features": { + "ghcr.io/devcontainers/features/docker-in-docker:2": { + "version": "latest", + "moby": true, + "installDockerBuildx": false + } + }, + "customizations": { + "vscode": { + "extensions": [ + "ms-kubernetes-tools.vscode-kubernetes-tools" + ], + "settings": { + "terminal.integrated.defaultProfile.linux": "bash", + "terminal.integrated.profiles.linux": { + "zsh": { "path": "/bin/zsh" }, + "bash": { "path": "/bin/bash" } + } + } + } + }, + "postStartCommand": "minikube start && helm upgrade --install -n spire-server spire-crds charts/spire-crds --create-namespace && kubectl version", + "hostRequirements": { + "cpus": 1 + }, + "remoteUser": "dev" +} diff --git a/.github/workflows/update-devcontainer-image.yaml b/.github/workflows/update-devcontainer-image.yaml new file mode 100644 index 0000000..54fc4fb --- /dev/null +++ b/.github/workflows/update-devcontainer-image.yaml @@ -0,0 +1,44 @@ +name: Update devcontainer image + +on: + schedule: + - cron: '0 8 * * 1' + + # Allows you to run this workflow manually from the Actions tab + workflow_dispatch: + +env: + HELM_VERSION: v3.11.1 + +jobs: + build-and-push-devcontainer-image: + runs-on: ubuntu-20.04 + permissions: + contents: read + id-token: write + packages: write + + env: + COSIGN_EXPERIMENTAL: 1 + + steps: + - name: Checkout + uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1 + - name: Install cosign + uses: sigstore/cosign-installer@1fc5bd396d372bee37d608f955b336615edf79c8 # v3.2.0 + with: + cosign-release: v1.13.1 + - name: Install regctl + uses: regclient/actions/regctl-installer@b6614f5f56245066b533343a85f4109bdc38c8cc # main + - name: Log in to GHCR + uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3.0.0 + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + - name: Build / Push images + run: | + set -e + cd .devcontainer/ + docker build -t ghcr.io/spiffe/helm-charts-hardened-devcontainer:latest . + docker push ghcr.io/spiffe/helm-charts-hardened-devcontainer:latest diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 1d4a7ae..b66b877 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -60,3 +60,7 @@ Any changes to Chart.yaml or values.yaml require an update of the README.md. Thi In contrary to many other Helm repositories we do NOT require contributors to increate the Chart version. We have customized our release pipeline so we can bundle various PRs in a single release. Maintainers of the helm-charts in this repo will take care of the semantic versioning. [readme-generator]: https://github.com/bitnami-labs/readme-generator-for-helm "Auto generate READMEs for Helm Charts." + +## devcontainer support + +We have a usable devcontainer with all the dev tools preinstalled to make contributions easier. You should be able to use it via Codespaces (https://github.com/codespaces/), Visual Studio Code (https://code.visualstudio.com/), DevPod (https://devpod.sh), etc. Please consult the documentation for those tools for how to use them.