Repository navigation
CI: manifest-diff workflow #2447
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
brainrake
wants to merge
39
commits into
develop
Choose a base branch
from
martonboros/manifest-diff-tooling
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Changes from all commits
Commits
Show all changes
39 commits
Select commit
Hold shift + click to select a range
98904bd
Capture AMI manifest at build time via Packer, drop SSH approach
brainrake ba097ed
Use bsdtar --format=mtree for the manifest, not a hand-rolled walk
brainrake 9fd063f
Re-trigger CI
brainrake 60abe68
Cache AMI manifest for all arches, not just amd64
brainrake 67e06d7
Merge branch 'develop' into martonboros/manifest-diff-tooling
brainrake c59a367
shfmt: tab-indent manifest-snapshot.sh
brainrake 74c2bf5
Run apt-get update before installing libarchive-tools
brainrake 53d69bc
Post AMI manifest diff as a PR comment
brainrake aa57d40
Post AMI manifest diff as one collapsed, updated-in-place comment
brainrake b7f02c6
Shrink per-leg diff truncation cap to fit GitHub's comment size limit
brainrake bdba4a1
Merge branch 'develop' into martonboros/manifest-diff-tooling
brainrake c6a6ae1
Merge branch 'develop' into martonboros/manifest-diff-tooling
brainrake e8ca552
Use GH Actions cache instead of S3 for the manifest baseline
brainrake 1665ed5
Key AMI manifest cache by nix store path, not git sha
brainrake 69bebfe
Update .github/workflows/testinfra-ami-build.yml
brainrake 32debc2
Address remaining review feedback from mmlb
brainrake a0be138
Merge remote-tracking branch 'origin/develop' into martonboros/manife…
brainrake 24e003f
Make truncation note a link instead of code-fence text
brainrake dd47954
Graceful skip when no baseline is cached, show exact AMI version
brainrake 68e67b9
fix(ami): inject AMI version via env, not inline expression
brainrake 1ce5070
fix(ami): avoid shellcheck quote-parse bug, fix useless-echo lint
brainrake d6f9c81
refactor(ami): extract manifest logic into 3 composite actions
brainrake 7f5ab58
Merge branch 'develop' into martonboros/manifest-diff-tooling
brainrake 93aca42
refactor: generalize manifest actions, key by content hash
brainrake dc03e48
feat(ci): extend manifest-diff mechanism to docker image builds
brainrake 38ed59c
refactor(ci): dedupe docker manifest snapshot, drop raw artifact uploads
brainrake 8ecff97
refactor(ci): move manifest diff/comment logic into the nix flake
brainrake f5bd80f
Merge branch 'develop' into martonboros/manifest-diff-tooling
brainrake 854f022
ci: collapse unchanged manifest lines in diff
brainrake 9b4a74f
Merge remote-tracking branch 'origin/develop' into martonboros/manife…
brainrake 1342cb1
ci: temp seed ami manifest baseline from pr build
brainrake 1fffa25
Merge branch 'martonboros/manifest-diff-tooling' of https://github.co…
brainrake a5871bf
ci: skip manifest comment when no legs reported
brainrake eb5d2cb
refactor(ci): trim manifest comment script, inline docker snapshot
brainrake 990c1e0
refactor(ci): fold artifact upload into diff-manifest, merge cache steps
brainrake 777dd0f
refactor(ci): fix manifest path, drop description input
brainrake 58469f2
refactor(ci): add --docker mode to manifest-snapshot.sh
brainrake 4777ac3
Revert "refactor(ci): add --docker mode to manifest-snapshot.sh"
brainrake d9f98fa
ci: TEMP add marker file to exercise manifest diff
brainrake File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,27 @@ | ||
| name: Cache manifest | ||
| description: Annotates a rootfs manifest with a version label and caches it as the diff baseline, keyed by its own content hash | ||
|
|
||
| inputs: | ||
| key_prefix: | ||
| description: 'Cache key prefix (e.g. ami-manifest-15-amd64, docker-manifest-17-production)' | ||
| required: true | ||
| version_label: | ||
| description: 'Version string to stamp into the manifest' | ||
| required: true | ||
|
|
||
| runs: | ||
| using: composite | ||
| steps: | ||
| - id: hash | ||
| shell: bash | ||
| env: | ||
| VERSION_LABEL: ${{ inputs.version_label }} | ||
| run: | | ||
| printf '%s\n' "# version: $VERSION_LABEL" | cat - /tmp/manifest.txt > /tmp/manifest.new | ||
| mv /tmp/manifest.new /tmp/manifest.txt | ||
| echo "value=$(sha256sum /tmp/manifest.txt | cut -d' ' -f1)" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | ||
| with: | ||
| path: /tmp/manifest.txt | ||
| key: ${{ inputs.key_prefix }}-${{ steps.hash.outputs.value }} |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| name: Diff manifest | ||
| description: Restores the cached baseline manifest and diffs it against this build's manifest | ||
|
|
||
| inputs: | ||
| key_prefix: | ||
| description: 'Cache key prefix matching the one used by cache-manifest (e.g. ami-manifest-15-amd64)' | ||
| required: true | ||
| publish_hint: | ||
| description: 'Shown when no baseline is cached yet, naming what publishes one' | ||
| required: true | ||
| artifact_name: | ||
| description: 'Name of the uploaded diff artifact' | ||
| required: true | ||
|
|
||
| runs: | ||
| using: composite | ||
| steps: | ||
| - run: mv /tmp/manifest.txt /tmp/current-manifest.txt | ||
| shell: bash | ||
|
|
||
| - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | ||
| with: | ||
| path: /tmp/manifest.txt | ||
| key: ${{ inputs.key_prefix }}- | ||
| restore-keys: ${{ inputs.key_prefix }}- | ||
|
|
||
| - shell: bash | ||
| env: | ||
| PUBLISH_HINT: ${{ inputs.publish_hint }} | ||
| run: nix run .#manifest-diff -- /tmp/manifest.txt /tmp/current-manifest.txt "$PUBLISH_HINT" /tmp/manifest-diff.txt | ||
|
|
||
| - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 | ||
| with: | ||
| name: ${{ inputs.artifact_name }} | ||
| path: /tmp/manifest-diff.txt | ||
| retention-days: 7 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,50 @@ | ||
| name: Post manifest comment | ||
| description: Assembles per-leg manifest diffs into one collapsed comment and posts it, updating any existing one in place | ||
|
|
||
| inputs: | ||
| marker: | ||
| description: 'Unique HTML comment marker identifying this comment (e.g. ami-manifest-diff)' | ||
| required: true | ||
| title: | ||
| description: 'Comment heading (e.g. AMI manifest diff)' | ||
| required: true | ||
| artifact_pattern: | ||
| description: 'Glob matching the uploaded per-leg diff artifacts (e.g. ami-manifest-diff-*)' | ||
| required: true | ||
|
|
||
| runs: | ||
| using: composite | ||
| steps: | ||
| - uses: ./.github/actions/nix-install-ephemeral | ||
|
|
||
| - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 | ||
| with: | ||
| pattern: ${{ inputs.artifact_pattern }} | ||
| path: diffs | ||
|
|
||
| - id: render | ||
| shell: bash | ||
| env: | ||
| MARKER: ${{ inputs.marker }} | ||
| TITLE: ${{ inputs.title }} | ||
| ARTIFACT_PATTERN: ${{ inputs.artifact_pattern }} | ||
| RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} | ||
| run: | | ||
| PREFIX="${ARTIFACT_PATTERN%-\*}" | ||
| nix run .#manifest-comment -- "$MARKER" "$TITLE" "$PREFIX" "$RUN_URL" > /tmp/comment.md | ||
| [ -s /tmp/comment.md ] && echo "has_comment=true" >> "$GITHUB_OUTPUT" || true | ||
|
|
||
| - uses: peter-evans/find-comment@v3 | ||
| id: fc | ||
| if: steps.render.outputs.has_comment == 'true' | ||
| with: | ||
| issue-number: ${{ github.event.pull_request.number }} | ||
| body-includes: "<!-- ${{ inputs.marker }} -->" | ||
|
|
||
| - uses: peter-evans/create-or-update-comment@v4 | ||
| if: steps.render.outputs.has_comment == 'true' | ||
| with: | ||
| comment-id: ${{ steps.fc.outputs.comment-id }} | ||
| issue-number: ${{ github.event.pull_request.number }} | ||
| body-path: /tmp/comment.md | ||
| edit-mode: replace |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,47 @@ | ||
| { | ||
| writeShellApplication, | ||
| coreutils, | ||
| }: | ||
| writeShellApplication { | ||
| name = "manifest-comment"; | ||
| runtimeInputs = [ | ||
| coreutils | ||
| ]; | ||
| text = '' | ||
| if [ "$#" -lt 4 ]; then | ||
| echo "Usage: manifest-comment <marker> <title> <diffs_prefix> <run_url>" >&2 | ||
| exit 1 | ||
| fi | ||
| shopt -s nullglob | ||
| MARKER="$1" | ||
| TITLE="$2" | ||
| PREFIX="$3" | ||
| RUN_URL="$4" | ||
|
|
||
| fence=$'\x60\x60\x60' | ||
| dirs=("diffs/''${PREFIX}"-*) | ||
| if [ "''${#dirs[@]}" -eq 0 ]; then | ||
| exit 0 | ||
| fi | ||
|
|
||
| echo "<!-- $MARKER -->" | ||
| echo "## $TITLE" | ||
| echo | ||
|
|
||
| for dir in "''${dirs[@]}"; do | ||
| leg="''${dir#diffs/"''${PREFIX}"-}" | ||
| file="$dir/manifest-diff.txt" | ||
| first="$(head -1 "$file")" | ||
| if [[ "$first" != "baseline: "* ]]; then | ||
| printf '<details>\n<summary>%s: %s</summary>\n</details>\n\n' "$leg" "$first" | ||
| continue | ||
| fi | ||
| body="$(tail -n +2 "$file")" | ||
| printf '<details>\n<summary>%s: changed (%s)</summary>\n\n%sdiff\n%s\n%s\n' "$leg" "$first" "$fence" "''${body:0:6000}" "$fence" | ||
| if [ "''${#body}" -gt 6000 ]; then | ||
| echo "truncated, [full output]($RUN_URL)" | ||
| fi | ||
| printf '</details>\n\n' | ||
| done | ||
| ''; | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,48 @@ | ||
| { | ||
| writeShellApplication, | ||
| diffutils, | ||
| gnused, | ||
| coreutils, | ||
| }: | ||
| writeShellApplication { | ||
| name = "manifest-diff"; | ||
| runtimeInputs = [ | ||
| diffutils | ||
| gnused | ||
| coreutils | ||
| ]; | ||
| text = '' | ||
| if [ "$#" -lt 4 ]; then | ||
| echo "Usage: manifest-diff <manifest_path> <current_manifest_path> <publish_hint> <diff_path>" >&2 | ||
| exit 1 | ||
| fi | ||
| MANIFEST_PATH="$1" | ||
| CURRENT_MANIFEST_PATH="$2" | ||
| PUBLISH_HINT="$3" | ||
| DIFF_PATH="$4" | ||
|
|
||
| if [ -s "$MANIFEST_PATH" ]; then | ||
| mv "$MANIFEST_PATH" /tmp/baseline-raw.txt | ||
| BASELINE_VERSION=$(sed -n 's/^# version: //p' /tmp/baseline-raw.txt | head -1) | ||
| tail -n +2 /tmp/baseline-raw.txt > /tmp/baseline.txt | ||
| else | ||
| touch /tmp/baseline.txt | ||
| BASELINE_VERSION="" | ||
| fi | ||
| mv "$CURRENT_MANIFEST_PATH" "$MANIFEST_PATH" | ||
| { | ||
| if [ -z "$BASELINE_VERSION" ]; then | ||
| echo "No baseline cached yet. $PUBLISH_HINT" | ||
| elif diff -q /tmp/baseline.txt "$MANIFEST_PATH" > /dev/null; then | ||
| echo "No changes vs baseline $BASELINE_VERSION." | ||
| else | ||
| echo "baseline: $BASELINE_VERSION" | ||
| diff \ | ||
| --old-line-format='-%L' \ | ||
| --new-line-format='+%L' \ | ||
| --unchanged-group-format=$'... %dn unchanged\n' \ | ||
| /tmp/baseline.txt "$MANIFEST_PATH" || true | ||
| fi | ||
| } | tee "$DIFF_PATH" | ||
| ''; | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.