Skip to content

Updatecli: Dependency Management #1193

Updatecli: Dependency Management

Updatecli: Dependency Management #1193

Workflow file for this run

name: "Updatecli: Dependency Management"
on:
schedule:
# Runs at 06 PM UTC
- cron: '0 18 * * *'
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
permissions:
contents: write
issues: write
pull-requests: write
id-token: write # for vault authentication
jobs:
updatecli:
runs-on: ubuntu-latest
# if you want to testupdatecli on another branch, you also need to modify updatecli/values.yaml
if: ${{github.ref == 'refs/heads/main-source' && github.repository == 'rancher/rke2-charts'}}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Install Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: 'stable'
- name: Install Updatecli
uses: updatecli/updatecli-action@d422ba543720d01a96d4c3e3ab8544cc188cd711 # v3.5.0
- name: Read Secrets for the Github App
uses: rancher-eio/read-vault-secrets@0da85151ad1f19ed7986c41587e45aac1ace74b6 # v3
with:
secrets: |
secret/data/github/repo/${{ github.repository }}/issues-manager/github/app-credentials appId | CREATE_ISSUE_APP_ID ;
secret/data/github/repo/${{ github.repository }}/issues-manager/github/app-credentials privateKey | CREATE_ISSUE_PRIVATE_KEY
- name: Get Github App token
id: get_token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ env.CREATE_ISSUE_APP_ID }}
private-key: ${{ env.CREATE_ISSUE_PRIVATE_KEY }}
owner: rancher
repositories: |
rke2
- name: Delete leftover UpdateCLI branches
run: |
gh pr list \
--search "is:closed is:pr head:updatecli_" \
--json headRefName \
--jq ".[].headRefName" | sort -u > closed_prs_branches.txt
gh pr list \
--search "is:open is:pr head:updatecli_" \
--json headRefName \
--jq ".[].headRefName" | sort -u > open_prs_branches.txt
for branch in $(comm -23 closed_prs_branches.txt open_prs_branches.txt); do
if (git ls-remote --exit-code --heads origin "$branch"); then
echo "Deleting leftover UpdateCLI branch - $branch";
git push origin --delete "$branch";
fi
done
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Apply Updatecli
# Never use '--debug' option, because it might leak the access tokens.
run: "updatecli pipeline apply --clean --config ./updatecli/updatecli.d/ --values ./updatecli/values.yaml"
env:
UPDATECLI_GITHUB_ACTOR: ${{ github.actor }}
UPDATECLI_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
UPDATECLI_GITHUB_WORKFLOW_URL: "https://github.com/${{github.repository}}/actions/runs/${{github.run_id}}"
GH_TOKEN: ${{ steps.get_token.outputs.token }}