Makefile 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406
  1. # set the shell to bash always
  2. SHELL := /bin/bash
  3. # set make and shell flags to exit on errors
  4. MAKEFLAGS += --warn-undefined-variables
  5. .SHELLFLAGS := -euo pipefail -c
  6. ARCH ?= amd64 arm64 ppc64le
  7. BUILD_ARGS ?= CGO_ENABLED=0
  8. DOCKER_BUILD_ARGS ?=
  9. DOCKERFILE ?= Dockerfile
  10. DOCKER ?= docker
  11. # default target is build
  12. .DEFAULT_GOAL := all
  13. .PHONY: all
  14. all: $(addprefix build-,$(ARCH))
  15. # Image registry for build/push image targets
  16. export IMAGE_REGISTRY ?= ghcr.io
  17. export IMAGE_REPO ?= external-secrets/external-secrets
  18. export IMAGE_NAME ?= $(IMAGE_REGISTRY)/$(IMAGE_REPO)
  19. BUNDLE_DIR ?= deploy/crds
  20. CRD_DIR ?= config/crds
  21. HELM_DIR ?= deploy/charts/external-secrets
  22. TF_DIR ?= terraform
  23. OUTPUT_DIR ?= bin
  24. # Get the currently used golang install path (in GOPATH/bin, unless GOBIN is set)
  25. ifeq (,$(shell go env GOBIN))
  26. GOBIN=$(shell go env GOPATH)/bin
  27. else
  28. GOBIN=$(shell go env GOBIN)
  29. endif
  30. # check if there are any existing `git tag` values
  31. ifeq ($(shell git tag),)
  32. # no tags found - default to initial tag `v0.0.0`
  33. export VERSION := $(shell echo "v0.0.0-$$(git rev-list HEAD --count)-g$$(git describe --dirty --always)" | sed 's/-/./2' | sed 's/-/./2')
  34. else
  35. # use tags
  36. export VERSION := $(shell git describe --dirty --always --tags --exclude 'helm*' | sed 's/-/./2' | sed 's/-/./2')
  37. endif
  38. TAG_SUFFIX ?=
  39. export IMAGE_TAG ?= $(VERSION)$(TAG_SUFFIX)
  40. # ====================================================================================
  41. # Colors
  42. BLUE := $(shell printf "\033[34m")
  43. YELLOW := $(shell printf "\033[33m")
  44. RED := $(shell printf "\033[31m")
  45. GREEN := $(shell printf "\033[32m")
  46. CNone := $(shell printf "\033[0m")
  47. # ====================================================================================
  48. # Logger
  49. TIME_LONG = `date +%Y-%m-%d' '%H:%M:%S`
  50. TIME_SHORT = `date +%H:%M:%S`
  51. TIME = $(TIME_SHORT)
  52. INFO = echo ${TIME} ${BLUE}[ .. ]${CNone}
  53. WARN = echo ${TIME} ${YELLOW}[WARN]${CNone}
  54. ERR = echo ${TIME} ${RED}[FAIL]${CNone}
  55. OK = echo ${TIME} ${GREEN}[ OK ]${CNone}
  56. FAIL = (echo ${TIME} ${RED}[FAIL]${CNone} && false)
  57. # ====================================================================================
  58. # Conformance
  59. reviewable: generate docs manifests helm.generate helm.schema.update helm.docs lint ## Ensure a PR is ready for review.
  60. @go mod tidy
  61. @cd e2e/ && go mod tidy
  62. check-diff: reviewable ## Ensure branch is clean.
  63. @$(INFO) checking that branch is clean
  64. @test -z "$$(git status --porcelain)" || (echo "$$(git status --porcelain)" && $(FAIL))
  65. @$(OK) branch is clean
  66. update-deps:
  67. go get -u
  68. cd e2e && go get -u
  69. @go mod tidy
  70. @cd e2e/ && go mod tidy
  71. # ====================================================================================
  72. # Golang
  73. .PHONY: test
  74. test: generate envtest ## Run tests
  75. @$(INFO) go test unit-tests
  76. KUBEBUILDER_ASSETS="$(shell $(ENVTEST) use $(KUBERNETES_VERSION) -p path --bin-dir $(LOCALBIN))" go test -race -v $(shell go list ./... | grep -v e2e) -coverprofile cover.out
  77. @$(OK) go test unit-tests
  78. .PHONY: test.e2e
  79. test.e2e: generate ## Run e2e tests
  80. @$(INFO) go test e2e-tests
  81. $(MAKE) -C ./e2e test
  82. @$(OK) go test e2e-tests
  83. .PHONY: test.e2e.managed
  84. test.e2e.managed: generate ## Run e2e tests managed
  85. @$(INFO) go test e2e-tests-managed
  86. $(MAKE) -C ./e2e test.managed
  87. @$(OK) go test e2e-tests-managed
  88. .PHONY: test.crds
  89. test.crds: cty crds.generate.tests ## Test CRDs for modification and backwards compatibility
  90. @$(INFO) $(CTY) test tests
  91. $(CTY) test tests
  92. @$(OK) No breaking CRD changes detected
  93. .PHONY: test.crds.update
  94. test.crds.update: cty crds.generate.tests ## Update the snapshots used by the CRD tests
  95. @$(INFO) $(CTY) test tests -u
  96. $(CTY) test tests -u
  97. @$(OK) Successfully updated all test snapshots
  98. .PHONY: build
  99. build: $(addprefix build-,$(ARCH)) ## Build binary
  100. .PHONY: build-%
  101. build-%: generate ## Build binary for the specified arch
  102. @$(INFO) go build $*
  103. $(BUILD_ARGS) GOOS=linux GOARCH=$* \
  104. go build -o '$(OUTPUT_DIR)/external-secrets-linux-$*' main.go
  105. @$(OK) go build $*
  106. lint: golangci-lint ## Run golangci-lint
  107. @if ! $(GOLANGCI_LINT) run; then \
  108. echo -e "\033[0;33mgolangci-lint failed: some checks can be fixed with \`\033[0;32mmake fmt\033[0m\033[0;33m\`\033[0m"; \
  109. exit 1; \
  110. fi
  111. @$(OK) Finished linting
  112. fmt: golangci-lint ## Ensure consistent code style
  113. @go mod tidy
  114. @cd e2e/ && go mod tidy
  115. @go fmt ./...
  116. @$(GOLANGCI_LINT) run --fix
  117. @$(OK) Ensured consistent code style
  118. generate: ## Generate code and crds
  119. @./hack/crd.generate.sh $(BUNDLE_DIR) $(CRD_DIR)
  120. @$(OK) Finished generating deepcopy and crds
  121. # ====================================================================================
  122. # Local Utility
  123. # This is for running out-of-cluster locally, and is for convenience.
  124. # For more control, try running the binary directly with different arguments.
  125. run: generate ## Run app locally (without a k8s cluster)
  126. go run ./main.go
  127. manifests: helm.generate ## Generate manifests from helm chart
  128. mkdir -p $(OUTPUT_DIR)/deploy/manifests
  129. helm dependency build $(HELM_DIR)
  130. helm template external-secrets $(HELM_DIR) -f deploy/manifests/helm-values.yaml > $(OUTPUT_DIR)/deploy/manifests/external-secrets.yaml
  131. crds.install: generate ## Install CRDs into a cluster. This is for convenience
  132. kubectl apply -f $(BUNDLE_DIR) --server-side
  133. crds.uninstall: ## Uninstall CRDs from a cluster. This is for convenience
  134. kubectl delete -f $(BUNDLE_DIR)
  135. crds.generate.tests:
  136. ./hack/test.crds.generate.sh $(BUNDLE_DIR) tests/crds
  137. @$(OK) Finished generating crds for testing
  138. tilt-up: tilt manifests ## Generates the local manifests that tilt will use to deploy the controller's objects.
  139. $(LOCALBIN)/tilt up
  140. # ====================================================================================
  141. # Helm Chart
  142. helm.docs: ## Generate helm docs
  143. @cd $(HELM_DIR); \
  144. $(DOCKER) run --rm -v $(shell pwd)/$(HELM_DIR):/helm-docs -u $(shell id -u) docker.io/jnorwood/helm-docs:v1.7.0
  145. HELM_VERSION ?= $(shell helm show chart $(HELM_DIR) | grep '^version:' | sed 's/version: //g')
  146. helm.build: helm.generate ## Build helm chart
  147. @$(INFO) helm package
  148. @helm package $(HELM_DIR) --dependency-update --destination $(OUTPUT_DIR)/chart
  149. @mv $(OUTPUT_DIR)/chart/external-secrets-$(HELM_VERSION).tgz $(OUTPUT_DIR)/chart/external-secrets.tgz
  150. @$(OK) helm package
  151. HELM_SCHEMA_NAME := schema
  152. HELM_SCHEMA_VER := 2.2.1
  153. HELM_SCHEMA_URL := https://github.com/losisin/helm-values-schema-json.git
  154. helm.schema.plugin:
  155. @v=$$(helm plugin list | awk '$$1=="$(HELM_SCHEMA_NAME)"{print $$2}'); \
  156. if [ -z "$$v" ]; then \
  157. $(INFO) "Installing $(HELM_SCHEMA_NAME) v$(HELM_SCHEMA_VER)"; \
  158. helm plugin install --version $(HELM_SCHEMA_VER) $(HELM_SCHEMA_URL); \
  159. $(OK) "Installed $(HELM_SCHEMA_NAME) v$(HELM_SCHEMA_VER)"; \
  160. elif [ "$$v" != "$(HELM_SCHEMA_VER)" ]; then \
  161. $(INFO) "Found $(HELM_SCHEMA_NAME) $$v. Reinstalling v$(HELM_SCHEMA_VER)"; \
  162. helm plugin remove $(HELM_SCHEMA_NAME); \
  163. helm plugin install --version $(HELM_SCHEMA_VER) $(HELM_SCHEMA_URL); \
  164. $(OK) "Reinstalled $(HELM_SCHEMA_NAME) v$(HELM_SCHEMA_VER)"; \
  165. else \
  166. $(OK) "$(HELM_SCHEMA_NAME) already at v$(HELM_SCHEMA_VER)"; \
  167. fi
  168. helm.schema.update: helm.schema.plugin
  169. @$(INFO) Generating values.schema.json
  170. @helm schema -f $(HELM_DIR)/values.yaml -o $(HELM_DIR)/values.schema.json
  171. @$(OK) Generated values.schema.json
  172. helm.generate:
  173. ./hack/helm.generate.sh $(BUNDLE_DIR) $(HELM_DIR)
  174. @$(OK) Finished generating helm chart files
  175. helm.test: helm.generate
  176. @helm unittest deploy/charts/external-secrets/
  177. helm.test.update: helm.generate
  178. @helm unittest -u deploy/charts/external-secrets/
  179. helm.update.appversion:
  180. @chartversion=$$(yq .version ./deploy/charts/external-secrets/Chart.yaml) ; \
  181. chartappversion=$$(yq .appVersion ./deploy/charts/external-secrets/Chart.yaml) ; \
  182. chartname=$$(yq .name ./deploy/charts/external-secrets/Chart.yaml) ; \
  183. $(INFO) Update chartname and chartversion string in test snapshots.; \
  184. sed -s -i "s/^\([[:space:]]\+helm\.sh\/chart:\).*/\1 $${chartname}-$${chartversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  185. sed -s -i "s/^\([[:space:]]\+app\.kubernetes\.io\/version:\).*/\1 $${chartappversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  186. sed -s -i "s/^\([[:space:]]\+image: ghcr\.io\/external-secrets\/external-secrets:\).*/\1$${chartappversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  187. $(OK) "Version strings updated"
  188. # ====================================================================================
  189. # Documentation
  190. .PHONY: docs
  191. docs: generate ## Generate docs
  192. $(MAKE) -C ./hack/api-docs build
  193. .PHONY: docs.publish
  194. docs.publish: generate ## Generate and deploys docs
  195. $(MAKE) -C ./hack/api-docs build.publish
  196. .PHONY: docs.serve
  197. docs.serve: ## Serve docs
  198. $(MAKE) -C ./hack/api-docs serve
  199. DOCS_VERSION ?= $(VERSION)
  200. .PHONY: docs.check
  201. docs.check: ## Check docs
  202. $(MAKE) -C ./hack/api-docs check DOCS_VERSION=$(DOCS_VERSION)
  203. .PHONY: docs.update
  204. docs.update: ## Update docs
  205. $(MAKE) -C ./hack/api-docs stability-support.update DOCS_VERSION=$(DOCS_VERSION)
  206. # ====================================================================================
  207. # Build Artifacts
  208. .PHONY: build.all
  209. build.all: docker.build helm.build ## Build all artifacts (docker image, helm chart)
  210. .PHONY: docker.image
  211. docker.image: ## Emit IMAGE_NAME:IMAGE_TAG
  212. @echo $(IMAGE_NAME):$(IMAGE_TAG)
  213. .PHONY: docker.imagename
  214. docker.imagename: ## Emit IMAGE_NAME
  215. @echo $(IMAGE_NAME)
  216. .PHONY: docker.tag
  217. docker.tag: ## Emit IMAGE_TAG
  218. @echo $(IMAGE_TAG)
  219. .PHONY: docker.build
  220. docker.build: $(addprefix build-,$(ARCH)) ## Build the docker image
  221. @$(INFO) $(DOCKER) build
  222. echo $(DOCKER) build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  223. DOCKER_BUILDKIT=1 $(DOCKER) build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  224. @$(OK) $(DOCKER) build
  225. .PHONY: docker.push
  226. docker.push: ## Push the docker image to the registry
  227. @$(INFO) $(DOCKER) push
  228. @$(DOCKER) push $(IMAGE_NAME):$(IMAGE_TAG)
  229. @$(OK) $(DOCKER) push
  230. # RELEASE_TAG is tag to promote. Default is promoting to main branch, but can be overriden
  231. # to promote a tag to a specific version.
  232. RELEASE_TAG ?= $(IMAGE_TAG)
  233. SOURCE_TAG ?= $(VERSION)$(TAG_SUFFIX)
  234. .PHONY: docker.promote
  235. docker.promote: ## Promote the docker image to the registry
  236. @$(INFO) promoting $(SOURCE_TAG) to $(RELEASE_TAG)
  237. $(DOCKER) manifest inspect --verbose $(IMAGE_NAME):$(SOURCE_TAG) > .tagmanifest
  238. for digest in $$(jq -r 'if type=="array" then .[].Descriptor.digest else .Descriptor.digest end' < .tagmanifest); do \
  239. $(DOCKER) pull $(IMAGE_NAME)@$$digest; \
  240. done
  241. $(DOCKER) manifest create $(IMAGE_NAME):$(RELEASE_TAG) \
  242. $$(jq -j '"--amend $(IMAGE_NAME)@" + if type=="array" then .[].Descriptor.digest else .Descriptor.digest end + " "' < .tagmanifest)
  243. $(DOCKER) manifest push $(IMAGE_NAME):$(RELEASE_TAG)
  244. @$(OK) $(DOCKER) push $(RELEASE_TAG) \
  245. # ====================================================================================
  246. # Terraform
  247. tf.plan.%: ## Runs terraform plan for a provider
  248. @cd $(TF_DIR)/$*; \
  249. terraform init; \
  250. terraform plan
  251. tf.apply.%: ## Runs terraform apply for a provider
  252. @cd $(TF_DIR)/$*; \
  253. terraform init; \
  254. terraform apply -auto-approve
  255. tf.destroy.%: ## Runs terraform destroy for a provider
  256. @cd $(TF_DIR)/$*; \
  257. terraform init; \
  258. terraform destroy -auto-approve
  259. tf.show.%: ## Runs terraform show for a provider and outputs to a file
  260. @cd $(TF_DIR)/$*; \
  261. terraform init; \
  262. terraform plan -out tfplan.binary; \
  263. terraform show -json tfplan.binary > plan.json
  264. # ====================================================================================
  265. # Help
  266. .PHONY: help
  267. # only comments after make target name are shown as help text
  268. help: ## Displays this help message
  269. @echo -e "$$(grep -hE '^\S+:.*##' $(MAKEFILE_LIST) | sed -e 's/:.*##\s*/|/' -e 's/^\(.\+\):\(.*\)/\\x1b[36m\1\\x1b[m:\2/' | column -c2 -t -s'|' | sort)"
  270. .PHONY: clean
  271. clean: ## Clean bins
  272. @$(INFO) clean
  273. @rm -f $(OUTPUT_DIR)/external-secrets-linux-*
  274. @$(OK) go build $*
  275. # ====================================================================================
  276. # Build Dependencies
  277. ifeq ($(OS),Windows_NT) # is Windows_NT on XP, 2000, 7, Vista, 10...
  278. detected_OS := windows
  279. real_OS := windows
  280. arch := x86_64
  281. else
  282. detected_OS := $(shell uname -s)
  283. real_OS := $(detected_OS)
  284. arch := $(shell uname -m)
  285. ifeq ($(detected_OS),Darwin)
  286. detected_OS := mac
  287. real_OS := darwin
  288. endif
  289. ifeq ($(detected_OS),Linux)
  290. detected_OS := linux
  291. real_OS := linux
  292. endif
  293. endif
  294. ## Location to install dependencies to
  295. LOCALBIN ?= $(shell pwd)/bin
  296. $(LOCALBIN):
  297. mkdir -p $(LOCALBIN)
  298. ## Tool Binaries
  299. TILT ?= $(LOCALBIN)/tilt
  300. CTY ?= $(LOCALBIN)/cty
  301. ENVTEST ?= $(LOCALBIN)/setup-envtest
  302. GOLANGCI_LINT ?= $(LOCALBIN)/golangci-lint
  303. ## Tool Versions
  304. GOLANGCI_VERSION := 2.1.6
  305. KUBERNETES_VERSION := 1.30.x
  306. TILT_VERSION := 0.33.21
  307. CTY_VERSION := 1.1.3
  308. .PHONY: envtest
  309. envtest: $(ENVTEST) ## Download envtest-setup locally if necessary.
  310. $(ENVTEST): $(LOCALBIN)
  311. test -s $(LOCALBIN)/setup-envtest || GOBIN=$(LOCALBIN) go install sigs.k8s.io/controller-runtime/tools/setup-envtest@latest
  312. .PHONY: golangci-lint
  313. .PHONY: $(GOLANGCI_LINT)
  314. golangci-lint: $(GOLANGCI_LINT) ## Download golangci-lint locally if necessary.
  315. $(GOLANGCI_LINT): $(LOCALBIN)
  316. test -s $(LOCALBIN)/golangci-lint && $(LOCALBIN)/golangci-lint version | grep -q $(GOLANGCI_VERSION) || \
  317. curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(LOCALBIN) v$(GOLANGCI_VERSION)
  318. .PHONY: tilt
  319. .PHONY: $(TILT)
  320. tilt: $(TILT) ## Download tilt locally if necessary. Architecture is locked at x86_64.
  321. $(TILT): $(LOCALBIN)
  322. test -s $(LOCALBIN)/tilt || curl -fsSL https://github.com/tilt-dev/tilt/releases/download/v$(TILT_VERSION)/tilt.$(TILT_VERSION).$(detected_OS).$(arch).tar.gz | tar -xz -C $(LOCALBIN) tilt
  323. .PHONY: cty
  324. .PHONY: $(CTY)
  325. cty: $(CTY) ## Download cty locally if necessary. Architecture is locked at x86_64.
  326. $(CTY): $(LOCALBIN)
  327. test -s $(LOCALBIN)/cty || curl -fsSL https://github.com/Skarlso/crd-to-sample-yaml/releases/download/v$(CTY_VERSION)/cty_$(real_OS)_amd64.tar.gz | tar -xz -C $(LOCALBIN) cty