Makefile 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319
  1. # set the shell to bash always
  2. SHELL := /bin/bash
  3. # set make and shell flags to exit on errors
  4. MAKEFLAGS += --warn-undefined-variables
  5. .SHELLFLAGS := -euo pipefail -c
  6. ARCH ?= amd64 arm64
  7. BUILD_ARGS ?= CGO_ENABLED=0
  8. DOCKER_BUILD_ARGS ?=
  9. DOCKERFILE ?= Dockerfile
  10. # default target is build
  11. .DEFAULT_GOAL := all
  12. .PHONY: all
  13. all: $(addprefix build-,$(ARCH))
  14. # Image registry for build/push image targets
  15. export IMAGE_REGISTRY ?= ghcr.io
  16. export IMAGE_REPO ?= external-secrets/external-secrets
  17. export IMAGE_NAME ?= $(IMAGE_REGISTRY)/$(IMAGE_REPO)
  18. BUNDLE_DIR ?= deploy/crds
  19. CRD_DIR ?= config/crds
  20. HELM_DIR ?= deploy/charts/external-secrets
  21. TF_DIR ?= terraform
  22. OUTPUT_DIR ?= bin
  23. # Get the currently used golang install path (in GOPATH/bin, unless GOBIN is set)
  24. ifeq (,$(shell go env GOBIN))
  25. GOBIN=$(shell go env GOPATH)/bin
  26. else
  27. GOBIN=$(shell go env GOBIN)
  28. endif
  29. # check if there are any existing `git tag` values
  30. ifeq ($(shell git tag),)
  31. # no tags found - default to initial tag `v0.0.0`
  32. export VERSION := $(shell echo "v0.0.0-$$(git rev-list HEAD --count)-g$$(git describe --dirty --always)" | sed 's/-/./2' | sed 's/-/./2')
  33. else
  34. # use tags
  35. export VERSION := $(shell git describe --dirty --always --tags --exclude 'helm*' | sed 's/-/./2' | sed 's/-/./2')
  36. endif
  37. TAG_SUFFIX ?=
  38. export IMAGE_TAG ?= $(VERSION)$(TAG_SUFFIX)
  39. # ====================================================================================
  40. # Colors
  41. BLUE := $(shell printf "\033[34m")
  42. YELLOW := $(shell printf "\033[33m")
  43. RED := $(shell printf "\033[31m")
  44. GREEN := $(shell printf "\033[32m")
  45. CNone := $(shell printf "\033[0m")
  46. # ====================================================================================
  47. # Logger
  48. TIME_LONG = `date +%Y-%m-%d' '%H:%M:%S`
  49. TIME_SHORT = `date +%H:%M:%S`
  50. TIME = $(TIME_SHORT)
  51. INFO = echo ${TIME} ${BLUE}[ .. ]${CNone}
  52. WARN = echo ${TIME} ${YELLOW}[WARN]${CNone}
  53. ERR = echo ${TIME} ${RED}[FAIL]${CNone}
  54. OK = echo ${TIME} ${GREEN}[ OK ]${CNone}
  55. FAIL = (echo ${TIME} ${RED}[FAIL]${CNone} && false)
  56. # ====================================================================================
  57. # Conformance
  58. reviewable: generate docs manifests helm.generate helm.docs lint ## Ensure a PR is ready for review.
  59. @go mod tidy
  60. @cd e2e/ && go mod tidy
  61. check-diff: reviewable ## Ensure branch is clean.
  62. @$(INFO) checking that branch is clean
  63. @test -z "$$(git status --porcelain)" || (echo "$$(git status --porcelain)" && $(FAIL))
  64. @$(OK) branch is clean
  65. update-deps:
  66. go get -u
  67. cd e2e && go get -u
  68. @go mod tidy
  69. @cd e2e/ && go mod tidy
  70. # ====================================================================================
  71. # Golang
  72. .PHONY: test
  73. test: generate envtest ## Run tests
  74. @$(INFO) go test unit-tests
  75. KUBEBUILDER_ASSETS="$(shell $(ENVTEST) use $(KUBERNETES_VERSION) -p path --bin-dir $(LOCALBIN))" go test -race -v $(shell go list ./... | grep -v e2e) -coverprofile cover.out
  76. @$(OK) go test unit-tests
  77. .PHONY: test.e2e
  78. test.e2e: generate ## Run e2e tests
  79. @$(INFO) go test e2e-tests
  80. $(MAKE) -C ./e2e test
  81. @$(OK) go test e2e-tests
  82. .PHONY: test.e2e.managed
  83. test.e2e.managed: generate ## Run e2e tests managed
  84. @$(INFO) go test e2e-tests-managed
  85. $(MAKE) -C ./e2e test.managed
  86. @$(OK) go test e2e-tests-managed
  87. .PHONY: build
  88. build: $(addprefix build-,$(ARCH)) ## Build binary
  89. .PHONY: build-%
  90. build-%: generate ## Build binary for the specified arch
  91. @$(INFO) go build $*
  92. $(BUILD_ARGS) GOOS=linux GOARCH=$* \
  93. go build -o '$(OUTPUT_DIR)/external-secrets-linux-$*' main.go
  94. @$(OK) go build $*
  95. lint: golangci-lint ## Run golangci-lint
  96. @if ! $(GOLANGCI_LINT) run; then \
  97. echo -e "\033[0;33mgolangci-lint failed: some checks can be fixed with \`\033[0;32mmake fmt\033[0m\033[0;33m\`\033[0m"; \
  98. exit 1; \
  99. fi
  100. @$(OK) Finished linting
  101. fmt: golangci-lint ## Ensure consistent code style
  102. @go mod tidy
  103. @cd e2e/ && go mod tidy
  104. @go fmt ./...
  105. @$(GOLANGCI_LINT) run --fix
  106. @$(OK) Ensured consistent code style
  107. generate: ## Generate code and crds
  108. @./hack/crd.generate.sh $(BUNDLE_DIR) $(CRD_DIR)
  109. @$(OK) Finished generating deepcopy and crds
  110. # ====================================================================================
  111. # Local Utility
  112. # This is for running out-of-cluster locally, and is for convenience.
  113. # For more control, try running the binary directly with different arguments.
  114. run: generate ## Run app locally (without a k8s cluster)
  115. go run ./main.go
  116. manifests: helm.generate ## Generate manifests from helm chart
  117. mkdir -p $(OUTPUT_DIR)/deploy/manifests
  118. helm template external-secrets $(HELM_DIR) -f deploy/manifests/helm-values.yaml > $(OUTPUT_DIR)/deploy/manifests/external-secrets.yaml
  119. crds.install: generate ## Install CRDs into a cluster. This is for convenience
  120. kubectl apply -f $(BUNDLE_DIR)
  121. crds.uninstall: ## Uninstall CRDs from a cluster. This is for convenience
  122. kubectl delete -f $(BUNDLE_DIR)
  123. # ====================================================================================
  124. # Helm Chart
  125. helm.docs: ## Generate helm docs
  126. @cd $(HELM_DIR); \
  127. docker run --rm -v $(shell pwd)/$(HELM_DIR):/helm-docs -u $(shell id -u) jnorwood/helm-docs:v1.5.0
  128. HELM_VERSION ?= $(shell helm show chart $(HELM_DIR) | grep 'version:' | sed 's/version: //g')
  129. helm.build: helm.generate ## Build helm chart
  130. @$(INFO) helm package
  131. @helm package $(HELM_DIR) --dependency-update --destination $(OUTPUT_DIR)/chart
  132. @mv $(OUTPUT_DIR)/chart/external-secrets-$(HELM_VERSION).tgz $(OUTPUT_DIR)/chart/external-secrets.tgz
  133. @$(OK) helm package
  134. helm.generate:
  135. ./hack/helm.generate.sh $(BUNDLE_DIR) $(HELM_DIR)
  136. @$(OK) Finished generating helm chart files
  137. helm.test: helm.generate
  138. @helm unittest --file tests/*.yaml --file 'tests/**/*.yaml' deploy/charts/external-secrets/
  139. helm.test.update: helm.generate
  140. @helm unittest -u --file tests/*.yaml --file 'tests/**/*.yaml' deploy/charts/external-secrets/
  141. helm.update.appversion:
  142. @chartversion=$$(yq .version ./deploy/charts/external-secrets/Chart.yaml) ; \
  143. chartappversion=$$(yq .appVersion ./deploy/charts/external-secrets/Chart.yaml) ; \
  144. chartname=$$(yq .name ./deploy/charts/external-secrets/Chart.yaml) ; \
  145. $(INFO) Update chartname and chartversion string in test snapshots.; \
  146. sed -s -i "s/^\([[:space:]]\+helm\.sh\/chart:\).*/\1 $${chartname}-$${chartversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  147. sed -s -i "s/^\([[:space:]]\+app\.kubernetes\.io\/version:\).*/\1 $${chartappversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  148. sed -s -i "s/^\([[:space:]]\+image: ghcr\.io\/external-secrets\/external-secrets:\).*/\1$${chartappversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  149. $(OK) "Version strings updated"
  150. # ====================================================================================
  151. # Documentation
  152. .PHONY: docs
  153. docs: generate ## Generate docs
  154. $(MAKE) -C ./hack/api-docs build
  155. .PHONY: docs.publish
  156. docs.publish: generate ## Generate and deploys docs
  157. $(MAKE) -C ./hack/api-docs build.publish
  158. .PHONY: docs.serve
  159. docs.serve: ## Serve docs
  160. $(MAKE) -C ./hack/api-docs serve
  161. # ====================================================================================
  162. # Build Artifacts
  163. .PHONY: build.all
  164. build.all: docker.build helm.build ## Build all artifacts (docker image, helm chart)
  165. .PHONY: docker.image
  166. docker.image: ## Emit IMAGE_NAME:IMAGE_TAG
  167. @echo $(IMAGE_NAME):$(IMAGE_TAG)
  168. .PHONY: docker.imagename
  169. docker.imagename: ## Emit IMAGE_NAME
  170. @echo $(IMAGE_NAME)
  171. .PHONY: docker.tag
  172. docker.tag: ## Emit IMAGE_TAG
  173. @echo $(IMAGE_TAG)
  174. .PHONY: docker.build
  175. docker.build: $(addprefix build-,$(ARCH)) ## Build the docker image
  176. @$(INFO) docker build
  177. echo docker build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  178. DOCKER_BUILDKIT=1 docker build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  179. @$(OK) docker build
  180. .PHONY: docker.push
  181. docker.push: ## Push the docker image to the registry
  182. @$(INFO) docker push
  183. @docker push $(IMAGE_NAME):$(IMAGE_TAG)
  184. @$(OK) docker push
  185. # RELEASE_TAG is tag to promote. Default is promoting to main branch, but can be overriden
  186. # to promote a tag to a specific version.
  187. RELEASE_TAG ?= $(IMAGE_TAG)
  188. SOURCE_TAG ?= $(VERSION)$(TAG_SUFFIX)
  189. .PHONY: docker.promote
  190. docker.promote: ## Promote the docker image to the registry
  191. @$(INFO) promoting $(SOURCE_TAG) to $(RELEASE_TAG)
  192. docker manifest inspect --verbose $(IMAGE_NAME):$(SOURCE_TAG) > .tagmanifest
  193. for digest in $$(jq -r 'if type=="array" then .[].Descriptor.digest else .Descriptor.digest end' < .tagmanifest); do \
  194. docker pull $(IMAGE_NAME)@$$digest; \
  195. done
  196. docker manifest create $(IMAGE_NAME):$(RELEASE_TAG) \
  197. $$(jq -j '"--amend $(IMAGE_NAME)@" + if type=="array" then .[].Descriptor.digest else .Descriptor.digest end + " "' < .tagmanifest)
  198. docker manifest push $(IMAGE_NAME):$(RELEASE_TAG)
  199. @$(OK) docker push $(RELEASE_TAG) \
  200. # ====================================================================================
  201. # Terraform
  202. tf.plan.%: ## Runs terrform plan for a provider
  203. @cd $(TF_DIR)/$*; \
  204. terraform init; \
  205. terraform plan
  206. tf.apply.%: ## Runs terrform apply for a provider
  207. @cd $(TF_DIR)/$*; \
  208. terraform init; \
  209. terraform apply -auto-approve
  210. tf.destroy.%: ## Runs terrform destroy for a provider
  211. @cd $(TF_DIR)/$*; \
  212. terraform init; \
  213. terraform destroy -auto-approve
  214. tf.show.%: ## Runs terrform show for a provider and outputs to a file
  215. @cd $(TF_DIR)/$*; \
  216. terraform init; \
  217. terraform plan -out tfplan.binary; \
  218. terraform show -json tfplan.binary > plan.json
  219. # ====================================================================================
  220. # Help
  221. .PHONY: help
  222. # only comments after make target name are shown as help text
  223. help: ## Displays this help message
  224. @echo -e "$$(grep -hE '^\S+:.*##' $(MAKEFILE_LIST) | sed -e 's/:.*##\s*/|/' -e 's/^\(.\+\):\(.*\)/\\x1b[36m\1\\x1b[m:\2/' | column -c2 -t -s'|' | sort)"
  225. .PHONY: clean
  226. clean: ## Clean bins
  227. @$(INFO) clean
  228. @rm -f $(OUTPUT_DIR)/external-secrets-linux-*
  229. @$(OK) go build $*
  230. # ====================================================================================
  231. # Build Dependencies
  232. ## Location to install dependencies to
  233. LOCALBIN ?= $(shell pwd)/bin
  234. $(LOCALBIN):
  235. mkdir -p $(LOCALBIN)
  236. ## Tool Binaries
  237. ENVTEST ?= $(LOCALBIN)/setup-envtest
  238. GOLANGCI_LINT ?= $(LOCALBIN)/golangci-lint
  239. ## Tool Versions
  240. GOLANGCI_VERSION := 1.52.2
  241. KUBERNETES_VERSION := 1.28.x
  242. .PHONY: envtest
  243. envtest: $(ENVTEST) ## Download envtest-setup locally if necessary.
  244. $(ENVTEST): $(LOCALBIN)
  245. test -s $(LOCALBIN)/setup-envtest || GOBIN=$(LOCALBIN) go install sigs.k8s.io/controller-runtime/tools/setup-envtest@latest
  246. .PHONY: golangci-lint
  247. .PHONY: $(GOLANGCI_LINT)
  248. golangci-lint: $(GOLANGCI_LINT) ## Download golangci-lint locally if necessary.
  249. $(GOLANGCI_LINT): $(LOCALBIN)
  250. test -s $(LOCALBIN)/golangci-lint && $(LOCALBIN)/golangci-lint version --format short | grep -q $(GOLANGCI_VERSION) || \
  251. curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(LOCALBIN) v$(GOLANGCI_VERSION)