Makefile 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588
  1. # set the shell to bash always
  2. SHELL := /usr/bin/env bash
  3. # set make and shell flags to exit on errors
  4. MAKEFLAGS += --warn-undefined-variables
  5. .SHELLFLAGS := -euo pipefail -c
  6. ARCH ?= amd64 arm64 ppc64le
  7. # Detect local architecture for e2e testing
  8. LOCAL_ARCH := $(shell uname -m)
  9. ifeq ($(LOCAL_ARCH),x86_64)
  10. LOCAL_GOARCH := amd64
  11. else ifeq ($(LOCAL_ARCH),aarch64)
  12. LOCAL_GOARCH := arm64
  13. else ifeq ($(LOCAL_ARCH),arm64)
  14. LOCAL_GOARCH := arm64
  15. else ifeq ($(LOCAL_ARCH),ppc64le)
  16. LOCAL_GOARCH := ppc64le
  17. else
  18. LOCAL_GOARCH := amd64
  19. endif
  20. BUILD_ARGS ?= CGO_ENABLED=0
  21. DOCKER_BUILD_ARGS ?=
  22. DOCKERFILE ?= Dockerfile
  23. DOCKER ?= docker
  24. # default target is build
  25. .DEFAULT_GOAL := all
  26. .PHONY: all
  27. all: $(addprefix build-,$(ARCH))
  28. # Image registry for build/push image targets
  29. export IMAGE_REGISTRY ?= ghcr.io
  30. export IMAGE_REPO ?= external-secrets/external-secrets
  31. export IMAGE_NAME ?= $(IMAGE_REGISTRY)/$(IMAGE_REPO)
  32. BUNDLE_DIR ?= deploy/crds
  33. CRD_DIR ?= config/crds
  34. HELM_DIR ?= deploy/charts/external-secrets
  35. TF_DIR ?= terraform
  36. OUTPUT_DIR ?= bin
  37. # Get the currently used golang install path (in GOPATH/bin, unless GOBIN is set)
  38. ifeq (,$(shell go env GOBIN))
  39. GOBIN=$(shell go env GOPATH)/bin
  40. else
  41. GOBIN=$(shell go env GOBIN)
  42. endif
  43. # check if there are any existing `git tag` values
  44. ifeq ($(shell git tag),)
  45. # no tags found - default to initial tag `v0.0.0`
  46. export VERSION := $(shell echo "v0.0.0-$$(git rev-list HEAD --count)-g$$(git describe --dirty --always)" | sed 's/-/./2' | sed 's/-/./2')
  47. else
  48. # use tags
  49. export VERSION := $(shell git describe --dirty --always --tags --exclude 'helm*' | sed 's/-/./2' | sed 's/-/./2')
  50. endif
  51. TAG_SUFFIX ?=
  52. export IMAGE_TAG ?= $(VERSION)$(TAG_SUFFIX)
  53. # ====================================================================================
  54. # Colors
  55. BLUE := $(shell printf "\033[34m")
  56. YELLOW := $(shell printf "\033[33m")
  57. RED := $(shell printf "\033[31m")
  58. GREEN := $(shell printf "\033[32m")
  59. CNone := $(shell printf "\033[0m")
  60. # ====================================================================================
  61. # Logger
  62. TIME_LONG = `date +%Y-%m-%d' '%H:%M:%S`
  63. TIME_SHORT = `date +%H:%M:%S`
  64. TIME = $(TIME_SHORT)
  65. INFO = echo ${TIME} ${BLUE}[ .. ]${CNone}
  66. WARN = echo ${TIME} ${YELLOW}[WARN]${CNone}
  67. ERR = echo ${TIME} ${RED}[FAIL]${CNone}
  68. OK = echo ${TIME} ${GREEN}[ OK ]${CNone}
  69. FAIL = (echo ${TIME} ${RED}[FAIL]${CNone} && false)
  70. # ====================================================================================
  71. # Protobuf
  72. .PHONY: proto
  73. proto: ## Generate protobuf code
  74. @$(INFO) generating protobuf code
  75. @protoc --go_out=. --go_opt=paths=source_relative \
  76. --go-grpc_out=. --go-grpc_opt=paths=source_relative \
  77. -I. \
  78. providers/v2/common/proto/provider/secretstore.proto
  79. @protoc --go_out=. --go_opt=paths=source_relative \
  80. --go-grpc_out=. --go-grpc_opt=paths=source_relative \
  81. -I. \
  82. providers/v2/common/proto/generator/generator.proto
  83. @for file in \
  84. providers/v2/common/proto/provider/secretstore.pb.go \
  85. providers/v2/common/proto/provider/secretstore_grpc.pb.go \
  86. providers/v2/common/proto/generator/generator.pb.go \
  87. providers/v2/common/proto/generator/generator_grpc.pb.go; do \
  88. tmp=$$(mktemp); \
  89. cat hack/boilerplate.go.txt "$$file" > "$$tmp"; \
  90. mv "$$tmp" "$$file"; \
  91. done
  92. @$(OK) protobuf code generated
  93. # ====================================================================================
  94. # Conformance
  95. reviewable: generate docs manifests helm.generate helm.schema.update helm.docs lint license.check helm.test.update test.crds.update tf.fmt generate-providers verify-providers ## Ensure a PR is ready for review.
  96. @for module in . e2e apis runtime $$(find providers/v1 generators/v1 providers/v2 -name go.mod -not -path '*/vendor/*' -exec dirname {} \; | sort); do \
  97. (cd "$$module" && GOWORK=off go mod tidy); \
  98. done
  99. check-diff: reviewable ## Ensure branch is clean.
  100. @$(INFO) checking that branch is clean
  101. @test -z "$$(git status --porcelain)" || (echo "$$(git status --porcelain)" && $(FAIL))
  102. @$(OK) branch is clean
  103. update-deps: ## Update dependencies across all modules (root, apis, runtime, e2e, providers, generators)
  104. @./hack/update-deps.sh
  105. .PHONY: license.check
  106. license.check:
  107. $(DOCKER) run --rm -u $(shell id -u) -v $(shell pwd):/github/workspace apache/skywalking-eyes:0.6.0 header check
  108. # ====================================================================================
  109. # Golang
  110. .PHONY: go-work ## Creates go workspace and syncs it
  111. go-work:
  112. @$(INFO) creating go workspace
  113. @rm -rf go.work go.work.sum
  114. @GOWORK=off go work init
  115. @GOWORK="$(shell pwd)/go.work" go work use -r .
  116. @GOWORK="$(shell pwd)/go.work" go work edit -dropuse ./e2e
  117. @GOWORK="$(shell pwd)/go.work" go work sync
  118. @$(OK) created go workspace
  119. .PHONY: test
  120. test: generate envtest go-work ## Run tests
  121. @$(INFO) go test unit-tests
  122. KUBEBUILDER_ASSETS="$(abspath $(shell $(ENVTEST) use $(KUBERNETES_VERSION) -p path --bin-dir $(LOCALBIN)))" go test -tags $(PROVIDER) work -v -race -coverprofile cover.out
  123. @$(OK) go test unit-tests
  124. .PHONY: test.e2e
  125. test.e2e: generate ## Run e2e tests
  126. @$(INFO) go test e2e-tests
  127. $(MAKE) -C ./e2e test
  128. @$(OK) go test e2e-tests
  129. .PHONY: test.e2e.managed
  130. test.e2e.managed: generate ## Run e2e tests managed
  131. @$(INFO) go test e2e-tests-managed
  132. $(MAKE) -C ./e2e test.managed
  133. @$(OK) go test e2e-tests-managed
  134. .PHONY: test.e2e.v2
  135. test.e2e.v2: generate ## Run V2 E2E tests
  136. @$(INFO) go test v2 e2e-tests
  137. $(MAKE) -C ./e2e test.v2
  138. @$(OK) go test v2 e2e-tests
  139. .PHONY: test.e2e.v2.operational
  140. test.e2e.v2.operational: generate ## Run focused V2 operational E2E tests
  141. @$(INFO) go test v2 operational e2e-tests
  142. $(MAKE) -C ./e2e test.v2.operational
  143. @$(OK) go test v2 operational e2e-tests
  144. .PHONY: test.crds
  145. test.crds: cty crds.generate.tests ## Test CRDs for modification and backwards compatibility
  146. @$(INFO) $(CTY) test tests
  147. $(CTY) test tests
  148. @$(OK) No breaking CRD changes detected
  149. .PHONY: test.crds.update
  150. test.crds.update: cty crds.generate.tests ## Update the snapshots used by the CRD tests
  151. @$(INFO) $(CTY) test tests -u
  152. $(CTY) test tests -u
  153. @$(OK) Successfully updated all test snapshots
  154. .PHONY: build
  155. build: $(addprefix build-,$(ARCH)) ## Build binary
  156. PROVIDER ?= all_providers
  157. .PHONY: build-%
  158. build-%: generate ## Build binary for the specified arch
  159. @$(INFO) go build $*
  160. $(BUILD_ARGS) GOOS=linux GOARCH=$* \
  161. go build -tags $(PROVIDER) -o '$(OUTPUT_DIR)/external-secrets-linux-$*' main.go
  162. @$(OK) go build $*
  163. lint: golangci-lint ## Run golangci-lint (set LINT_TARGET to run on specific module, LINT_JOBS for parallel jobs)
  164. @if [ -n "$(LINT_TARGET)" ]; then \
  165. $(INFO) Running golangci-lint on $(LINT_TARGET); \
  166. (cd $(LINT_TARGET) && $(GOLANGCI_LINT) run ./...) || exit 1; \
  167. $(OK) Finished linting $(LINT_TARGET); \
  168. else \
  169. $(INFO) Running golangci-lint on all modules in parallel; \
  170. JOBS=$${LINT_JOBS:-1}; \
  171. TMPDIR=$$(mktemp -d); \
  172. GOLANGCI=$(GOLANGCI_LINT); \
  173. trap "rm -rf $$TMPDIR" EXIT; \
  174. export TMPDIR GOLANGCI; \
  175. find . -name go.mod -not -path "*/vendor/*" -not -path "*/e2e/*" -not -path "*/node_modules/*" -exec dirname {} \; | \
  176. xargs -n 1 -P $$JOBS sh -c ' \
  177. module="$$0"; \
  178. name=$$(echo "$$module" | sed "s/[\/\.]/_/g"); \
  179. echo "Linting $$module"; \
  180. if (cd "$$module" && $$GOLANGCI run ./... 2>&1); then \
  181. echo "✓ $$module" > "$$TMPDIR/$$name.success"; \
  182. else \
  183. echo "✗ $$module" > "$$TMPDIR/$$name.failed"; \
  184. exit 1; \
  185. fi \
  186. '; \
  187. FAILED=$$(find $$TMPDIR -name "*.failed" 2>/dev/null | wc -l | tr -d " "); \
  188. SUCCESS=$$(find $$TMPDIR -name "*.success" 2>/dev/null | wc -l | tr -d " "); \
  189. echo "Results: $$SUCCESS passed, $$FAILED failed"; \
  190. if [ $$FAILED -ne 0 ]; then \
  191. echo "Failed modules:"; \
  192. cat $$TMPDIR/*.failed 2>/dev/null || true; \
  193. $(ERR) Linting failed in $$FAILED module\(s\); \
  194. exit 1; \
  195. fi; \
  196. $(OK) Finished linting all modules; \
  197. fi
  198. generate: ## Generate code and crds
  199. @./hack/crd.generate.sh $(BUNDLE_DIR) $(CRD_DIR)
  200. @$(OK) Finished generating deepcopy and crds
  201. generate-providers: ## Generate provider main.go and Dockerfile files from provider.yaml configs
  202. @$(INFO) Generating provider files
  203. @cd providers/v2/hack && go run generate-provider-main.go -providers-dir=..
  204. @$(OK) Generated provider files
  205. verify-providers: ## Verify that provider files are up to date
  206. @$(INFO) Verifying provider files are up to date
  207. @cd providers/v2/hack && go run generate-provider-main.go -providers-dir=.. -dry-run
  208. @if ! git diff --quiet providers/v2/*/main.go providers/v2/*/Dockerfile 2>/dev/null; then \
  209. echo "Provider files are out of date. Run 'make generate-providers' to update them."; \
  210. git diff providers/v2/*/main.go providers/v2/*/Dockerfile; \
  211. exit 1; \
  212. fi
  213. @$(OK) Provider files are up to date
  214. # ====================================================================================
  215. # Local Utility
  216. # This is for running out-of-cluster locally, and is for convenience.
  217. # For more control, try running the binary directly with different arguments.
  218. run: generate ## Run app locally (without a k8s cluster)
  219. go run -tags $(PROVIDER) ./main.go
  220. manifests: helm.generate ## Generate manifests from helm chart
  221. mkdir -p $(OUTPUT_DIR)/deploy/manifests
  222. helm dependency build $(HELM_DIR)
  223. helm template external-secrets $(HELM_DIR) -f deploy/manifests/helm-values.yaml > $(OUTPUT_DIR)/deploy/manifests/external-secrets.yaml
  224. crds.install: generate ## Install CRDs into a cluster. This is for convenience
  225. kubectl apply -f $(BUNDLE_DIR) --server-side --force-conflicts
  226. crds.uninstall: ## Uninstall CRDs from a cluster. This is for convenience
  227. kubectl delete -f $(BUNDLE_DIR)
  228. crds.generate.tests:
  229. ./hack/test.crds.generate.sh $(BUNDLE_DIR) tests/crds
  230. @$(OK) Finished generating crds for testing
  231. tilt-up: tilt manifests ## Generates the local manifests that tilt will use to deploy the controller's objects.
  232. $(LOCALBIN)/tilt up
  233. # ====================================================================================
  234. # Helm Chart
  235. helm.docs: ## Generate helm docs
  236. @cd $(HELM_DIR); \
  237. $(DOCKER) run --rm -v $(shell pwd)/$(HELM_DIR):/helm-docs -u $(shell id -u) docker.io/jnorwood/helm-docs:v1.14.2
  238. HELM_VERSION ?= $(shell helm show chart $(HELM_DIR) | grep '^version:' | sed 's/version: //g')
  239. helm.build: helm.generate ## Build helm chart
  240. @$(INFO) helm package
  241. @helm package $(HELM_DIR) --dependency-update --destination $(OUTPUT_DIR)/chart
  242. @mv $(OUTPUT_DIR)/chart/external-secrets-$(HELM_VERSION).tgz $(OUTPUT_DIR)/chart/external-secrets.tgz
  243. @$(OK) helm package
  244. # install_helm_plugin is for installing the provided plugin, if it doesn't exist
  245. # $1 - plugin name
  246. # $2 - plugin version
  247. # $3 - plugin url
  248. define install_helm_plugin
  249. @v=$$(helm plugin list | awk '$$1=="$(1)"{print $$2}'); \
  250. if [ -z "$$v" ]; then \
  251. $(INFO) "Installing $(1) v$(2)"; \
  252. helm plugin install --version $(2) $(3); \
  253. $(OK) "Installed $(1) v$(2)"; \
  254. elif [ "$$v" != "$(2)" ]; then \
  255. $(INFO) "Found $(1) $$v. Reinstalling v$(2)"; \
  256. helm plugin remove $(1); \
  257. helm plugin install --version $(2) $(3); \
  258. $(OK) "Reinstalled $(1) v$(2)"; \
  259. else \
  260. $(OK) "$(1) already at v$(2)"; \
  261. fi
  262. endef
  263. HELM_SCHEMA_NAME := schema
  264. HELM_SCHEMA_VER := 2.2.1
  265. HELM_SCHEMA_URL := https://github.com/losisin/helm-values-schema-json.git
  266. helm.schema.plugin:
  267. $(call install_helm_plugin,$(HELM_SCHEMA_NAME),$(HELM_SCHEMA_VER), $(HELM_SCHEMA_URL))
  268. HELM_UNITTEST_PLUGIN_NAME := unittest
  269. HELM_UNITTEST_PLUGIN_VER := 1.0.0
  270. HELM_UNITTEST_PLUGIN_URL := https://github.com/helm-unittest/helm-unittest.git
  271. helm.unittest.plugin:
  272. $(call install_helm_plugin,$(HELM_UNITTEST_PLUGIN_NAME),$(HELM_UNITTEST_PLUGIN_VER), $(HELM_UNITTEST_PLUGIN_URL))
  273. helm.schema.update: helm.schema.plugin
  274. @$(INFO) Generating values.schema.json
  275. @helm schema -f $(HELM_DIR)/values.yaml -o $(HELM_DIR)/values.schema.json
  276. @$(OK) Generated values.schema.json
  277. helm.generate:
  278. ./hack/helm.generate.sh $(BUNDLE_DIR) $(HELM_DIR)
  279. @$(OK) Finished generating helm chart files
  280. helm.test: helm.unittest.plugin helm.generate
  281. @helm unittest deploy/charts/external-secrets/
  282. helm.test.update: helm.unittest.plugin helm.generate
  283. @helm unittest -u deploy/charts/external-secrets/
  284. helm.update.appversion:
  285. @chartversion=$$(yq .version ./deploy/charts/external-secrets/Chart.yaml) ; \
  286. chartappversion=$$(yq .appVersion ./deploy/charts/external-secrets/Chart.yaml) ; \
  287. chartname=$$(yq .name ./deploy/charts/external-secrets/Chart.yaml) ; \
  288. $(INFO) Update chartname and chartversion string in test snapshots.; \
  289. sed -s -i "s/^\([[:space:]]\+helm\.sh\/chart:\).*/\1 $${chartname}-$${chartversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  290. sed -s -i "s/^\([[:space:]]\+app\.kubernetes\.io\/version:\).*/\1 $${chartappversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  291. sed -s -i "s/^\([[:space:]]\+image: ghcr\.io\/external-secrets\/external-secrets:\).*/\1$${chartappversion}/" ./deploy/charts/external-secrets/tests/__snapshot__/*.yaml.snap ; \
  292. $(OK) "Version strings updated"
  293. # ====================================================================================
  294. # Documentation
  295. .PHONY: docs
  296. docs: generate ## Generate docs
  297. $(MAKE) -C ./hack/api-docs build
  298. .PHONY: docs.publish
  299. docs.publish: generate ## Generate and deploys docs
  300. $(MAKE) -C ./hack/api-docs build.publish
  301. .PHONY: docs.serve
  302. docs.serve: ## Serve docs
  303. $(MAKE) -C ./hack/api-docs serve
  304. DOCS_VERSION ?= $(VERSION)
  305. .PHONY: docs.update
  306. docs.update: ## Update docs
  307. $(MAKE) -C ./hack/api-docs stability-support.update DOCS_VERSION=$(DOCS_VERSION)
  308. # ====================================================================================
  309. # Build Artifacts
  310. .PHONY: build.all
  311. build.all: docker.build helm.build ## Build all artifacts (docker image, helm chart)
  312. .PHONY: docker.image
  313. docker.image: ## Emit IMAGE_NAME:IMAGE_TAG
  314. @echo $(IMAGE_NAME):$(IMAGE_TAG)
  315. .PHONY: docker.imagename
  316. docker.imagename: ## Emit IMAGE_NAME
  317. @echo $(IMAGE_NAME)
  318. .PHONY: docker.tag
  319. docker.tag: ## Emit IMAGE_TAG
  320. @echo $(IMAGE_TAG)
  321. .PHONY: docker.build
  322. docker.build: docker.build.controller docker.build.providers ## Build all docker images (controller + providers)
  323. .PHONY: docker.build.e2e
  324. docker.build.e2e: docker.build.controller.e2e ## Build docker images for local e2e testing (local arch only)
  325. .PHONY: docker.build.controller
  326. docker.build.controller: $(addprefix build-,$(ARCH)) ## Build the controller docker image
  327. @$(INFO) $(DOCKER) build controller
  328. @echo $(DOCKER) build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  329. @DOCKER_BUILDKIT=1 $(DOCKER) build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  330. @$(OK) $(DOCKER) build controller
  331. .PHONY: docker.build.controller.e2e
  332. docker.build.controller.e2e: build-$(LOCAL_GOARCH) ## Build the controller docker image for local arch only
  333. @$(INFO) $(DOCKER) build controller for $(LOCAL_GOARCH)
  334. @echo $(DOCKER) build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  335. @DOCKER_BUILDKIT=1 $(DOCKER) build -f $(DOCKERFILE) . $(DOCKER_BUILD_ARGS) -t $(IMAGE_NAME):$(IMAGE_TAG)
  336. @$(OK) $(DOCKER) build controller for $(LOCAL_GOARCH)
  337. .PHONY: docker.build.providers
  338. docker.build.providers: docker.build.provider.kubernetes docker.build.provider.aws docker.build.provider.fake ## Build all provider images
  339. .PHONY: docker.build.provider.kubernetes
  340. docker.build.provider.kubernetes: ## Build Kubernetes provider image
  341. @$(INFO) $(DOCKER) build kubernetes provider
  342. @DOCKER_BUILDKIT=1 $(DOCKER) build \
  343. -f providers/v2/kubernetes/Dockerfile \
  344. . \
  345. $(DOCKER_BUILD_ARGS) \
  346. -t $(IMAGE_REGISTRY)/external-secrets/provider-kubernetes:$(IMAGE_TAG)
  347. @$(OK) $(DOCKER) build kubernetes provider
  348. .PHONY: docker.build.provider.aws
  349. docker.build.provider.aws: ## Build AWS provider image
  350. @$(INFO) $(DOCKER) build AWS provider
  351. @DOCKER_BUILDKIT=1 $(DOCKER) build \
  352. -f providers/v2/aws/Dockerfile \
  353. . \
  354. $(DOCKER_BUILD_ARGS) \
  355. -t $(IMAGE_REGISTRY)/external-secrets/provider-aws:$(IMAGE_TAG)
  356. @$(OK) $(DOCKER) build AWS provider
  357. .PHONY: docker.build.provider.fake
  358. docker.build.provider.fake: ## Build Fake provider image
  359. @$(INFO) $(DOCKER) build Fake provider
  360. @DOCKER_BUILDKIT=1 $(DOCKER) build \
  361. -f providers/v2/fake/Dockerfile \
  362. . \
  363. $(DOCKER_BUILD_ARGS) \
  364. -t $(IMAGE_REGISTRY)/external-secrets/provider-fake:$(IMAGE_TAG)
  365. @$(OK) $(DOCKER) build Fake provider
  366. .PHONY: docker.push
  367. docker.push: docker.push.controller docker.push.providers ## Push all docker images to the registry
  368. .PHONY: docker.push.controller
  369. docker.push.controller: ## Push the controller docker image to the registry
  370. @$(INFO) $(DOCKER) push controller
  371. @$(DOCKER) push $(IMAGE_NAME):$(IMAGE_TAG)
  372. @$(OK) $(DOCKER) push controller
  373. .PHONY: docker.push.providers
  374. docker.push.providers: docker.push.provider.kubernetes docker.push.provider.aws docker.push.provider.fake ## Push all provider images
  375. .PHONY: docker.push.provider.kubernetes
  376. docker.push.provider.kubernetes: ## Push Kubernetes provider image
  377. @$(INFO) $(DOCKER) push kubernetes provider
  378. @$(DOCKER) push $(IMAGE_REGISTRY)/external-secrets/provider-kubernetes:$(IMAGE_TAG)
  379. @$(OK) $(DOCKER) push kubernetes provider
  380. .PHONY: docker.push.provider.aws
  381. docker.push.provider.aws: ## Push AWS provider image
  382. @$(INFO) $(DOCKER) push AWS provider
  383. @$(DOCKER) push $(IMAGE_REGISTRY)/external-secrets/provider-aws:$(IMAGE_TAG)
  384. @$(OK) $(DOCKER) push AWS provider
  385. .PHONY: docker.push.provider.fake
  386. docker.push.provider.fake: ## Push Fake provider image
  387. @$(INFO) $(DOCKER) push Fake provider
  388. @$(DOCKER) push $(IMAGE_REGISTRY)/external-secrets/provider-fake:$(IMAGE_TAG)
  389. @$(OK) $(DOCKER) push Fake provider
  390. # RELEASE_TAG is tag to promote. Default is promoting to main branch, but can be overriden
  391. # to promote a tag to a specific version.
  392. RELEASE_TAG ?= $(IMAGE_TAG)
  393. SOURCE_TAG ?= $(VERSION)$(TAG_SUFFIX)
  394. .PHONY: docker.promote
  395. docker.promote: ## Promote the docker image to the registry
  396. @$(INFO) promoting $(SOURCE_TAG) to $(RELEASE_TAG)
  397. $(DOCKER) manifest inspect --verbose $(IMAGE_NAME):$(SOURCE_TAG) > .tagmanifest
  398. for digest in $$(jq -r 'if type=="array" then .[] | select(.Descriptor.platform.architecture != "unknown") | .Descriptor.digest else .Descriptor.digest end' < .tagmanifest); do \
  399. $(DOCKER) pull $(IMAGE_NAME)@$$digest; \
  400. done
  401. $(DOCKER) manifest create $(IMAGE_NAME):$(RELEASE_TAG) \
  402. $$(jq -j 'if type=="array" then [.[] | select(.Descriptor.platform.architecture != "unknown")] | map("--amend $(IMAGE_NAME)@" + .Descriptor.digest) | join(" ") else "--amend $(IMAGE_NAME)@" + .Descriptor.digest end' < .tagmanifest)
  403. $(DOCKER) manifest push $(IMAGE_NAME):$(RELEASE_TAG)
  404. @$(OK) $(DOCKER) push $(RELEASE_TAG) \
  405. # ====================================================================================
  406. # Terraform
  407. define run_terraform
  408. @cd $(TF_DIR)/$1/infrastructure && \
  409. terraform init && \
  410. $2 && \
  411. cd ../kubernetes && \
  412. terraform init && \
  413. $3
  414. endef
  415. tf.plan.%:
  416. $(call run_terraform,$*,terraform plan,terraform plan)
  417. tf.apply.%:
  418. $(call run_terraform,$*,terraform apply -auto-approve,terraform apply -auto-approve)
  419. tf.destroy.%:
  420. @cd $(TF_DIR)/$*/kubernetes && \
  421. terraform init && \
  422. terraform destroy -auto-approve && \
  423. cd ../infrastructure && \
  424. terraform init && \
  425. terraform destroy -auto-approve
  426. tf.fmt:
  427. @cd $(TF_DIR) && \
  428. terraform fmt -recursive
  429. # ====================================================================================
  430. # Help
  431. .PHONY: help
  432. # only comments after make target name are shown as help text
  433. help: ## Displays this help message
  434. @echo -e "$$(grep -hE '^\S+:.*##' $(MAKEFILE_LIST) | sed -e 's/:.*##\s*/|/' -e 's/^\(.\+\):\(.*\)/\\x1b[36m\1\\x1b[m:\2/' | column -c2 -t -s'|' | sort)"
  435. .PHONY: clean
  436. clean: ## Clean bins
  437. @$(INFO) clean
  438. @rm -f $(OUTPUT_DIR)/external-secrets-linux-*
  439. @$(OK) go build $*
  440. # ====================================================================================
  441. # Build Dependencies
  442. detected_OS := $(shell uname -s)
  443. real_OS := $(detected_OS)
  444. arch := $(shell uname -m)
  445. ifeq ($(detected_OS),Darwin)
  446. detected_OS := mac
  447. real_OS := darwin
  448. endif
  449. ifeq ($(detected_OS),Linux)
  450. detected_OS := linux
  451. real_OS := linux
  452. endif
  453. ## Location to install dependencies to
  454. LOCALBIN ?= $(shell pwd)/bin
  455. $(LOCALBIN):
  456. mkdir -p $(LOCALBIN)
  457. ## Tool Binaries
  458. TILT ?= $(LOCALBIN)/tilt
  459. CTY ?= $(LOCALBIN)/cty
  460. ENVTEST ?= $(LOCALBIN)/setup-envtest
  461. GOLANGCI_LINT ?= $(LOCALBIN)/golangci-lint
  462. LINT_TARGET ?= ""
  463. ## Tool Versions
  464. GOLANGCI_VERSION := 2.11.3
  465. KUBERNETES_VERSION := 1.33.x
  466. TILT_VERSION := 0.33.21
  467. CTY_VERSION := 1.1.3
  468. .PHONY: envtest
  469. envtest: $(ENVTEST) ## Download envtest-setup locally if necessary.
  470. $(ENVTEST): $(LOCALBIN)
  471. test -s $(LOCALBIN)/setup-envtest || GOBIN=$(LOCALBIN) go install sigs.k8s.io/controller-runtime/tools/setup-envtest@latest
  472. .PHONY: golangci-lint
  473. .PHONY: $(GOLANGCI_LINT)
  474. golangci-lint: $(GOLANGCI_LINT) ## Download golangci-lint locally if necessary.
  475. $(GOLANGCI_LINT): $(LOCALBIN)
  476. test -s $(LOCALBIN)/golangci-lint && $(LOCALBIN)/golangci-lint version | grep -q $(GOLANGCI_VERSION) || \
  477. curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(LOCALBIN) v$(GOLANGCI_VERSION)
  478. .PHONY: tilt
  479. .PHONY: $(TILT)
  480. tilt: $(TILT) ## Download tilt locally if necessary. Architecture is locked at x86_64.
  481. $(TILT): $(LOCALBIN)
  482. test -s $(LOCALBIN)/tilt || curl -fsSL https://github.com/tilt-dev/tilt/releases/download/v$(TILT_VERSION)/tilt.$(TILT_VERSION).$(detected_OS).$(arch).tar.gz | tar -xz -C $(LOCALBIN) tilt
  483. .PHONY: cty
  484. .PHONY: $(CTY)
  485. cty: $(CTY) ## Download cty locally if necessary. Architecture is locked at x86_64.
  486. $(CTY): $(LOCALBIN)
  487. test -s $(LOCALBIN)/cty || curl -fsSL https://github.com/Skarlso/crd-to-sample-yaml/releases/download/v$(CTY_VERSION)/cty_$(real_OS)_amd64.tar.gz | tar -xz -C $(LOCALBIN) cty