Project pinned digest-safe retention tool through existing GitOps resources
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
942059a6fe
commit
a12f1169f9
6 changed files with 988 additions and 2 deletions
|
|
@ -40,11 +40,31 @@ def verify_frontend(source_dir=None):
|
|||
if len(body)>32768 or hashlib.sha256(body).hexdigest()!=digest or cm['data'][name].encode()!=body:
|
||||
raise ValueError('frontend definition projection mismatch: '+name)
|
||||
|
||||
def verify_platform(source_file=None):
|
||||
pin=json.loads((ROOT/'k8s/gitops/platform-source.json').read_text())
|
||||
if (pin.get('schema_version')!=1 or pin.get('repository')!='coulomb/railiance-platform'
|
||||
or pin.get('path')!='scripts/forgejo_package_prune.py'
|
||||
or not re.fullmatch('[0-9a-f]{40}',pin['revision'])):
|
||||
raise ValueError('invalid platform source pin')
|
||||
if source_file is None:
|
||||
url=f"https://forgejo.coulomb.social/coulomb/railiance-platform/raw/commit/{pin['revision']}/{pin['path']}"
|
||||
with urllib.request.urlopen(url,timeout=10) as response: body=response.read(131073)
|
||||
else: body=Path(source_file).read_bytes()
|
||||
docs=list(yaml.safe_load_all(render()))
|
||||
cm=next(d for d in docs if d['metadata']['name']=='actcore-ops-service-inventory')
|
||||
worker=next(d for d in docs if d['metadata']['name']=='actcore-worker')
|
||||
if (len(body)>131072 or hashlib.sha256(body).hexdigest()!=pin['sha256']
|
||||
or cm['data']['forgejo_package_prune.py'].encode()!=body
|
||||
or worker['spec']['template']['metadata']['annotations'].get('activity-core/retention-sha256')!=pin['sha256']):
|
||||
raise ValueError('platform tool projection mismatch')
|
||||
|
||||
if __name__=='__main__':
|
||||
parser=argparse.ArgumentParser(); parser.add_argument('--check',action='store_true'); parser.add_argument('--verify-frontend',action='store_true'); args=parser.parse_args()
|
||||
parser=argparse.ArgumentParser(); parser.add_argument('--check',action='store_true'); parser.add_argument('--verify-frontend',action='store_true'); parser.add_argument('--verify-platform',action='store_true'); args=parser.parse_args()
|
||||
path=ROOT/'k8s/gitops/runtime.yaml'; text=render()
|
||||
if args.check:
|
||||
if path.read_text()!=text: raise SystemExit('GitOps projection stale; run scripts/render_gitops.py')
|
||||
else: path.write_text(text)
|
||||
|
||||
if args.verify_frontend: verify_frontend()
|
||||
|
||||
if args.verify_platform: verify_platform()
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue