ci: merge travis matrix, add `salt-lint` & `rubocop` to `lint` jobtags/v0.5.2
# -*- coding: utf-8 -*- | |||||
# vim: ft=yaml | |||||
--- | |||||
# General overrides used across formulas in the org | |||||
Metrics/LineLength: | |||||
# Increase from default of `80` | |||||
# Based on https://github.com/PyCQA/flake8-bugbear#opinionated-warnings (`B950`) | |||||
Max: 88 | |||||
# Any offenses that should be fixed, e.g. collected via. `rubocop --auto-gen-config` |
# -*- coding: utf-8 -*- | |||||
# vim: ft=yaml | |||||
--- | |||||
exclude_paths: [] | |||||
skip_list: | |||||
# Using `salt-lint` for linting other files as well, such as Jinja macros/templates | |||||
- 205 # Use ".sls" as a Salt State file extension | |||||
# Skipping `207` and `208` because `210` is sufficient, at least for the time-being | |||||
# I.e. Allows 3-digit unquoted codes to still be used, such as `644` and `755` | |||||
- 207 # File modes should always be encapsulated in quotation marks | |||||
- 208 # File modes should always contain a leading zero | |||||
tags: [] | |||||
verbosity: 1 |
# -*- coding: utf-8 -*- | # -*- coding: utf-8 -*- | ||||
# vim: ft=yaml | # vim: ft=yaml | ||||
--- | --- | ||||
## Machine config | |||||
dist: trusty | dist: trusty | ||||
stages: | |||||
- test | |||||
- lint | |||||
- name: release | |||||
if: branch = master AND type != pull_request | |||||
sudo: required | sudo: required | ||||
cache: bundler | |||||
language: ruby | |||||
services: | services: | ||||
- docker | - docker | ||||
# Make sure the instances listed below match up with | |||||
# the `platforms` defined in `kitchen.yml` | |||||
env: | |||||
matrix: | |||||
# - INSTANCE: default-debian-10-develop-py3 | |||||
- INSTANCE: default-ubuntu-1804-develop-py3 | |||||
# - INSTANCE: default-centos-7-develop-py3 | |||||
# - INSTANCE: default-fedora-30-develop-py3 | |||||
# - INSTANCE: default-opensuse-leap-15-develop-py3 | |||||
# - INSTANCE: default-amazonlinux-2-develop-py2 | |||||
# - INSTANCE: default-arch-base-latest-develop-py2 | |||||
- INSTANCE: default-debian-9-2019-2-py3 | |||||
# - INSTANCE: default-ubuntu-1804-2019-2-py3 | |||||
- INSTANCE: default-centos-7-2019-2-py3 | |||||
# - INSTANCE: default-fedora-30-2019-2-py3 | |||||
# - INSTANCE: default-opensuse-leap-15-2019-2-py3 | |||||
# - INSTANCE: default-amazonlinux-2-2019-2-py2 | |||||
# - INSTANCE: default-arch-base-latest-2019-2-py2 | |||||
# - INSTANCE: default-debian-9-2018-3-py2 | |||||
# - INSTANCE: default-ubuntu-1604-2018-3-py2 | |||||
# - INSTANCE: default-centos-7-2018-3-py2 | |||||
- INSTANCE: default-fedora-29-2018-3-py2 | |||||
- INSTANCE: default-opensuse-leap-15-2018-3-py2 | |||||
# - INSTANCE: default-amazonlinux-2-2018-3-py2 | |||||
- INSTANCE: default-arch-base-latest-2018-3-py2 | |||||
# - INSTANCE: default-debian-8-2017-7-py2 | |||||
- INSTANCE: default-ubuntu-1604-2017-7-py2 | |||||
# - INSTANCE: default-centos-6-2017-7-py2 | |||||
# - INSTANCE: default-fedora-29-2017-7-py2 | |||||
# - INSTANCE: default-opensuse-leap-15-2017-7-py2 | |||||
# - INSTANCE: default-amazonlinux-2-2017-7-py2 | |||||
# - INSTANCE: default-arch-base-latest-2017-7-py2 | |||||
## Language and cache config | |||||
language: ruby | |||||
cache: bundler | |||||
## Script to run for the test stage | |||||
script: | script: | ||||
- bin/kitchen verify ${INSTANCE} | |||||
- bin/kitchen verify "${INSTANCE}" | |||||
## Stages and jobs matrix | |||||
stages: | |||||
- test | |||||
- name: release | |||||
if: branch = master AND type != pull_request | |||||
jobs: | jobs: | ||||
allow_failures: | |||||
- env: Lint_rubocop | |||||
fast_finish: true | |||||
include: | include: | ||||
# Define the `lint` stage (runs `yamllint` and `commitlint`) | |||||
- stage: lint | |||||
language: node_js | |||||
## Define the test stage that runs the linters (and testing matrix, if applicable) | |||||
# Run all of the linters in a single job (except `rubocop`) | |||||
- language: node_js | |||||
node_js: lts/* | node_js: lts/* | ||||
env: Lint | |||||
name: 'Lint: salt-lint, yamllint & commitlint' | |||||
before_install: skip | before_install: skip | ||||
script: | script: | ||||
# Need to use `pip3` due to using `trusty` on Travis | |||||
- sudo apt-get install python3-pip python3-setuptools python3-wheel -y | |||||
# Install and run `salt-lint` | |||||
- pip3 install --user salt-lint PyYAML==4.2b4 | |||||
- git ls-files | grep '\.sls$\|\.jinja$\|\.j2$\|\.tmpl$' | |||||
| xargs -I {} salt-lint {} | |||||
# Install and run `yamllint` | # Install and run `yamllint` | ||||
# Need at least `v1.17.0` for the `yaml-files` setting | # Need at least `v1.17.0` for the `yaml-files` setting | ||||
- pip install --user yamllint>=1.17.0 | |||||
- pip3 install --user yamllint>=1.17.0 | |||||
- yamllint -s . | - yamllint -s . | ||||
# Install and run `commitlint` | # Install and run `commitlint` | ||||
- npm install @commitlint/config-conventional -D | - npm install @commitlint/config-conventional -D | ||||
- npm install @commitlint/travis-cli -D | - npm install @commitlint/travis-cli -D | ||||
- commitlint-travis | - commitlint-travis | ||||
# Define the release stage that runs `semantic-release` | |||||
# Run the `rubocop` linter in a separate job that is allowed to fail | |||||
# Once these lint errors are fixed, this can be merged into a single job | |||||
- language: node_js | |||||
node_js: lts/* | |||||
env: Lint_rubocop | |||||
name: 'Lint: rubocop' | |||||
before_install: skip | |||||
script: | |||||
# Install and run `rubocop` | |||||
- gem install rubocop | |||||
- rubocop -d | |||||
## Define the rest of the matrix based on Kitchen testing | |||||
# Make sure the instances listed below match up with | |||||
# the `platforms` defined in `kitchen.yml` | |||||
# - env: INSTANCE=default-debian-10-develop-py3 | |||||
- env: INSTANCE=default-ubuntu-1804-develop-py3 | |||||
# - env: INSTANCE=default-centos-7-develop-py3 | |||||
# - env: INSTANCE=default-fedora-30-develop-py3 | |||||
# - env: INSTANCE=default-opensuse-leap-15-develop-py3 | |||||
# - env: INSTANCE=default-amazonlinux-2-develop-py2 | |||||
# - env: INSTANCE=default-arch-base-latest-develop-py2 | |||||
- env: INSTANCE=default-debian-9-2019-2-py3 | |||||
# - env: INSTANCE=default-ubuntu-1804-2019-2-py3 | |||||
- env: INSTANCE=default-centos-7-2019-2-py3 | |||||
# - env: INSTANCE=default-fedora-30-2019-2-py3 | |||||
# - env: INSTANCE=default-opensuse-leap-15-2019-2-py3 | |||||
# - env: INSTANCE=default-amazonlinux-2-2019-2-py2 | |||||
# - env: INSTANCE=default-arch-base-latest-2019-2-py2 | |||||
# - env: INSTANCE=default-debian-9-2018-3-py2 | |||||
# - env: INSTANCE=default-ubuntu-1604-2018-3-py2 | |||||
# - env: INSTANCE=default-centos-7-2018-3-py2 | |||||
- env: INSTANCE=default-fedora-29-2018-3-py2 | |||||
- env: INSTANCE=default-opensuse-leap-15-2018-3-py2 | |||||
# - env: INSTANCE=default-amazonlinux-2-2018-3-py2 | |||||
- env: INSTANCE=default-arch-base-latest-2018-3-py2 | |||||
# - env: INSTANCE=default-debian-8-2017-7-py2 | |||||
- env: INSTANCE=default-ubuntu-1604-2017-7-py2 | |||||
# - env: INSTANCE=default-centos-6-2017-7-py2 | |||||
# - env: INSTANCE=default-fedora-29-2017-7-py2 | |||||
# - env: INSTANCE=default-opensuse-leap-15-2017-7-py2 | |||||
# - env: INSTANCE=default-amazonlinux-2-2017-7-py2 | |||||
# - env: INSTANCE=default-arch-base-latest-2017-7-py2 | |||||
## Define the release stage that runs `semantic-release` | |||||
- stage: release | - stage: release | ||||
language: node_js | language: node_js | ||||
node_js: lts/* | node_js: lts/* | ||||
env: Release | |||||
name: 'Run semantic-release inc. file updates to AUTHORS, CHANGELOG & FORMULA' | |||||
before_install: skip | before_install: skip | ||||
script: | script: | ||||
# Update `AUTHORS.md` | # Update `AUTHORS.md` |
# Default settings | # Default settings | ||||
- '*.yaml' | - '*.yaml' | ||||
- '*.yml' | - '*.yml' | ||||
- .salt-lint | |||||
- .yamllint | - .yamllint | ||||
# SaltStack Formulas additional settings | # SaltStack Formulas additional settings | ||||
- '*.example' | - '*.example' |
source "https://rubygems.org" | |||||
# frozen_string_literal: true | |||||
source 'https://rubygems.org' | |||||
gem 'kitchen-docker', '>= 2.9' | gem 'kitchen-docker', '>= 2.9' | ||||
gem 'kitchen-salt', '>= 0.6.0' | |||||
gem 'kitchen-inspec', '>= 1.1' | gem 'kitchen-inspec', '>= 1.1' | ||||
gem 'kitchen-salt', '>= 0.6.0' |
# this file is here to facilitate running it. | # this file is here to facilitate running it. | ||||
# | # | ||||
require "pathname" | |||||
ENV["BUNDLE_GEMFILE"] ||= File.expand_path("../../Gemfile", | |||||
Pathname.new(__FILE__).realpath) | |||||
require 'pathname' | |||||
ENV['BUNDLE_GEMFILE'] ||= File.expand_path('../../Gemfile', | |||||
Pathname.new(__FILE__).realpath) | |||||
bundle_binstub = File.expand_path("../bundle", __FILE__) | |||||
bundle_binstub = File.expand_path('bundle', __dir__) | |||||
if File.file?(bundle_binstub) | if File.file?(bundle_binstub) | ||||
if File.read(bundle_binstub, 300) =~ /This file was generated by Bundler/ | if File.read(bundle_binstub, 300) =~ /This file was generated by Bundler/ | ||||
load(bundle_binstub) | load(bundle_binstub) | ||||
else | else | ||||
abort("Your `bin/bundle` was not generated by Bundler, so this binstub cannot run. | |||||
Replace `bin/bundle` by running `bundle binstubs bundler --force`, then run this command again.") | |||||
abort( | |||||
'Your `bin/bundle` was not generated by Bundler, '\ | |||||
'so this binstub cannot run. Replace `bin/bundle` by running '\ | |||||
'`bundle binstubs bundler --force`, then run this command again.' | |||||
) | |||||
end | end | ||||
end | end | ||||
require "rubygems" | |||||
require "bundler/setup" | |||||
require 'rubygems' | |||||
require 'bundler/setup' | |||||
load Gem.bin_path("test-kitchen", "kitchen") | |||||
load Gem.bin_path('test-kitchen', 'kitchen') |
{%- set comment = app_details.get('comment', None) %} | {%- set comment = app_details.get('comment', None) %} | ||||
{%- if from_addr is not none %} | {%- if from_addr is not none %} | ||||
ufw-app-{{method}}-{{app_name}}-{{from_addr}}: | |||||
ufw-app-{{ method }}-{{ app_name }}-{{ from_addr }}: | |||||
{%- else %} | {%- else %} | ||||
ufw-app-{{method}}-{{app_name}}: | |||||
ufw-app-{{ method }}-{{ app_name }}: | |||||
{%- endif %} | {%- endif %} | ||||
ufw.{{method}}: | |||||
- app: '"{{app_name}}"' | |||||
ufw.{{ method }}: | |||||
- app: '"{{ app_name }}"' | |||||
{%- if from_addr is not none %} | {%- if from_addr is not none %} | ||||
- from_addr: {{from_addr}} | |||||
- from_addr: {{ from_addr }} | |||||
{%- endif %} | {%- endif %} | ||||
{%- if to_addr is not none %} | {%- if to_addr is not none %} | ||||
- to_addr: {{to_addr}} | |||||
- to_addr: {{ to_addr }} | |||||
{%- endif %} | {%- endif %} | ||||
# Debian Jessie doesn't implement the **comment** directive | # Debian Jessie doesn't implement the **comment** directive | ||||
# CentOS-6 throws an UTF-8 error | # CentOS-6 throws an UTF-8 error | ||||
{%- if comment is not none and salt['grains.get']('osfinger') != 'Debian-8' and salt['grains.get']('osfinger') != 'CentOS-6' %} | {%- if comment is not none and salt['grains.get']('osfinger') != 'Debian-8' and salt['grains.get']('osfinger') != 'CentOS-6' %} | ||||
- comment: '"{{comment}}"' | |||||
- comment: '"{{ comment }}"' | |||||
{%- endif %} | {%- endif %} | ||||
- listen_in: | - listen_in: | ||||
- cmd: reload-ufw | - cmd: reload-ufw |
{%- for interface_name, interface_details in ufw.get('interfaces', {}).items() %} | {%- for interface_name, interface_details in ufw.get('interfaces', {}).items() %} | ||||
{%- set comment = interface_details.get('comment', None) %} | {%- set comment = interface_details.get('comment', None) %} | ||||
ufw-interface-{{interface_name}}: | |||||
ufw-interface-{{ interface_name }}: | |||||
ufw.allowed: | ufw.allowed: | ||||
- interface: {{interface_name}} | |||||
- interface: {{ interface_name }} | |||||
{%- if comment is not none %} | {%- if comment is not none %} | ||||
- comment: '"{{comment}}"' | |||||
- comment: '"{{ comment }}"' | |||||
{%- endif %} | {%- endif %} | ||||
- listen_in: | - listen_in: | ||||
- cmd: reload-ufw | - cmd: reload-ufw |
{%- for open_addr, open_details in ufw.get('open', {}).items() %} | {%- for open_addr, open_details in ufw.get('open', {}).items() %} | ||||
{%- set comment = open_details.get('comment', None) %} | {%- set comment = open_details.get('comment', None) %} | ||||
ufw-open-{{open_addr}}: | |||||
ufw-open-{{ open_addr }}: | |||||
ufw.allowed: | ufw.allowed: | ||||
- from_addr: {{open_addr}} | |||||
- from_addr: {{ open_addr }} | |||||
{%- if comment is not none %} | {%- if comment is not none %} | ||||
- comment: '"{{comment}}"' | |||||
- comment: '"{{ comment }}"' | |||||
{%- endif %} | {%- endif %} | ||||
- listen_in: | - listen_in: | ||||
- cmd: reload-ufw | - cmd: reload-ufw |
{%- set to_port = service_details.get('to_port', service_name) %} | {%- set to_port = service_details.get('to_port', service_name) %} | ||||
{%- set comment = service_details.get('comment', None) %} | {%- set comment = service_details.get('comment', None) %} | ||||
ufw-svc-{{method}}-{{service_name}}-{{from_addr}}: | |||||
ufw.{{method}}: | |||||
ufw-svc-{{ method }}-{{ service_name }}-{{ from_addr }}: | |||||
ufw.{{ method }}: | |||||
{%- if protocol is not none %} | {%- if protocol is not none %} | ||||
- protocol: {{protocol}} | |||||
- protocol: {{ protocol }} | |||||
{%- endif %} | {%- endif %} | ||||
{%- if from_addr is not none %} | {%- if from_addr is not none %} | ||||
- from_addr: {{from_addr}} | |||||
- from_addr: {{ from_addr }} | |||||
{%- endif %} | {%- endif %} | ||||
{%- if from_port is not none %} | {%- if from_port is not none %} | ||||
- from_port: "{{from_port}}" | |||||
- from_port: "{{ from_port }}" | |||||
{%- endif %} | {%- endif %} | ||||
{%- if to_addr is not none %} | {%- if to_addr is not none %} | ||||
- to_addr: {{to_addr}} | |||||
- to_addr: {{ to_addr }} | |||||
{%- endif %} | {%- endif %} | ||||
# Debian Jessie doesn't implement the **comment** directive | # Debian Jessie doesn't implement the **comment** directive | ||||
# CentOS-6 throws an UTF-8 error | # CentOS-6 throws an UTF-8 error | ||||
{%- if comment is not none and salt['grains.get']('osfinger') != 'Debian-8' and salt['grains.get']('osfinger') != 'CentOS-6' %} | {%- if comment is not none and salt['grains.get']('osfinger') != 'Debian-8' and salt['grains.get']('osfinger') != 'CentOS-6' %} | ||||
- comment: '"{{comment}}"' | |||||
- comment: '"{{ comment }}"' | |||||
{%- endif %} | {%- endif %} | ||||
- to_port: "{{to_port}}" | |||||
- to_port: "{{ to_port }}" | |||||
- listen_in: | - listen_in: | ||||
- cmd: reload-ufw | - cmd: reload-ufw | ||||