Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .envrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
has nix && use flake
watch_file *.nix
dotenv_if_exists .env # You can create a .env file with your env vars for this project. You can also use .secrets if you are using act. See the line below.
dotenv_if_exists .secrets # Used by [act](https://nektosact.com/) to load secrets into the pipelines
27 changes: 14 additions & 13 deletions .github/workflows/ci-pull-request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,36 +13,37 @@ permissions:
jobs:
build:
runs-on: ubuntu-latest
defaults:
run:
shell: nix develop --command bash {0}
steps:
- name: Checkout code
uses: actions/checkout@v2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3

- name: Setup Node.js
uses: actions/setup-node@v2
with:
node-version: '20.x'
- name: Install Nix
uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22

- name: Install tfx-cli and typescript
run: |
npm install -g tfx-cli
npm install -g typescript
- name: Enable Nix cache
uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14
with:
use-flakehub: false

- name: Login to Azure DevOps
uses: azure/login@v2
uses: azure/login@532459ea530d8321f2fb9bb10d1e0bcf23869a43 # v3.0.0
with:
client-id: ${{ secrets.AZURE_APPLICATION_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}

- name: Get Azure DevOps access token
id: devops_token
# Use the runner's az (the one azure/login authenticated), not the nixpkgs az.
shell: bash
run: |
TOKEN="$(az account get-access-token --resource "${{ secrets.AZURE_MARKETPLACE_ACCESS_SCOPE }}" --query accessToken -o tsv)"
echo "::add-mask::$TOKEN"
echo "azure_devops_access_token=$TOKEN" >> "$GITHUB_OUTPUT"

- name: Build release
run: |
make build


just build
33 changes: 17 additions & 16 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,23 @@ concurrency:
jobs:
build-and-release:
runs-on: ubuntu-latest
defaults:
run:
shell: nix develop --command bash {0}
Comment thread
tembleking marked this conversation as resolved.
steps:
- name: Checkout code
uses: actions/checkout@v2
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
fetch-depth: 0 # Need history to compare versions

- name: Install Nix
uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22

- name: Enable Nix cache
uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14
Comment thread
airadier marked this conversation as resolved.
with:
use-flakehub: false

- name: Check for version change
id: check_version
run: |
Expand All @@ -41,21 +52,9 @@ jobs:
echo "changed=false" >> $GITHUB_OUTPUT
fi

- name: Setup Node.js
if: steps.check_version.outputs.changed == 'true'
uses: actions/setup-node@v2
with:
node-version: '20.x'

- name: Install tfx-cli and typescript
if: steps.check_version.outputs.changed == 'true'
run: |
npm install -g tfx-cli
npm install -g typescript

- name: Login to Azure DevOps
if: steps.check_version.outputs.changed == 'true'
uses: azure/login@v1
uses: azure/login@532459ea530d8321f2fb9bb10d1e0bcf23869a43 # v3.0.0
with:
client-id: ${{ secrets.AZURE_APPLICATION_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
Expand All @@ -64,20 +63,22 @@ jobs:
- name: Get Azure DevOps access token
if: steps.check_version.outputs.changed == 'true'
id: get_token
# Use the runner's az (the one azure/login authenticated), not the nixpkgs az.
shell: bash
run: |
echo "AZURE_DEVOPS_ACCESS_TOKEN=$(az account get-access-token --resource ${{ secrets.AZURE_MARKETPLACE_ACCESS_SCOPE }} --query accessToken -o tsv)" >> $GITHUB_ENV

- name: Build release
if: steps.check_version.outputs.changed == 'true'
run: |
make build
just build

- name: Publish release
if: steps.check_version.outputs.changed == 'true'
env:
AZURE_DEVOPS_ACCESS_TOKEN: ${{ env.AZURE_DEVOPS_ACCESS_TOKEN }}
run: |
make publish-release
just publish-release

- name: Create Git Tag
if: steps.check_version.outputs.changed == 'true'
Expand Down
13 changes: 12 additions & 1 deletion .github/workflows/sync-versions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,14 +9,25 @@ jobs:
sync-versions:
runs-on: ubuntu-latest
if: contains(github.event.pull_request.labels.*.name, 'skip-version-sync') == false
defaults:
run:
shell: nix develop --command bash {0}
steps:
- name: Checkout code
uses: actions/checkout@v3
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
ref: ${{ github.head_ref }}
token: ${{ secrets.GITHUB_TOKEN }}
fetch-depth: 0

- name: Install Nix
uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22

- name: Enable Nix cache
uses: DeterminateSystems/magic-nix-cache-action@908b263ff629f4cc17666315b7fd3ec127c6244d # v14
with:
use-flakehub: false

- name: Check for version change
id: version_changed
run: |
Expand Down
6 changes: 5 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,4 +6,8 @@ node_modules/
output.html
.npm
id
local_text.txt
local_text.txt
.direnv
result
Comment thread
tembleking marked this conversation as resolved.
.env
.secrets
24 changes: 0 additions & 24 deletions Makefile

This file was deleted.

61 changes: 61 additions & 0 deletions flake.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

49 changes: 49 additions & 0 deletions flake.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
flake-utils.url = "github:numtide/flake-utils";
};
outputs =
{
self,
nixpkgs,
flake-utils,
}:
flake-utils.lib.eachDefaultSystem (
system:
let
pkgs = import nixpkgs {
inherit system;
config.allowUnfree = true;
overlays = [ self.overlays.default ];
};
in
{
packages.tfx-cli = pkgs.tfx-cli;

devShells.default =
with pkgs;
mkShell {
packages = [
azure-cli
curl
git
jq
just
nodejs_22
pinact
sd
tfx-cli
typescript
];
};

formatter = pkgs.nixfmt-tree;
}
)
// {
overlays.default = final: prev: {
tfx-cli = final.callPackage ./nix/tfx-cli.nix { };
};
};
}
68 changes: 68 additions & 0 deletions justfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
typescript_source := justfile_directory() / "sysdig-cli-scan-task"
azure_devops_access_token := env_var_or_default("AZURE_DEVOPS_ACCESS_TOKEN", "")

# List available recipes
default:
@just --list

# Install deps and compile the TypeScript task
build:
npm install
cd {{typescript_source}} && npm install && tsc

# Publish a test build shared with the sysdigtest org
publish-local: build
tfx extension publish \
--manifest-globs vss-extension-test.json \
--publisher IgorEulalio \
--extension-id b52fe4a2-0476-4973-bc50-cc44e9032e11 \
--share-with sysdigtest \
--token {{azure_devops_access_token}}

# Publish the release build to the marketplace
publish-release:
tfx extension publish \
--manifest-globs {{justfile_directory()}}/vss-extension.json \
--overrides-file {{justfile_directory()}}/vss-extension-release.json \
--token {{azure_devops_access_token}}

# Pin GitHub Actions to commit SHAs
pin-actions:
pinact run -u

# Update everything: flake inputs, tfx-cli, and pinned actions
update:
nix flake update
nix develop --command just update-tfx
nix develop --command just pin-actions

# Bump tfx-cli to the latest upstream commit and recompute its hashes
update-tfx:
#!/usr/bin/env bash
set -euo pipefail
rev="$(git ls-remote https://github.com/Microsoft/tfs-cli HEAD | cut -f1)"
version="$(curl -fsSL "https://raw.githubusercontent.com/Microsoft/tfs-cli/${rev}/package.json" | jq -r .version)"
sd 'rev = ".*";' "rev = \"${rev}\";" nix/tfx-cli.nix
sd 'version = ".*";' "version = \"${version}\";" nix/tfx-cli.nix
just rehash-tfx
echo "tfx-cli -> ${version} (${rev})"

# Recompute the source and npm hashes in nix/tfx-cli.nix
rehash-tfx:
#!/usr/bin/env bash
set -euo pipefail
rehash() {
local key="$1" old new
old="$(grep -oE "${key} = \"[^\"]*\"" nix/tfx-cli.nix | head -1)"
sd "${key} = \".*\";" "${key} = \"\";" nix/tfx-cli.nix
new="$( (nix build -L --no-link .#tfx-cli || true) 2>&1 | sed -nE 's/.*got:[[:space:]]+([^ ]+).*/\1/p' | tail -1)"
if [ -z "${new}" ]; then
sd "${key} = \".*\";" "${old};" nix/tfx-cli.nix
echo "error: could not parse a new ${key}; restored previous value" >&2
exit 1
fi
sd "${key} = \"\";" "${key} = \"${new}\";" nix/tfx-cli.nix
echo "${key} -> ${new}"
}
rehash hash
rehash npmDepsHash
Loading