Repository navigation
ci: gate chart releases on version bumps and image tags, and alert on drift - #52
Conversation
… drift Add a Chart checks workflow on every PR to `main`. It fails when `helm/` changed but the chart `version` did not, when `image.tag` in `helm/values.yaml` is set and differs from `appVersion`, and when `docker manifest inspect` cannot resolve the image at `appVersion`. The release workflow now refuses to overwrite a published tarball on gh-pages, checks the image before publishing, and runs on any `helm/**` change. Add a daily Chart drift workflow. When the newest stable image tag has been on Docker Hub for 72 hours and the published chart still ships an older `appVersion`, it posts to Slack and fails the run. Delete `helm/.github/workflows/release.yaml`. GitHub only reads workflows from the repo root, so it never ran. Bump the chart to `0.11.9`, with the `ChartVersion` default in `cloudformation/firewall-eks.yaml` and `cloudformation/README.md` to match.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit eb943f7. Configure here.
Andre Coetzee (Andre153)
left a comment
There was a problem hiding this comment.
Approving. The three workflows do what the description says. I reproduced the version-bump, tag==appVersion and manifest steps, the already-published guard, and the drift job's jq against live Docker Hub and index.yaml data. actionlint and zizmor are clean on the new files; the two hits in release.yaml predate this PR.
Two things the gates leave open, both inline: the version check is stale once main moves, so same-number bumps from two PRs can both land; and CloudFormation ChartVersion is not covered although the release bot refuses to run when it drifts (#48 trips this today).
Bugbot's ordering finding is wrong; evidence in that thread. An autofix that flips the sign makes the drift job alert on every run.
Also confirmed: every published tarball through 0.11.8 contains .github/workflows/release.yaml (there is no .helmignore), so the 0.11.9 bump is a real content change.
The firewall release bot rewrites the chart version and image pins in `helm/`, `cloudformation/firewall-eks.yaml` and the two READMEs, and exits without opening the bump PR when any pin is missing or differs from `helm/Chart.yaml`. Chart checks now matches each pin with the bot's own patterns and fails the PR when one is missing, duplicated, or different.

Linear: FIRE-197
Chart releases lagged image releases, and a published chart version could change after release. The release bot in socket-nginx-firewall already opens the image bump PR here (PR 51 for
2.9.10). This PR adds gates and a drift alert around it..github/workflows/chart-checks.yaml(new, every PR tomain) fails whenhelm/changed butversioninhelm/Chart.yamldid not, whenimage.taginhelm/values.yamlis set and differs fromappVersion, whendocker manifest inspectcannot resolve the image atappVersion, and when a pin the firewall release bot rewrites differs fromhelm/Chart.yaml. The bot updates the chart version and image pins inhelm/values.yaml,helm/README.md,cloudformation/firewall-eks.yaml,cloudformation/values/dns-override.values.yamlandcloudformation/README.md, and exits without opening its bump PR when one is missing or does not match. The check uses the bot's patterns. A GitHub release can exist without its Docker Hub tag:v2.0.9has one, andsocketdev/socket-registry-firewall:2.0.9returns 404..github/workflows/release.yamlexits with an error when the chart tarball already exists on gh-pages instead of overwriting it, checks the image before publishing, and triggers onhelm/**. Chart0.9.0was published twice with different contents after ahelm/README.mdchange fired the release without a version bump..github/workflows/chart-drift.yaml(new, daily at 14:00 UTC) posts to Slack throughSLACK_HELM_DRIFT_WEBHOOK_URLin thealertsenvironment and fails the run when the newest stable image tag on Docker Hub differs from the published chart'sappVersionand was pushed more than 72 hours ago.image.tagstays pinned inhelm/values.yamlbecause the release bot rewrites it on every bump. The new check keeps it equal toappVersion.helm/.github/workflows/release.yaml. GitHub only reads workflows from the repo root, so it never ran.0.11.8to0.11.9, with theChartVersiondefault incloudformation/firewall-eks.yamlandcloudformation/README.mdto match. The release bot requires them to equal the chart version.Testing
chart-checks.yamlstep in a scratch repo. It passes on this branch and fails on ahelm/change without a bump, on a mismatchedimage.tag, and onappVersion2.0.9. A change outsidehelm/skips the version check.ChartVersiondefault incloudformation/firewall-eks.yamland the chart version line incloudformation/README.md. The release bot's updater gives the same result on both trees.docker manifest inspectresolvessocketdev/socket-registry-firewall:2.9.10and fails for2.0.9.curlresponses. In sync and drift under 72 hours exit 0. Drift past 72 hours fails, posts when the webhook is set, and reports the missing secret when it is not.2.9.10sorts above2.9.9.actionlintpasses onchart-checks.yaml. Not run:zizmor.After merge
SLACK_HELM_DRIFT_WEBHOOK_URLin thealertsenvironment.mainwith "Require branches to be up to date before merging". The version check compares against the base at the PR's last push, so two PRs can both bump to the same version. With the up-to-date rule, the second PR has to rebase, the check runs again, and it fails until the version is bumped.ChartVersiondefault incloudformation/firewall-eks.yamlandcloudformation/README.mdto its chart version.Out of scope: OCI registry push (CE-119) and moving off the socketdev-demo download URL (CE-238).
Note
Low Risk
Changes are limited to GitHub Actions, Helm metadata, and CloudFormation default strings; release behavior is stricter but does not alter runtime firewall code.
Overview
Adds CI gates and monitoring so Helm chart releases stay immutable, aligned with Docker images, and don’t publish missing tags.
PR checks (
chart-checks.yaml): anyhelm/change must bumpChart.yamlversion; non-emptyvalues.yamlimage.tagmust matchappVersion;docker manifest inspectmust resolve the image atappVersion.Release workflow (
release.yaml): triggers on allhelm/**changes; verifies the image exists before publish; refuses to overwrite an already-published chart tarball on gh-pages.Drift detection (
chart-drift.yaml): daily job compares newest semver Docker Hub tag to the published chart’sappVersionand fails (and Slack-alerts viaalertsenv) when the image has been newer for more than 72 hours.Removes the unused
helm/.github/workflows/release.yaml. Bumps chart 0.11.8 → 0.11.9 and syncs CloudFormationChartVersiondefaults;Chart.yamlcomments document theimage.tag/appVersioncontract enforced by CI.Reviewed by Cursor Bugbot for commit eb943f7. Configure here.