From 679be5dedc55fdda17cce98eeb3c7e574bcfe6b7 Mon Sep 17 00:00:00 2001 From: Chris Farhood Date: Mon, 9 Feb 2026 13:03:07 -0500 Subject: [PATCH 1/2] fix: only update GitHub main for stable releases --- .gitea/workflows/release.yaml | 26 +++++++++++++++++++++----- 1 file changed, 21 insertions(+), 5 deletions(-) diff --git a/.gitea/workflows/release.yaml b/.gitea/workflows/release.yaml index ca7f00d..3e16e83 100644 --- a/.gitea/workflows/release.yaml +++ b/.gitea/workflows/release.yaml @@ -115,6 +115,9 @@ jobs: continue-on-error: true run: | [ "$SKIP_BUILD" = "true" ] && exit 0 + # Push tag to GitHub first so it exists before creating the release + git remote add github-release https://x-access-token:${{ secrets.GH_PAT }}@github.com/cpfarhood/headlamp-polaris-plugin.git 2>/dev/null || true + git push -f github-release ${GITHUB_REF_NAME} 2>/dev/null || true GH_API="https://api.github.com/repos/cpfarhood/headlamp-polaris-plugin" # Create release or fetch existing one BODY=$(curl -s -X POST \ @@ -163,23 +166,36 @@ jobs: VERSION=${GITHUB_REF_NAME#v} git config user.name "gitea-actions[bot]" git config user.email "gitea-actions[bot]@git.farh.net" - git fetch origin main - git checkout origin/main -B main + # Determine which Gitea branch to update based on version suffix + if [[ "$VERSION" == *"-dev."* ]]; then + GITEA_BRANCH="dev/namespace-drawer" + else + GITEA_BRANCH="main" + fi + git fetch origin ${GITEA_BRANCH} + git checkout origin/${GITEA_BRANCH} -B temp-update sed -i "s|headlamp/plugin/archive-checksum:.*|headlamp/plugin/archive-checksum: sha256:${CHECKSUM}|" artifacthub-pkg.yml sed -i "s|headlamp/plugin/archive-url:.*|headlamp/plugin/archive-url: \"https://github.com/cpfarhood/headlamp-polaris-plugin/releases/download/${GITHUB_REF_NAME}/headlamp-polaris-plugin-${VERSION}.tar.gz\"|" artifacthub-pkg.yml sed -i "s|^version:.*|version: ${VERSION}|" artifacthub-pkg.yml git add artifacthub-pkg.yml git diff --cached --quiet || { git commit -m "ci: update artifact hub metadata for ${GITHUB_REF_NAME}" - git push origin main + git push origin temp-update:${GITEA_BRANCH} } # Force-move tag to the commit with correct checksum. # This triggers a new CI run, but the guard step will detect # that the release checksum already matches and skip the build. git tag -f ${GITHUB_REF_NAME} git push -f origin ${GITHUB_REF_NAME} - # Also push to GitHub directly to avoid waiting for mirror sync + # Only push to GitHub main branch for STABLE releases + # Dev releases only create GitHub releases, don't update main branch + # This keeps GitHub main branch at latest stable for ArtifactHub git remote add github https://x-access-token:${{ secrets.GH_PAT }}@github.com/cpfarhood/headlamp-polaris-plugin.git 2>/dev/null || true - git push github main 2>/dev/null || true + if [[ "$VERSION" != *"-dev."* ]]; then + echo "Stable release detected - pushing to GitHub main branch" + git push github temp-update:main 2>/dev/null || true + else + echo "Dev release detected - skipping GitHub main branch update" + fi git push -f github ${GITHUB_REF_NAME} 2>/dev/null || true echo "Tag ${GITHUB_REF_NAME} aligned with updated metadata" From 2c26d49bf9c34da5c9619f5cbc4c2e1f0273fb0a Mon Sep 17 00:00:00 2001 From: Chris Farhood Date: Mon, 9 Feb 2026 13:41:30 -0500 Subject: [PATCH 2/2] docs: add dev/preview version installation instructions Documents how to install dev preview versions using direct URLs since they are not published to ArtifactHub. Includes sidecar pattern example and manual download instructions. --- README.md | 53 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) diff --git a/README.md b/README.md index 1da893b..948c89e 100644 --- a/README.md +++ b/README.md @@ -83,6 +83,59 @@ npm run build npx @kinvolk/headlamp-plugin extract . /headlamp/plugins ``` +## Installing Dev/Preview Versions + +Dev preview versions (e.g., `v0.2.0-dev.4`) are published to [GitHub Releases](https://github.com/cpfarhood/headlamp-polaris-plugin/releases) but are **not available via ArtifactHub**. These versions contain experimental features and are intended for testing. + +To install a dev version, use the direct URL method: + +### Sidecar container pattern (recommended) + +Create a ConfigMap with the dev version URL: + +```yaml +apiVersion: v1 +kind: ConfigMap +metadata: + name: headlamp-plugin-config + namespace: kube-system +data: + plugin.yml: | + plugins: + - url: https://github.com/cpfarhood/headlamp-polaris-plugin/releases/download/v0.2.0-dev.4/headlamp-polaris-plugin-0.2.0-dev.4.tar.gz +``` + +Then configure Headlamp to use a sidecar container that installs from this config: + +```yaml +# In Headlamp Helm values or deployment +containers: + - name: headlamp-plugin-installer + image: node:lts-alpine + command: ["/bin/sh", "-c"] + args: + - | + npm install -g @kinvolk/headlamp-plugin + headlamp-plugin install --config /config/plugin.yml + volumeMounts: + - name: plugins + mountPath: /headlamp/plugins + - name: plugin-config + mountPath: /config +volumes: + - name: plugins + emptyDir: {} + - name: plugin-config + configMap: + name: headlamp-plugin-config +``` + +### Manual download + +Browse [GitHub Releases](https://github.com/cpfarhood/headlamp-polaris-plugin/releases), download the dev version tarball, and extract it to your Headlamp plugins directory. + +**Note:** Dev versions are tagged with the `-dev.N` suffix and may introduce breaking changes or unstable features. Use stable versions for production deployments. + ## RBAC / Security Setup The plugin fetches audit data through the Kubernetes API server's **service proxy** sub-resource. The identity making the request (Headlamp's service account, or the user's own token in token-auth mode) must be granted: