From 9fd699e301eeb5e7168474fd9044461e41299293 Mon Sep 17 00:00:00 2001 From: Lemon-miaow Date: Sun, 27 Sep 2026 17:06:20 +0800 Subject: [PATCH] =?UTF-8?q?ci(alerts):=20=E7=94=A8=E5=9B=BA=E5=AE=9A?= =?UTF-8?q?=E7=89=88=E6=9C=AC=E7=9A=84=20promtool=203.15.0=20=E6=A3=80?= =?UTF-8?q?=E6=9F=A5=E5=91=8A=E8=AD=A6=E8=A7=84=E5=88=99=E5=B9=B6=E8=B7=91?= =?UTF-8?q?=E8=A7=84=E5=88=99=E5=8D=95=E6=B5=8B?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/ci.yml | 19 +++++++++++++++++++ .github/workflows/release.yml | 7 ++++--- 2 files changed, 23 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f85df98..36807a6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -142,6 +142,25 @@ jobs: - run: sh deploy/uninstall_test.sh - run: bash deploy/e2e_release_test.sh + # The shipped alert rules (deploy/alerts): promtool parses them and runs their unit tests, + # which pin when each alert fires and that it stays quiet before. internal/metrics' + # alerts_test.go pins what promtool cannot see from there: the PrometheusRule twin and the + # metric names the rules read. + alerts: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + + # A pinned release, like shellcheck's, so a new Prometheus cannot change what fails. + - name: promtool + run: | + curl -fsSL -o prometheus.tar.gz \ + https://github.com/prometheus/prometheus/releases/download/v3.15.0/prometheus-3.15.0.linux-amd64.tar.gz + echo "2a542df32eac02ee17b9d844fb2aa1de00dafa5476579ba8a3ba862e9d572ea0 prometheus.tar.gz" | sha256sum -c + tar -xzf prometheus.tar.gz --strip-components=1 prometheus-3.15.0.linux-amd64/promtool + ./promtool check rules deploy/alerts/felis-alerts.yaml + ./promtool test rules deploy/alerts/felis-alerts_test.yml + panel: runs-on: ubuntu-latest steps: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 12937c6..aba745a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -39,9 +39,10 @@ permissions: jobs: # A tag that ships red is worse than a tag that fails to ship. These are ci.yml's gates, # called rather than copied: Go (race, vet, staticcheck), govulncheck, the PostgreSQL - # contract suite, shellcheck and the bootstrap tests, the panel, and the Java layer the - # binary EMBEDS (bootstrap_asset.go ships the plugin sources, so a tag whose plugins do - # not compile turns every install of that release into a failed bootstrap). + # contract suite, shellcheck and the bootstrap tests, promtool on the alert rules, the + # panel, and the Java layer the binary EMBEDS (bootstrap_asset.go ships the plugin + # sources, so a tag whose plugins do not compile turns every install of that release into + # a failed bootstrap). gates: uses: ./.github/workflows/ci.yml