Skip to content

feat(runner/triggers): detect Services whose selector matches no endpoints #428

feat(runner/triggers): detect Services whose selector matches no endpoints

feat(runner/triggers): detect Services whose selector matches no endpoints #428

name: Update Image Tags on PR
on:
pull_request:
branches:
- main
- prod
types: [opened, synchronize, reopened]
permissions:
contents: read
jobs:
update-tags:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
packages: read
steps:
- name: Checkout PR branch
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
token: ${{ secrets.GITHUB_TOKEN }}
ref: ${{ github.head_ref }}
- name: Update image tags
working-directory: ./charts/nudgebee-agent
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
BASE_REF: ${{ github.base_ref }}
run: |
echo "Updating image tags for $BASE_REF branch..."
# nudgebee-agent: newest timestamp_sha tag from GHCR
nudgebee_app_image=$(gh api -H "Accept: application/vnd.github+json" \
"/orgs/nudgebee/packages/container/nudgebee-agent/versions?per_page=20" \
--jq '[.[].metadata.container.tags[]] | map(select(test("^[0-9]{4}-"))) | .[0]')
echo "nudgebee_app_image: $nudgebee_app_image"
yq -i ".runner.image.tag=\"$nudgebee_app_image\"" values.yaml
# node-agent: newest semver tag from GHCR
nudgebee_node_image=$(gh api -H "Accept: application/vnd.github+json" \
"/orgs/nudgebee/packages/container/node-agent/versions?per_page=20" \
--jq '[.[].metadata.container.tags[]] | map(select(test("^[0-9]+\\.[0-9]+\\.[0-9]+"))) | .[0]')
echo "nudgebee_node_image: $nudgebee_node_image"
yq -i ".nodeAgent.image.tag=\"$nudgebee_node_image\"" values.yaml
# kubewatch: newest semver tag from GHCR
nudgebee_kubewatch_image=$(gh api -H "Accept: application/vnd.github+json" \
"/orgs/nudgebee/packages/container/kubewatch/versions?per_page=20" \
--jq '[.[].metadata.container.tags[]] | map(select(test("^[0-9]+\\.[0-9]+\\.[0-9]+"))) | .[0]')
echo "nudgebee_kubewatch_image: $nudgebee_kubewatch_image"
yq -i ".kubewatch.image.tag=\"$nudgebee_kubewatch_image\"" values.yaml
# application-profiler: newest short-SHA tag from GHCR (bpf is canonical;
# all variants share the same SHA since release.yml builds them together).
# The `{}` placeholder is preserved — the agent substitutes it per variant at runtime.
nudgebee_profiler_sha=$(gh api -H "Accept: application/vnd.github+json" \
"/orgs/nudgebee/packages/container/application-profiler-bpf/versions?per_page=20" \
--jq '[.[].metadata.container.tags[]] | map(select(test("^[0-9a-f]{7}$"))) | .[0]')
echo "nudgebee_profiler_sha: $nudgebee_profiler_sha"
yq -i ".runner.profilerImage=\"ghcr.io/nudgebee/application-profiler-{}:$nudgebee_profiler_sha\"" values.yaml
- name: Commit updated image tags
env:
BASE_REF: ${{ github.base_ref }}
HEAD_REF: ${{ github.head_ref }}
run: |
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
if [[ -n $(git status --porcelain) ]]; then
git add charts/nudgebee-agent/values.yaml
git commit -m "chore: update image tags for $BASE_REF release"
git push origin "$HEAD_REF"
echo "Image tags updated and committed to PR branch"
else
echo "No changes to commit - image tags are already up to date"
fi
- name: Comment on PR
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
BASE_REF: ${{ github.base_ref }}
with:
script: |
const { data: files } = await github.rest.pulls.listFiles({
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: context.issue.number,
});
const valuesChanged = files.some(file => file.filename.includes('values.yaml'));
if (valuesChanged) {
await github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
repo: context.repo.repo,
body: `📦 **Image Tags Updated**
I've automatically updated the image tags in \`charts/nudgebee-agent/values.yaml\` to the latest versions from GHCR for the \`${process.env.BASE_REF}\` branch.
The image tags are now synchronized with the latest builds and ready for release.`
});
}