1.9 KiB
1.9 KiB
webhook-interceptor
The Webhook Interceptor checks for specific conditions when a webhook is received.
This way we can trigger cleanups when the PR is closed.
HTTP Headers
Push Event
X-Interceptor-Push-Ref: string: "refs/heads/master"
X-Interceptor-Include-Repo: []string{"my/repo"}
X-Interceptor-Exclude-Repo: []string{"my/repo"}
Response Headers:
Commit: <Head Commit Hash>
Pull-Request Event
X-Interceptor-Pr-Action: []string{"opened", "reopened", "synchronize", "synchronized"}
Response Headers:
Issue: <Pull-Request ID>
Commit: <Pull-Request Head Commit Hash>
Issue Comment Event
X-Interceptor-Comment: "/test-deploy"
X-Interceptor-Comment-Action: []string{"created"}
X-Interceptor-Label: "test-deploy:#aabbcc"
X-Interceptor-Remove-Labels: []string{"test", "deploy"}
Actions
/test- addtestlabel and run test pipeline/deploy- adddeploylabel and run deploy pipeline/test-deploy- addtest-deploylabel and run test-deploy pipeline
Response Headers:
Issue: <Pull-Request ID>
Commit: <Pull-Request Head Commit Hash>
Validate Webhooks
Add secret webhook keys you want to have validated.
NOTE: the name must be webhook-secret.
cat <<EOF>webhook-secret.yaml
apiVersion: v1
kind: Secret
metadata:
name: webhook-secret
namespace: webhook-interceptor
type: Opaque
stringData:
github.com: "<secreet>"
github.com_foo: "<foo secret>"
github.com_foo_bar: "<bar secret>"
EOF
Build and run
Create git authentication secret:
NOTE: the name must be git-auth.
cat <<EOF>secret.yaml
apiVersion: v1
kind: Secret
metadata:
name: git-auth
namespace: webhook-interceptor
type: Opaque
stringData:
github.com: "<username>:<password>"
github.com_foo: "<foo username>:<foo password>"
github.com_foo_bar: "<bar username>:<bar password>"
EOF
echo KO_DOCKER_REPO='gcr.io/my-gcloud-project-name' >env.txt
./build.sh