49 lines
1.5 KiB
Python
Executable File
49 lines
1.5 KiB
Python
Executable File
#!/usr/bin/env python3
|
|
"""Fail closed unless a delivery capability is enabled in reviewed config."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import argparse
|
|
import json
|
|
from pathlib import Path
|
|
import sys
|
|
|
|
|
|
CAPABILITIES = {"package_publish", "static_deploy"}
|
|
|
|
|
|
class GateError(RuntimeError):
|
|
pass
|
|
|
|
|
|
def check(config_path: Path, capability: str) -> None:
|
|
if capability not in CAPABILITIES:
|
|
raise GateError(f"unsupported delivery capability: {capability}")
|
|
try:
|
|
config = json.loads(config_path.read_text(encoding="utf-8"))
|
|
except (OSError, json.JSONDecodeError) as exc:
|
|
raise GateError(f"invalid delivery configuration: {exc}") from exc
|
|
if set(config) != {"schema", *CAPABILITIES} or config["schema"] != 1:
|
|
raise GateError("delivery configuration has an unsupported shape or schema")
|
|
if any(type(config[name]) is not bool for name in CAPABILITIES):
|
|
raise GateError("delivery capability values must be booleans")
|
|
if not config[capability]:
|
|
raise GateError(f"{capability} is disabled in reviewed repository configuration")
|
|
|
|
|
|
def main() -> int:
|
|
parser = argparse.ArgumentParser(description=__doc__)
|
|
parser.add_argument("capability", choices=sorted(CAPABILITIES))
|
|
parser.add_argument("--config", type=Path, default=Path(".delivery/config.json"))
|
|
args = parser.parse_args()
|
|
try:
|
|
check(args.config, args.capability)
|
|
except GateError as exc:
|
|
print(f"error: {exc}", file=sys.stderr)
|
|
return 1
|
|
return 0
|
|
|
|
|
|
if __name__ == "__main__":
|
|
raise SystemExit(main())
|