From 104372adbe4cb1a3f33338923c39a128aa3be87a Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 10 Sep 2026 12:56:14 +0200 Subject: [PATCH 01/10] enable typos in operator-templating and downstream --- .pre-commit-config.yaml | 9 ++++ README.md | 73 +++++++++++++++++++++++++++++ template/.pre-commit-config.yaml.j2 | 14 ++++++ 3 files changed, 96 insertions(+) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 85e824d0..f7817110 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -5,6 +5,15 @@ default_language_version: node: system repos: + - repo: https://github.com/crate-ci/typos + rev: v1.50.1 + hooks: + - id: typos + # Drop the upstream default `--write-changes` so the hook reports and + # fails instead of rewriting files. Keep `--force-exclude` so the + # excludes in typos.toml still apply to the paths prek passes in. + args: ["--force-exclude"] + - repo: https://github.com/pre-commit/pre-commit-hooks rev: 3e8a8703264a2f4a69428a0aa4dcb512790b2c8c # 6.0.0 hooks: diff --git a/README.md b/README.md index 9972f105..4521fe66 100644 --- a/README.md +++ b/README.md @@ -65,6 +65,79 @@ These are the only variables currently being used on the playbooks, but can be e Additional settings can be found in `playbook/group_vars/all`, but these are not intended to be freely changed and should be treated with care. +## Spell checking + +Every managed repository runs [typos](https://github.com/crate-ci/typos) as a prek hook. +The hook is templated in `template/.pre-commit-config.yaml.j2`. +The word lists are **not** templated: each repository carries its own `typos.toml`, hand-maintained. + +That split is forced by the tool. typos has no layered configuration yet ([crate-ci/typos#193](https://github.com/crate-ci/typos/issues/193)). +Keeping the word lists local also means adding a word is a single PR in a single repository, rather than a PR here plus a sync to every managed repository. + +### The core config + +As convention, new repositories should start from this block and add only what they actually need. + +```toml +[files] +# Bare `typos` skips hidden directories, but prek passes explicit paths and so does +# check them. Turn it off so a local run and the hook agree; without it, .github/ +# and .readme/ are invisible locally but not to CI. +ignore-hidden = false + +extend-exclude = [ + # Required once ignore-hidden is off, or typos walks .git/objects. + ".git/", + # Generated by `make regenerate-nix` (crate2nix). + "Cargo.nix", + "crate-hashes.json", + # Generated by `make crds`. See "check each string once" below. + "extra/crds.yaml", + "deploy/helm/*/crds/crds.yaml", + # Diagram sources; the payload is base64 and produces only noise. + "*.drawio", + "*.drawio.svg", +] + +[default] +# typos has no native suppression directive (crate-ci/typos#316), so these regexes +# provide one. They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` +# comments. Both failure modes are safe: an unterminated `:off` suppresses nothing +# rather than swallowing the rest of the file, and `disable-line` only matches when +# the marker ends the line, so trailing text defeats it instead of widening it. +extend-ignore-re = [ + "(?Rm)^.*(#|//||#\\}|\\*/)?\\s*$", + "(#|//||#\\}|\\*/)?\\s*\\n.*", + "(?s)(#|//||#\\}|\\*/|\")?.*?(#|//||#\\}|\\*/|\")?", +] + +[default.extend-words] +# Azure Kubernetes Service. Appears in the README footer and as the runner platform +# in tests/interu.yaml. A single lowercase entry covers every casing. +aks = "aks" +``` + +`aks` is the only word that is genuinely universal. +Everything else measured across the operator repositories turned out to be repo-local: `aas` in opa-operator, `shs` in spark-k8s-operator, base64 fixtures in secret-operator. +Short tokens that appear in several repositories (`ot`, `fo`) do so for unrelated reasons and belong in the repository that has them, not here. + +### Check each string once + +`extra/crds.yaml` is excluded on purpose. +Its content is generated: partly Kubernetes' own schema documentation, which is not ours to correct, and partly doc comments owned by `operator-rs` or by the operator's own `crd` module — both of which are already checked at their source. +The same applies to files rendered from `template/`: a typo in `template/.readme/partials/borrowed/footer.md.j2.j2` is caught here, once, instead of in all sixteen repositories. + +> [!NOTE] +> Excluding rendered content more thoroughly — everything a repository receives from `operator-templating` or `operator-rs` — is a known refinement that has not been done yet. +> The generated CRDs are the case that mattered in practice. + +### Conventions + +- The hook runs report-only. `args: ["--force-exclude"]`. +- Every entry in a `typos.toml` gets a one-line comment saying what the word is. +- Prefer an in-place marker over a config entry when the word is correct at one site and would still be a typo elsewhere: `spellchecker:disable-line` at the end of the line, `spellchecker:ignore-next-line` on the line above, or `spellchecker:off` / `:on` around a block. +- Licence and other verbatim third-party files are excluded, never corrected. + ## Making changes to the template If you want to make a change that should be rolled out to all operators, make the change in the `template` directory. diff --git a/template/.pre-commit-config.yaml.j2 b/template/.pre-commit-config.yaml.j2 index 8b73bcdf..2f56acbb 100644 --- a/template/.pre-commit-config.yaml.j2 +++ b/template/.pre-commit-config.yaml.j2 @@ -7,6 +7,20 @@ default_language_version: node: system repos: + # The word lists live in a per-repo `typos.toml`, which is deliberately NOT + # templated: typos has no layered configuration + # (https://github.com/crate-ci/typos/issues/193), so the nearest config file + # wins outright and a templated one could not be extended locally. Only the + # hook itself is shared, because it is identical everywhere. + - repo: https://github.com/crate-ci/typos + rev: v1.50.1 + hooks: + - id: typos + # Drop the upstream default `--write-changes` so the hook reports and + # fails instead of rewriting files. Keep `--force-exclude` so the + # excludes in typos.toml still apply to the paths prek passes in. + args: ["--force-exclude"] + - repo: https://github.com/pre-commit/pre-commit-hooks rev: 3e8a8703264a2f4a69428a0aa4dcb512790b2c8c # 6.0.0 hooks: From 8fc24729231e48ec76d73b72694d9dbd2a61978b Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 10 Sep 2026 13:01:09 +0200 Subject: [PATCH 02/10] Adding typos.toml --- typos.toml | 52 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 typos.toml diff --git a/typos.toml b/typos.toml new file mode 100644 index 00000000..7811a496 --- /dev/null +++ b/typos.toml @@ -0,0 +1,52 @@ +# Configuration for typos (https://github.com/crate-ci/typos), run via the prek +# hook in .pre-commit-config.yaml. +# +# This config covers operator-templating itself. The operator repositories each +# carry their own typos.toml, which is deliberately NOT rolled out from +# template/: typos has no layered configuration +# (https://github.com/crate-ci/typos/issues/193), so the nearest config file +# wins outright and is never merged with one further up the tree. A templated +# config could not be extended with repo-specific words, and adding one word to +# one operator would otherwise mean a PR here plus a sync to all repositories. +# +# Only the hook is shared, via template/.pre-commit-config.yaml.j2. +# +# Before adding an entry here, consider an in-place marker instead. Use one when +# the word is correct at this one site and would still be a typo elsewhere: +# +# # spellchecker:disable-line at the end of the line it applies to +# # spellchecker:ignore-next-line on its own line, above the offending line +# # spellchecker:off / :on around a block +# +# Every entry below gets a one-line comment saying what the word is. + +[files] +# Bare `typos` skips hidden directories, but prek passes explicit paths and so +# does check them. Turn it off so both agree -- without this, template/.readme/ +# and template/.github/ are invisible to a local run but not to the hook. +ignore-hidden = false + +extend-exclude = [ + # `.git` itself, which ignore-hidden = false would otherwise pull in. + ".git/", +] + +[default] +# typos has no native suppression directive +# (https://github.com/crate-ci/typos/issues/316), so these regexes provide one. +# They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` comments. +# +# Both failure modes are safe: an unterminated `:off` suppresses nothing rather +# than swallowing the rest of the file, and `disable-line` only matches when the +# marker ends the line, so trailing text defeats it instead of widening it. +extend-ignore-re = [ + "(?Rm)^.*(#|//||#\\}|\\*/)?\\s*$", + "(#|//||#\\}|\\*/)?\\s*\\n.*", + "(?s)(#|//||#\\}|\\*/|\")?.*?(#|//||#\\}|\\*/|\")?", +] + +[default.extend-words] +# Azure Kubernetes Service. Appears in the README footer partial that is +# rendered into every operator repository. A single lowercase entry covers +# every casing, so no separate `AKS` entry is needed. +aks = "aks" From 4d9b209c7beb083801ea954749b1dbdba4c522bb Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Wed, 30 Sep 2026 14:56:53 +0200 Subject: [PATCH 03/10] Polishing files --- .pre-commit-config.yaml | 5 +++-- README.md | 5 ++--- template/.pre-commit-config.yaml.j2 | 13 ++++++------- typos.toml | 9 ++++----- 4 files changed, 15 insertions(+), 17 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index f7817110..fe90094e 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -6,11 +6,12 @@ default_language_version: repos: - repo: https://github.com/crate-ci/typos - rev: v1.50.1 + rev: 43b6c087ac471e2ea7b8af622ff15f05c0c365b # v1.50.1 hooks: - id: typos # Drop the upstream default `--write-changes` so the hook reports and - # fails instead of rewriting files. Keep `--force-exclude` so the + # fails instead of rewriting files. + # Keep `--force-exclude` so the # excludes in typos.toml still apply to the paths prek passes in. args: ["--force-exclude"] diff --git a/README.md b/README.md index 4521fe66..0e6ae519 100644 --- a/README.md +++ b/README.md @@ -81,8 +81,7 @@ As convention, new repositories should start from this block and add only what t ```toml [files] # Bare `typos` skips hidden directories, but prek passes explicit paths and so does -# check them. Turn it off so a local run and the hook agree; without it, .github/ -# and .readme/ are invisible locally but not to CI. +# check them. ignore-hidden = false extend-exclude = [ @@ -117,7 +116,7 @@ extend-ignore-re = [ aks = "aks" ``` -`aks` is the only word that is genuinely universal. +`aks` is the only word that is universal. Everything else measured across the operator repositories turned out to be repo-local: `aas` in opa-operator, `shs` in spark-k8s-operator, base64 fixtures in secret-operator. Short tokens that appear in several repositories (`ot`, `fo`) do so for unrelated reasons and belong in the repository that has them, not here. diff --git a/template/.pre-commit-config.yaml.j2 b/template/.pre-commit-config.yaml.j2 index 2f56acbb..00785c58 100644 --- a/template/.pre-commit-config.yaml.j2 +++ b/template/.pre-commit-config.yaml.j2 @@ -7,17 +7,16 @@ default_language_version: node: system repos: - # The word lists live in a per-repo `typos.toml`, which is deliberately NOT - # templated: typos has no layered configuration - # (https://github.com/crate-ci/typos/issues/193), so the nearest config file - # wins outright and a templated one could not be extended locally. Only the - # hook itself is shared, because it is identical everywhere. + # The word lists live in a per-repo `typos.toml`, which is not templated. + # typos has no layered configuration (https://github.com/crate-ci/typos/issues/193). + # A templated config can currently not be extended locally. - repo: https://github.com/crate-ci/typos - rev: v1.50.1 + rev: 43b6c087ac471e2ea7b8af622ff15f05c0c365b # v1.50.1 hooks: - id: typos # Drop the upstream default `--write-changes` so the hook reports and - # fails instead of rewriting files. Keep `--force-exclude` so the + # fails instead of rewriting files. + # Keep `--force-exclude` so the # excludes in typos.toml still apply to the paths prek passes in. args: ["--force-exclude"] diff --git a/typos.toml b/typos.toml index 7811a496..10408d1c 100644 --- a/typos.toml +++ b/typos.toml @@ -2,11 +2,9 @@ # hook in .pre-commit-config.yaml. # # This config covers operator-templating itself. The operator repositories each -# carry their own typos.toml, which is deliberately NOT rolled out from -# template/: typos has no layered configuration -# (https://github.com/crate-ci/typos/issues/193), so the nearest config file -# wins outright and is never merged with one further up the tree. A templated -# config could not be extended with repo-specific words, and adding one word to +# carry their own typos.toml, which is NOT rolled out from template. +# typos has no layered configuration (https://github.com/crate-ci/typos/issues/193), +# templated config could not be extended with repo-specific words, and adding one word to # one operator would otherwise mean a PR here plus a sync to all repositories. # # Only the hook is shared, via template/.pre-commit-config.yaml.j2. @@ -24,6 +22,7 @@ # Bare `typos` skips hidden directories, but prek passes explicit paths and so # does check them. Turn it off so both agree -- without this, template/.readme/ # and template/.github/ are invisible to a local run but not to the hook. + ignore-hidden = false extend-exclude = [ From 2d7322de1a2c91e3ee85ac217bb1b2b13a647b19 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 1 Oct 2026 09:05:27 +0200 Subject: [PATCH 04/10] Updating rev --- .pre-commit-config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index fe90094e..7f3ab16e 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -6,7 +6,7 @@ default_language_version: repos: - repo: https://github.com/crate-ci/typos - rev: 43b6c087ac471e2ea7b8af622ff15f05c0c365b # v1.50.1 + rev: 00f422f3b19c57bc6338715ebfe3316d38768461 # v1.50.3 hooks: - id: typos # Drop the upstream default `--write-changes` so the hook reports and From 383e20a5d5b02aa78550150bf33623b082278523 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 1 Oct 2026 09:12:35 +0200 Subject: [PATCH 05/10] making prek happy --- template/.pre-commit-config.yaml.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/template/.pre-commit-config.yaml.j2 b/template/.pre-commit-config.yaml.j2 index dca5d7b5..95da7135 100644 --- a/template/.pre-commit-config.yaml.j2 +++ b/template/.pre-commit-config.yaml.j2 @@ -15,7 +15,7 @@ repos: hooks: - id: typos # Drop the upstream default `--write-changes` so the hook reports and - # fails instead of rewriting files. + # fails instead of rewriting files. # Keep `--force-exclude` so the # excludes in typos.toml still apply to the paths prek passes in. args: ["--force-exclude"] From eee19fcc4f8b7d154de372bdfcdbdf1ad0726877 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 1 Oct 2026 09:14:05 +0200 Subject: [PATCH 06/10] again ci happy dance --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 0e6ae519..c642672d 100644 --- a/README.md +++ b/README.md @@ -81,7 +81,7 @@ As convention, new repositories should start from this block and add only what t ```toml [files] # Bare `typos` skips hidden directories, but prek passes explicit paths and so does -# check them. +# check them. ignore-hidden = false extend-exclude = [ From bd1979c98684ec3de317fa132ff701db1ae78454 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 1 Oct 2026 09:16:45 +0200 Subject: [PATCH 07/10] updating typo ref for template too --- template/.pre-commit-config.yaml.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/template/.pre-commit-config.yaml.j2 b/template/.pre-commit-config.yaml.j2 index 95da7135..c931d9af 100644 --- a/template/.pre-commit-config.yaml.j2 +++ b/template/.pre-commit-config.yaml.j2 @@ -11,7 +11,7 @@ repos: # typos has no layered configuration (https://github.com/crate-ci/typos/issues/193). # A templated config can currently not be extended locally. - repo: https://github.com/crate-ci/typos - rev: 43b6c087ac471e2ea7b8af622ff15f05c0c365b # v1.50.1 + rev: 00f422f3b19c57bc6338715ebfe3316d38768461 # v1.50.3 hooks: - id: typos # Drop the upstream default `--write-changes` so the hook reports and From 3579f4f86bcfc619af758208984c850d8ab0f3b1 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 1 Oct 2026 10:20:13 +0200 Subject: [PATCH 08/10] more condensed typos.toml and README.md entries --- README.md | 60 +++++++++++++++++++++++++++++++----------------------- typos.toml | 28 ++++++++----------------- 2 files changed, 43 insertions(+), 45 deletions(-) diff --git a/README.md b/README.md index c642672d..e6acf026 100644 --- a/README.md +++ b/README.md @@ -69,41 +69,54 @@ Additional settings can be found in `playbook/group_vars/all`, but these are not Every managed repository runs [typos](https://github.com/crate-ci/typos) as a prek hook. The hook is templated in `template/.pre-commit-config.yaml.j2`. -The word lists are **not** templated: each repository carries its own `typos.toml`, hand-maintained. +The word lists are **not** templated: each repository has its own `typos.toml`. That split is forced by the tool. typos has no layered configuration yet ([crate-ci/typos#193](https://github.com/crate-ci/typos/issues/193)). -Keeping the word lists local also means adding a word is a single PR in a single repository, rather than a PR here plus a sync to every managed repository. +Keeping the word lists local also means adding a word is a PR per repository instead of a templating run. ### The core config As convention, new repositories should start from this block and add only what they actually need. ```toml +# Configuration for typos (https://github.com/crate-ci/typos), run via the prek +# hook in .pre-commit-config.yaml. +# +# Before adding an entry here, consider an in-place marker instead. Use one when +# the word is correct at this one site and would still be a typo elsewhere: +# +# # spellchecker:disable-line at the end of the line it applies to +# # spellchecker:ignore-next-line on its own line, above the offending line +# # spellchecker:off / :on around a block +# +# Every entry below gets a one-line comment saying what the word is. + [files] -# Bare `typos` skips hidden directories, but prek passes explicit paths and so does -# check them. +# Bare `typos` skips hidden dirs by default, but prek passes explicit paths and +# so does check them. Turn it off so both agree. ignore-hidden = false extend-exclude = [ - # Required once ignore-hidden is off, or typos walks .git/objects. + # `.git` itself, which ignore-hidden = false would otherwise pull in. ".git/", - # Generated by `make regenerate-nix` (crate2nix). + # Generated by `make regenerate-nix` (crate2nix). Contains vendored crate + # metadata and hashes. "Cargo.nix", - "crate-hashes.json", - # Generated by `make crds`. See "check each string once" below. + # Generated by `make crds`. Most of the content is Kubernetes' own schema + # documentation, which is not ours to correct, and the doc comments we do + # own are already checked at their source in rust/operator-binary/src/crd/. "extra/crds.yaml", - "deploy/helm/*/crds/crds.yaml", - # Diagram sources; the payload is base64 and produces only noise. - "*.drawio", - "*.drawio.svg", ] [default] -# typos has no native suppression directive (crate-ci/typos#316), so these regexes -# provide one. They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` -# comments. Both failure modes are safe: an unterminated `:off` suppresses nothing -# rather than swallowing the rest of the file, and `disable-line` only matches when -# the marker ends the line, so trailing text defeats it instead of widening it. +# typos has no native suppression directive +# (https://github.com/crate-ci/typos/issues/316), so these regexes provide one. +# They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` comments, +# which spans every file type in this repo. +# +# Both failure modes are safe: +# * unterminated `:off` suppresses nothing rather than swallowing the rest of the file. +# * `disable-line` only matches when the marker ends the line. extend-ignore-re = [ "(?Rm)^.*(#|//||#\\}|\\*/)?\\s*$", "(#|//||#\\}|\\*/)?\\s*\\n.*", @@ -111,8 +124,8 @@ extend-ignore-re = [ ] [default.extend-words] -# Azure Kubernetes Service. Appears in the README footer and as the runner platform -# in tests/interu.yaml. A single lowercase entry covers every casing. +# Azure Kubernetes Service. Appears in README footer and as the runner platform `aks-1.36` in tests/interu.yaml. +# A single lowercase entry covers every casing, so no separate `AKS` entry is needed. aks = "aks" ``` @@ -123,19 +136,14 @@ Short tokens that appear in several repositories (`ot`, `fo`) do so for unrelate ### Check each string once `extra/crds.yaml` is excluded on purpose. -Its content is generated: partly Kubernetes' own schema documentation, which is not ours to correct, and partly doc comments owned by `operator-rs` or by the operator's own `crd` module — both of which are already checked at their source. +Its content is generated partly Kubernetes' own schema documentation and partly doc comments owned by `operator-rs` or by the operator's own `crd` module, the latter is already checked independently. The same applies to files rendered from `template/`: a typo in `template/.readme/partials/borrowed/footer.md.j2.j2` is caught here, once, instead of in all sixteen repositories. -> [!NOTE] -> Excluding rendered content more thoroughly — everything a repository receives from `operator-templating` or `operator-rs` — is a known refinement that has not been done yet. -> The generated CRDs are the case that mattered in practice. - ### Conventions - The hook runs report-only. `args: ["--force-exclude"]`. - Every entry in a `typos.toml` gets a one-line comment saying what the word is. -- Prefer an in-place marker over a config entry when the word is correct at one site and would still be a typo elsewhere: `spellchecker:disable-line` at the end of the line, `spellchecker:ignore-next-line` on the line above, or `spellchecker:off` / `:on` around a block. -- Licence and other verbatim third-party files are excluded, never corrected. +- Prefer an in-place marker over a config entry when the word is correct at one site and would still be a typo elsewhere ## Making changes to the template diff --git a/typos.toml b/typos.toml index 10408d1c..99d85692 100644 --- a/typos.toml +++ b/typos.toml @@ -1,14 +1,6 @@ # Configuration for typos (https://github.com/crate-ci/typos), run via the prek # hook in .pre-commit-config.yaml. # -# This config covers operator-templating itself. The operator repositories each -# carry their own typos.toml, which is NOT rolled out from template. -# typos has no layered configuration (https://github.com/crate-ci/typos/issues/193), -# templated config could not be extended with repo-specific words, and adding one word to -# one operator would otherwise mean a PR here plus a sync to all repositories. -# -# Only the hook is shared, via template/.pre-commit-config.yaml.j2. -# # Before adding an entry here, consider an in-place marker instead. Use one when # the word is correct at this one site and would still be a typo elsewhere: # @@ -19,10 +11,8 @@ # Every entry below gets a one-line comment saying what the word is. [files] -# Bare `typos` skips hidden directories, but prek passes explicit paths and so -# does check them. Turn it off so both agree -- without this, template/.readme/ -# and template/.github/ are invisible to a local run but not to the hook. - +# Bare `typos` skips hidden dirs by default, but prek passes explicit paths and +# so does check them. Turn it off so both agree. ignore-hidden = false extend-exclude = [ @@ -33,11 +23,12 @@ extend-exclude = [ [default] # typos has no native suppression directive # (https://github.com/crate-ci/typos/issues/316), so these regexes provide one. -# They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` comments. +# They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` comments, +# which spans every file type in this repo. # -# Both failure modes are safe: an unterminated `:off` suppresses nothing rather -# than swallowing the rest of the file, and `disable-line` only matches when the -# marker ends the line, so trailing text defeats it instead of widening it. +# Both failure modes are safe: +# * unterminated `:off` suppresses nothing rather than swallowing the rest of the file. +# * `disable-line` only matches when the marker ends the line. extend-ignore-re = [ "(?Rm)^.*(#|//||#\\}|\\*/)?\\s*$", "(#|//||#\\}|\\*/)?\\s*\\n.*", @@ -45,7 +36,6 @@ extend-ignore-re = [ ] [default.extend-words] -# Azure Kubernetes Service. Appears in the README footer partial that is -# rendered into every operator repository. A single lowercase entry covers -# every casing, so no separate `AKS` entry is needed. +# Azure Kubernetes Service. Appears in README footer and as the runner platform `aks-1.36` in tests/interu.yaml. +# A single lowercase entry covers every casing, so no separate `AKS` entry is needed. aks = "aks" From 8dc60631f05efeffb5fbde99b76a31a75165b451 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Thu, 1 Oct 2026 10:20:35 +0200 Subject: [PATCH 09/10] whitespace check --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index e6acf026..a5ae7c08 100644 --- a/README.md +++ b/README.md @@ -72,7 +72,7 @@ The hook is templated in `template/.pre-commit-config.yaml.j2`. The word lists are **not** templated: each repository has its own `typos.toml`. That split is forced by the tool. typos has no layered configuration yet ([crate-ci/typos#193](https://github.com/crate-ci/typos/issues/193)). -Keeping the word lists local also means adding a word is a PR per repository instead of a templating run. +Keeping the word lists local also means adding a word is a PR per repository instead of a templating run. ### The core config From 9ae086c194770bd591bdd6c4539b3b038988d832 Mon Sep 17 00:00:00 2001 From: Maxi Wittich Date: Fri, 2 Oct 2026 16:20:00 +0200 Subject: [PATCH 10/10] Applying review, change regex, more condensed README --- .pre-commit-config.yaml | 8 +++--- README.md | 42 +++++++++-------------------- template/.pre-commit-config.yaml.j2 | 8 +++--- typos.toml | 24 +++++++---------- 4 files changed, 31 insertions(+), 51 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 7f3ab16e..0837ede9 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -9,10 +9,10 @@ repos: rev: 00f422f3b19c57bc6338715ebfe3316d38768461 # v1.50.3 hooks: - id: typos - # Drop the upstream default `--write-changes` so the hook reports and - # fails instead of rewriting files. - # Keep `--force-exclude` so the - # excludes in typos.toml still apply to the paths prek passes in. + # Drop the upstream default `--write-changes` so the hook only + # reports failures instead of writing changes. + # Keep `--force-exclude` so the excludes in typos.toml still + # apply to the paths prek passes in. args: ["--force-exclude"] - repo: https://github.com/pre-commit/pre-commit-hooks diff --git a/README.md b/README.md index a5ae7c08..af5297a6 100644 --- a/README.md +++ b/README.md @@ -69,14 +69,13 @@ Additional settings can be found in `playbook/group_vars/all`, but these are not Every managed repository runs [typos](https://github.com/crate-ci/typos) as a prek hook. The hook is templated in `template/.pre-commit-config.yaml.j2`. -The word lists are **not** templated: each repository has its own `typos.toml`. - -That split is forced by the tool. typos has no layered configuration yet ([crate-ci/typos#193](https://github.com/crate-ci/typos/issues/193)). +The word lists are **not** templated: each repository has its own `typos.toml`, because typos has no layered configuration yet ([crate-ci/typos#193](https://github.com/crate-ci/typos/issues/193)). Keeping the word lists local also means adding a word is a PR per repository instead of a templating run. +Files rendered from `template/` are checked in this repository once. ### The core config -As convention, new repositories should start from this block and add only what they actually need. +As a convention, new repositories should start from this block and add only what they actually need. ```toml # Configuration for typos (https://github.com/crate-ci/typos), run via the prek @@ -85,9 +84,9 @@ As convention, new repositories should start from this block and add only what t # Before adding an entry here, consider an in-place marker instead. Use one when # the word is correct at this one site and would still be a typo elsewhere: # -# # spellchecker:disable-line at the end of the line it applies to -# # spellchecker:ignore-next-line on its own line, above the offending line -# # spellchecker:off / :on around a block +# # typos:ignore-line at the end of the line it applies to +# # typos:ignore-next-line on its own line, above the offending line +# # typos:off / typos:on around a block # # Every entry below gets a one-line comment saying what the word is. @@ -111,37 +110,22 @@ extend-exclude = [ [default] # typos has no native suppression directive # (https://github.com/crate-ci/typos/issues/316), so these regexes provide one. -# They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` comments, -# which spans every file type in this repo. -# -# Both failure modes are safe: -# * unterminated `:off` suppresses nothing rather than swallowing the rest of the file. -# * `disable-line` only matches when the marker ends the line. +# A marker must sit in a comment: after `#`, `//` or `;` (free text may follow), +# or inside a closed ``, `/* */` or `{# #}` (free text may precede the +# closer). An unterminated `typos:off` suppresses nothing. extend-ignore-re = [ - "(?Rm)^.*(#|//||#\\}|\\*/)?\\s*$", - "(#|//||#\\}|\\*/)?\\s*\\n.*", - "(?s)(#|//||#\\}|\\*/|\")?.*?(#|//||#\\}|\\*/|\")?", + '(?Rm)^.*?(?:(?:^|[^{])(?:#|//|;)[ \t]*typos:ignore-line\b.*|(?:|/\*[ \t]*typos:ignore-line\b.*?\*/|\{#[ \t]*typos:ignore-line\b.*?#\})[ \t]*)$', + '(?Rm)^[ \t]*(?:(?:#|//|;)[ \t]*typos:ignore-next-line\b.*|(?:|/\*[ \t]*typos:ignore-next-line\b.*?\*/|\{#[ \t]*typos:ignore-next-line\b.*?#\})[ \t]*)\r?\n.*$', + '(?ms)(?:(?:^|[^{])(?:#|//|;)[ \t]*typos:off\b||/\*[ \t]*typos:off\b[^\n]*?\*/|\{#[ \t]*typos:off\b[^\n]*?#\}).*?(?:(?:^|[^{])(?:#|//|;)[ \t]*typos:on\b||/\*[ \t]*typos:on\b[^\n]*?\*/|\{#[ \t]*typos:on\b[^\n]*?#\})', ] [default.extend-words] -# Azure Kubernetes Service. Appears in README footer and as the runner platform `aks-1.36` in tests/interu.yaml. -# A single lowercase entry covers every casing, so no separate `AKS` entry is needed. +# Azure Kubernetes Service aks = "aks" ``` -`aks` is the only word that is universal. -Everything else measured across the operator repositories turned out to be repo-local: `aas` in opa-operator, `shs` in spark-k8s-operator, base64 fixtures in secret-operator. -Short tokens that appear in several repositories (`ot`, `fo`) do so for unrelated reasons and belong in the repository that has them, not here. - -### Check each string once - -`extra/crds.yaml` is excluded on purpose. -Its content is generated partly Kubernetes' own schema documentation and partly doc comments owned by `operator-rs` or by the operator's own `crd` module, the latter is already checked independently. -The same applies to files rendered from `template/`: a typo in `template/.readme/partials/borrowed/footer.md.j2.j2` is caught here, once, instead of in all sixteen repositories. - ### Conventions -- The hook runs report-only. `args: ["--force-exclude"]`. - Every entry in a `typos.toml` gets a one-line comment saying what the word is. - Prefer an in-place marker over a config entry when the word is correct at one site and would still be a typo elsewhere diff --git a/template/.pre-commit-config.yaml.j2 b/template/.pre-commit-config.yaml.j2 index c931d9af..9f0db8ce 100644 --- a/template/.pre-commit-config.yaml.j2 +++ b/template/.pre-commit-config.yaml.j2 @@ -14,10 +14,10 @@ repos: rev: 00f422f3b19c57bc6338715ebfe3316d38768461 # v1.50.3 hooks: - id: typos - # Drop the upstream default `--write-changes` so the hook reports and - # fails instead of rewriting files. - # Keep `--force-exclude` so the - # excludes in typos.toml still apply to the paths prek passes in. + # Drop the upstream default `--write-changes` so the hook only + # reports failures instead of writing changes. + # Keep `--force-exclude` so the excludes in typos.toml still + # apply to the paths prek passes in. args: ["--force-exclude"] - repo: https://github.com/pre-commit/pre-commit-hooks diff --git a/typos.toml b/typos.toml index 99d85692..80c0516e 100644 --- a/typos.toml +++ b/typos.toml @@ -4,9 +4,9 @@ # Before adding an entry here, consider an in-place marker instead. Use one when # the word is correct at this one site and would still be a typo elsewhere: # -# # spellchecker:disable-line at the end of the line it applies to -# # spellchecker:ignore-next-line on its own line, above the offending line -# # spellchecker:off / :on around a block +# # typos:ignore-line at the end of the line it applies to +# # typos:ignore-next-line on its own line, above the offending line +# # typos:off / typos:on around a block # # Every entry below gets a one-line comment saying what the word is. @@ -23,19 +23,15 @@ extend-exclude = [ [default] # typos has no native suppression directive # (https://github.com/crate-ci/typos/issues/316), so these regexes provide one. -# They cover `#`, `//`, ``, `;`, `/* */` and Jinja `{# #}` comments, -# which spans every file type in this repo. -# -# Both failure modes are safe: -# * unterminated `:off` suppresses nothing rather than swallowing the rest of the file. -# * `disable-line` only matches when the marker ends the line. +# A marker must sit in a comment: after `#`, `//` or `;` (free text may follow), +# or inside a closed ``, `/* */` or `{# #}` (free text may precede the +# closer). An unterminated `typos:off` suppresses nothing. extend-ignore-re = [ - "(?Rm)^.*(#|//||#\\}|\\*/)?\\s*$", - "(#|//||#\\}|\\*/)?\\s*\\n.*", - "(?s)(#|//||#\\}|\\*/|\")?.*?(#|//||#\\}|\\*/|\")?", + '(?Rm)^.*?(?:(?:^|[^{])(?:#|//|;)[ \t]*typos:ignore-line\b.*|(?:|/\*[ \t]*typos:ignore-line\b.*?\*/|\{#[ \t]*typos:ignore-line\b.*?#\})[ \t]*)$', + '(?Rm)^[ \t]*(?:(?:#|//|;)[ \t]*typos:ignore-next-line\b.*|(?:|/\*[ \t]*typos:ignore-next-line\b.*?\*/|\{#[ \t]*typos:ignore-next-line\b.*?#\})[ \t]*)\r?\n.*$', + '(?ms)(?:(?:^|[^{])(?:#|//|;)[ \t]*typos:off\b||/\*[ \t]*typos:off\b[^\n]*?\*/|\{#[ \t]*typos:off\b[^\n]*?#\}).*?(?:(?:^|[^{])(?:#|//|;)[ \t]*typos:on\b||/\*[ \t]*typos:on\b[^\n]*?\*/|\{#[ \t]*typos:on\b[^\n]*?#\})', ] [default.extend-words] -# Azure Kubernetes Service. Appears in README footer and as the runner platform `aks-1.36` in tests/interu.yaml. -# A single lowercase entry covers every casing, so no separate `AKS` entry is needed. +# Azure Kubernetes Service aks = "aks"