Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bumped jenkins version and ci permissions #636

Merged
merged 1 commit into from
Dec 12, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-ansible-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-ansible/**
- .github/workflows/jenkins-agent-ansible-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-arachni-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-arachni/**
- .github/workflows/jenkins-agent-arachni-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-argocd-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-argocd/**
- .github/workflows/jenkins-agent-argocd-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-ci-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@ on:
paths:
- _test/kind/**
- .github/workflows/jenkins-agent-ci-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-conftest-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-conftest/**
- .github/workflows/jenkins-agent-conftest-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-cosign-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-cosign/**
- .github/workflows/jenkins-agent-cosign-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-erlang-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-erlang/**
- .github/workflows/jenkins-agent-erlang-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-golang-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-golang/**
- .github/workflows/jenkins-agent-golang-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-graalvm-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-graalvm/**
- .github/workflows/jenkins-agent-graalvm-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-gradle-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-gradle/**
- .github/workflows/jenkins-agent-gradle-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-helm-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-helm/**
- .github/workflows/jenkins-agent-helm-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-hugo-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-hugo/**
- .github/workflows/jenkins-agent-hugo-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-image-mgmt-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-image-mgmt/**
- .github/workflows/jenkins-agent-image-mgmt-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/jenkins-agent-image-mgmt-publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,19 @@ on:
paths:
- jenkins-agents/jenkins-agent-image-mgmt/version.json
- .github/workflows/jenkins-agent-image-mgmt-publish.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
context: jenkins-agents/jenkins-agent-image-mgmt
image_name: jenkins-agent-image-mgmt
REGISTRY: ${{ secrets.REGISTRY_URI }}
runs-on: ubuntu-latest
permissions:
packages: write
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4

Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-mongodb-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-mongodb/**
- .github/workflows/jenkins-agent-mongodb-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-mvn-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-mvn/**
- .github/workflows/jenkins-agent-mvn-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-npm-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-npm/**
- .github/workflows/jenkins-agent-npm-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-python-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-python/**
- .github/workflows/jenkins-agent-python-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/jenkins-agent-python-publish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,19 @@ on:
paths:
- jenkins-agents/jenkins-agent-python/version.json
- .github/workflows/jenkins-agent-python-publish.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
context: jenkins-agents/jenkins-agent-python
image_name: jenkins-agent-python
REGISTRY: ${{ secrets.REGISTRY_URI }}
runs-on: ubuntu-latest
permissions:
packages: write
steps:
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4

Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-ruby-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-ruby/**
- .github/workflows/jenkins-agent-ruby-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-rust-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-rust/**
- .github/workflows/jenkins-agent-rust-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/jenkins-agent-zap-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ on:
paths:
- jenkins-agents/jenkins-agent-zap/**
- .github/workflows/jenkins-agent-zap-pr.yaml

# Declare default permissions as read only.
permissions: read-all

jobs:
build:
env:
Expand Down
25 changes: 23 additions & 2 deletions _test/kind/setup.sh
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
set -euo pipefail

AGENT=$1
JENKINS_CHART_VERSION=${2:-3.11.10}
JENKINS_CHART_VERSION="4.9.1"
AGENT_PATH="jenkins-agents/${AGENT}"
SCRIPT_DIR=$(dirname -- "$(readlink -f "${BASH_SOURCE[0]}" || realpath "${BASH_SOURCE[0]}")")

Expand Down Expand Up @@ -61,6 +61,7 @@ then
then
kind create cluster --config ${SCRIPT_DIR}/kind-config.yaml
fi

podman save ${AGENT}:latest | docker load
docker tag localhost/${AGENT}:latest ${AGENT}:latest
kind load docker-image ${AGENT}:latest
Expand All @@ -71,21 +72,38 @@ then
--for=condition=ready pod \
--selector=app.kubernetes.io/component=controller \
--timeout=90s

# Would like to find a cleaner approach to configure the podTemplate and Jenkins job below
TPL_TEMP=$(mktemp -d)
JENKINS_AGENT="${AGENT}" envsubst < ${SCRIPT_DIR}/jenkins-podtemplate.yaml > ${TPL_TEMP}/podtemplate.yaml
JENKINS_AGENT="${AGENT}" JENKINSFILE=$(sed '2,$s/^/ /' ${AGENT_PATH}/Jenkinsfile.test) envsubst < ${SCRIPT_DIR}/jenkins-casc-config-scripts-template.yaml > ${TPL_TEMP}/jenkins-casc-config-scripts.yaml

# Use Helm to deploy and configure Jenkins
helm repo add jenkinsci https://charts.jenkins.io --force-update
helm repo update
echo "### Jenkins content will look like... ###"
helm template jenkins \
--version ${JENKINS_CHART_VERSION} \
-n jenkins --create-namespace \
-f ${SCRIPT_DIR}/jenkins-values.yaml \
-f ${TPL_TEMP}/podtemplate.yaml \
-f ${TPL_TEMP}/jenkins-casc-config-scripts.yaml \
jenkinsci/jenkins

echo "### Jenkins install ###"
helm install jenkins \
--version ${JENKINS_CHART_VERSION} \
-n jenkins --create-namespace \
-f ${SCRIPT_DIR}/jenkins-values.yaml \
-f ${TPL_TEMP}/podtemplate.yaml \
-f ${TPL_TEMP}/jenkins-casc-config-scripts.yaml \
jenkinsci/jenkins
# Make sure Jenkins is available

kubectl get statefulsets -n jenkins
kubectl describe statefulsets/jenkins -n jenkins
kubectl rollout status statefulsets/jenkins --watch=true --timeout=5m -n jenkins

# Make sure Jenkins is available
echo "### Wait for Jenkins instance to become ready ###"
do_until "http://localhost/login" "" 200 300 "Timed out waiting for Jenkins to become ready..."

Expand All @@ -97,6 +115,7 @@ then
echo "Failed to create Jenkins Crumb, exiting..."
exit 2
fi

token=$(curl -s http://localhost/me/descriptorByName/jenkins.security.ApiTokenProperty/generateNewToken --data 'newTokenName=foo' --user admin:${secret} -H "Jenkins-Crumb: ${crumb}" --cookie /tmp/cookies | jq -r '.data.tokenValue')
if [ -z ${token} ]
then
Expand Down Expand Up @@ -127,7 +146,9 @@ then
sleep 2
let "timeout += 2"
done

get_build_logs

JOB_STATUS=$(curl -s http://localhost/job/containers-quickstarts/job/${AGENT}/lastBuild/api/json --user admin:${token} | jq -r '.result')
kind delete cluster --name kind
if [[ ${JOB_STATUS} != "SUCCESS" ]]
Expand Down
Loading