Skip to content
Snippets Groups Projects
Jenkinsfile 18.2 KiB
Newer Older
  • Learn to ignore specific revisions
  • /*
     * Copyright (C) 2023 Das Land Schleswig-Holstein vertreten durch den
     * Ministerpräsidenten des Landes Schleswig-Holstein
     * Staatskanzlei
     * Abteilung Digitalisierung und zentrales IT-Management der Landesregierung
     *
     * Lizenziert unter der EUPL, Version 1.2 oder - sobald
     * diese von der Europäischen Kommission genehmigt wurden -
     * Folgeversionen der EUPL ("Lizenz");
     * Sie dürfen dieses Werk ausschließlich gemäß
     * dieser Lizenz nutzen.
     * Eine Kopie der Lizenz finden Sie hier:
     *
     * https://joinup.ec.europa.eu/collection/eupl/eupl-text-eupl-12
     *
     * Sofern nicht durch anwendbare Rechtsvorschriften
     * gefordert oder in schriftlicher Form vereinbart, wird
     * die unter der Lizenz verbreitete Software "so wie sie
     * ist", OHNE JEGLICHE GEWÄHRLEISTUNG ODER BEDINGUNGEN -
     * ausdrücklich oder stillschweigend - verbreitet.
     * Die sprachspezifischen Genehmigungen und Beschränkungen
     * unter der Lizenz sind dem Lizenztext zu entnehmen.
     */
    
    OZGCloud's avatar
    OZGCloud committed
    pipeline {
    
    OZGCloud's avatar
    OZGCloud committed
        agent {
            node {
    
                label 'ozgcloud-jenkins-build-agent-jdk21-node20'
    
    OZGCloud's avatar
    OZGCloud committed
            }
    
    OZGCloud's avatar
    OZGCloud committed
        }
    
    
        environment {
    
            BLUE_OCEAN_URL = "https://jenkins.infra.ozg-cloud.systems/job/alfa/job/${env.BRANCH_NAME}/${env.BUILD_NUMBER}/"
    
            RELEASE_REGEX = /\d+.\d+.\d+/
            SNAPSHOT_REGEX = /\d+.\d+.\d+-SNAPSHOT/
    
    OZGCloud's avatar
    OZGCloud committed
            FAILED_STAGE = ""
    
    OZGCloud's avatar
    OZGCloud committed
            SH_SUCCESS_STATUS_CODE = 0
    
    OZGCloud's avatar
    OZGCloud committed
        options {
            timeout(time: 1, unit: 'HOURS')
            disableConcurrentBuilds()
    
    OZGCloud's avatar
    OZGCloud committed
            buildDiscarder(logRotator(numToKeepStr: '5'))
    
    OZGCloud's avatar
    OZGCloud committed
        }
    
        stages {
    
    OZGCloud's avatar
    OZGCloud committed
            stage('Check Version') {
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
    
    OZGCloud's avatar
    OZGCloud committed
                        VERSION = getRootPomVersion()
    
                        def serverVersion = getParentPomVersion('alfa-server/pom.xml')
                        def clientVersion = getParentPomVersion('alfa-client/pom.xml')
    
    OZGCloud's avatar
    OZGCloud committed
    
    
    OZGCloud's avatar
    OZGCloud committed
                        if(isReleaseBranch()){
    
    OZGCloud's avatar
    OZGCloud committed
                            if ( !isReleaseVersion([VERSION, serverVersion, clientVersion]) ) {
    
    OZGCloud's avatar
    OZGCloud committed
                                error("Keine Release Version für Branch ${env.BRANCH_NAME}.")
                            }
                        } else {
    
    OZGCloud's avatar
    OZGCloud committed
                            if ( !isSnapshotVersion([VERSION, serverVersion, clientVersion]) ) {
    
    OZGCloud's avatar
    OZGCloud committed
                                error("Keine Snapshot Version für Branch ${env.BRANCH_NAME}.")
                            }
                        }
    
    OZGCloud's avatar
    OZGCloud committed
                        if( !isSameVersion([serverVersion, clientVersion], VERSION) ){
    
                            error("Versionen sind nicht identisch")
    
    OZGCloud's avatar
    OZGCloud committed
            stage('Client') {
    
                environment {
                    FORCE_COLOR = 'false'
                }
    
    OZGCloud's avatar
    OZGCloud committed
                steps {
    
    OZGCloud's avatar
    OZGCloud committed
                    script {
                        FAILED_STAGE=env.STAGE_NAME
    
    OZGCloud's avatar
    OZGCloud committed
    
    
    OZGCloud's avatar
    OZGCloud committed
                        withNPM(npmrcConfig: 'npm-nexus-auth') {
                            sh 'npm --version'
                            sh 'node --version'
    
    OZGCloud's avatar
    OZGCloud committed
    
    
    OZGCloud's avatar
    OZGCloud committed
                            dir('alfa-client') {
                                sh 'npm cache verify'
                                sh 'npm install'
    
    OZGCloud's avatar
    OZGCloud committed
                                if (isMasterBranch()) {
                                    withSonarQubeEnv('sonarqube-ozg-sh'){
                                        sh 'npm run ci-sonar'
                                }
                                } else {
                                    sh 'npm run ci-test'
                                }
                                if (isReleaseBranch()) {
                                    sh 'npm run ci-prodBuild'
                                }
                                else {
                                    sh 'npm run ci-build'
    
                // post {
                //     always{
                //         junit testResults: 'alfa-client/test-report.xml', skipPublishingChecks: true
                //     }
                // }
    
    OZGCloud's avatar
    OZGCloud committed
            }
    
            stage('Build and push client container') {
                steps {
                    script {
                        catchError(buildResult: 'SUCCESS', stageResult: 'FAILURE') {
                            dir('alfa-client') {
                                IMAGE_TAG = generateImageTag()
    
    
    OZGCloud's avatar
    OZGCloud committed
                                withNPM(npmrcConfig: 'npm-nexus-auth') {
                                    sh 'npm run ci-build-alfa-client-container'
                                }
    
    OZGCloud's avatar
    OZGCloud committed
                                withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
                                    sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'
    
                                    sh "docker tag docker.ozg-sh.de/alfa-client:build-latest docker.ozg-sh.de/alfa-client:${IMAGE_TAG}"
                                    sh "docker push docker.ozg-sh.de/alfa-client:${IMAGE_TAG}"
                                }
    
            stage('Set Version') {
              when {
                not {
                    anyOf {
                        branch 'master'
                        branch 'release'
                    }
                }
              }
              steps {
                    script {
                        FAILED_STAGE=env.STAGE_NAME
    
                        JAR_TAG = getRootPomVersion().replace("SNAPSHOT", "${env.BRANCH_NAME}-SNAPSHOT")
    
                    }
                    configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                        sh "mvn -s $MAVEN_SETTINGS versions:set -DnewVersion=${JAR_TAG} -DprocessAllModules=true"
                        
                    }
              }
            }
    
    
    OZGCloud's avatar
    OZGCloud committed
            stage('Build Server artefacts, build and push docker image') {
    
    OZGCloud's avatar
    OZGCloud committed
                steps {
                    script {
                        FAILED_STAGE=env.STAGE_NAME
    
                        IMAGE_TAG = generateImageTag()
    
    OZGCloud's avatar
    OZGCloud committed
    
    
    OZGCloud's avatar
    OZGCloud committed
                        configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                            sh 'mvn --version'
    
                            sh "mvn --no-transfer-progress -s $MAVEN_SETTINGS -pl -alfa-client clean install spring-boot:build-image -Dspring-boot.build-image.imageName=docker.ozg-sh.de/alfa:${IMAGE_TAG} -Dspring-boot.build-image.publish -Dmaven.wagon.http.retryHandler.count=3"
    
     						if (isMasterBranch()) {
    	                   		try {
    	    	                    dir('alfa-service'){
    	                                withSonarQubeEnv('sonarqube-ozg-sh'){
    
    	                                    sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS sonar:sonar'
    
    	                                }
    	                            }
    	                        }
    	                        catch (Exception e) {
    	                            unstable("SonarQube failed")
    	                        }
    	                    }
    
                post {
                    always{
                        junit testResults: '**/target/surefire-reports/*.xml', skipPublishingChecks: true
                    }
                }
    
    OZGCloud's avatar
    OZGCloud committed
            }
            stage('Deploy Maven Artifacts to Nexus') {
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
                    }
    
    OZGCloud's avatar
    OZGCloud committed
    
                    configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
    
                        sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS -pl -alfa-client -DskipTests deploy'
    
                        sh "mvn -s $MAVEN_SETTINGS versions:revert"
    
            stage('Tag and Push Docker Image') {
    
    OZGCloud's avatar
    OZGCloud committed
                when {
                    anyOf {
                        branch 'master'
                        branch 'release'
                    }
                }
    
    OZGCloud's avatar
    OZGCloud committed
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
    
    
    OZGCloud's avatar
    OZGCloud committed
                        if (isMasterBranch()) {
    
                            tagAndPushDockerImage('snapshot-latest')
    
    OZGCloud's avatar
    OZGCloud committed
                        }
    
    OZGCloud's avatar
    OZGCloud committed
                        else if (isReleaseBranch()) {
    
                            tagAndPushDockerImage('latest')
    
            stage('Test, build and deploy Alfa Helm Chart') {
    
    OZGCloud's avatar
    OZGCloud committed
                    script {
    
                        FAILED_STAGE=env.STAGE_NAME
    
    OZGCloud's avatar
    OZGCloud committed
                        HELM_CHART_VERSION = generateHelmChartVersion()
    
                        sh "./run_helm_test.sh"
    
                        dir('src/main/helm') {
    
    OZGCloud's avatar
    OZGCloud committed
                            sh "helm package --version=${HELM_CHART_VERSION} ."
    
                            deployHelmChart(HELM_CHART_VERSION, "alfa")
                        }
                    }
                }
            }
    
            stage('Test, build and deploy Alfa-Client Helm Chart') {
                steps {
                    script {
                        dir('alfa-client') {
                            FAILED_STAGE=env.STAGE_NAME
                            HELM_CHART_VERSION = generateHelmChartVersion()
    
                            sh "./run_helm_test.sh"
    
                            dir('src/main/helm') {
    
                                sh "helm package --version=${HELM_CHART_VERSION} ."
    
                                deployHelmChart(HELM_CHART_VERSION, "alfa-client")
                            }
    
    OZGCloud's avatar
    OZGCloud committed
                        }
    
            stage('Trigger Dev rollout') {
    
    OZGCloud's avatar
    OZGCloud committed
                when {
    
    OZGCloud's avatar
    OZGCloud committed
                }
                steps {
                    script {
    
    OZGCloud's avatar
    OZGCloud committed
                        FAILED_STAGE = env.STAGE_NAME
    
    OZGCloud's avatar
    OZGCloud committed
                        cloneGitopsRepo()
    
                        setNewDevVersion()
    
    OZGCloud's avatar
    OZGCloud committed
                        pushGitopsRepo()
    
            stage('Trigger Test rollout') {
    
                when {
                    branch 'release'
                }
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
    
    
    OZGCloud's avatar
    OZGCloud committed
                        cloneGitopsRepo()
    
                        setNewTestVersion()
    
    OZGCloud's avatar
    OZGCloud committed
                        pushGitopsRepo()
    
            stage ('Deploy SBOM to DependencyTrack') {
    
    OZGCloud's avatar
    OZGCloud committed
                steps {
    
    OZGCloud's avatar
    OZGCloud committed
                    script {
                        IMAGE_TAG = generateImageTag()
    
    OZGCloud's avatar
    OZGCloud committed
                        configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                            withCredentials([string(credentialsId: 'dependency-track-api-key', variable: 'API_KEY')]) {
    
                                dir('alfa-server') {
                                    catchError(buildResult: 'UNSTABLE', stageResult: 'FAILURE') {
                                        sh "mvn  --no-transfer-progress -s $MAVEN_SETTINGS io.github.pmckeown:dependency-track-maven-plugin:upload-bom -Ddependency-track.apiKey=$API_KEY -Ddependency-track.projectVersion=${IMAGE_TAG} -Ddependency-track.dependencyTrackBaseUrl=https://dependency-track.ozg-sh.de"
                                    }
    
    OZGCloud's avatar
    OZGCloud committed
                        }
    
            stage ('Trigger Barrierefreiheit Rollout') {
    
                   branch 'barrierefreiheit-dev'
    
                }
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
    
                        cloneGitopsRepo()
    
                        setNewBarrierefreiheitVersion()
    
                        pushGitopsRepo()
    
                    }
                }
            }
    
    
    OZGCloud's avatar
    OZGCloud committed
        }
        post {
            failure {
                script {
    
    OZGCloud's avatar
    OZGCloud committed
                    if (isMasterBranch() || isReleaseBranch()) {
    
                        sendFailureMessage()
    
    OZGCloud's avatar
    OZGCloud committed
        }
    }
    
    OZGCloud's avatar
    OZGCloud committed
    
    
    Void deployHelmChart(String helmChartVersion, String app ) {
    
        withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USERNAME', passwordVariable: 'PASSWORD')]){
    
    OZGCloud's avatar
    OZGCloud committed
            if (isReleaseBranch()) {
    
                result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps -F file=@'''+app+'''-'''+helmChartVersion+'''.tgz''', returnStdout: true
    
                result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps-snapshot -F file=@'''+app+'''-'''+helmChartVersion+'''.tgz''', returnStdout: true
    
    OZGCloud's avatar
    OZGCloud committed
    String generateHelmChartVersion() {
        def chartVersion = "${VERSION}"
    
    OZGCloud's avatar
    OZGCloud committed
        if (isMasterBranch()) {
    
            chartVersion += getCommitHash()
        }
        else if (isBarrierefreiheitBranch()) {
            chartVersion += "-barrierefreiheit${getCommitHash()}"
    
    OZGCloud's avatar
    OZGCloud committed
        }
    
    OZGCloud's avatar
    OZGCloud committed
        else if (!isReleaseBranch()) {
    
    OZGCloud's avatar
    OZGCloud committed
            chartVersion += "-${env.BRANCH_NAME}"
        }
    
        return chartVersion.replaceAll("_", "-")
    
    Void tagAndPushDockerImage(String newTag){
    
    OZGCloud's avatar
    OZGCloud committed
        withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
    
    OZGCloud's avatar
    OZGCloud committed
            sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'
    
            sh "docker tag docker.ozg-sh.de/alfa:${IMAGE_TAG} docker.ozg-sh.de/alfa:${newTag}"
            sh "docker push docker.ozg-sh.de/alfa:${newTag}"
    
        }
    }
    
    String generateImageTag() {
        def imageTag = "${env.BRANCH_NAME}-${VERSION}"
    
    
        if (isMasterBranch() || isBarrierefreiheitBranch()) {
            imageTag += getCommitHash()
    
    OZGCloud's avatar
    OZGCloud committed
    Void cloneGitopsRepo() {
    
        withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
    
            sh 'git clone https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
    
    OZGCloud's avatar
    OZGCloud committed
        configureGit()
    
    OZGCloud's avatar
    OZGCloud committed
    Void pushGitopsRepo() {
    
        withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
    
    OZGCloud's avatar
    OZGCloud committed
            dir("gitops") {
    
    OZGCloud's avatar
    OZGCloud committed
                if (hasUnpushedCommits()) {
    
                    sh 'git push https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
    
    OZGCloud's avatar
    OZGCloud committed
                }
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean hasUnpushedCommits() {
    
    OZGCloud's avatar
    OZGCloud committed
        return sh (script: "git cherry -v | grep .", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
    
    OZGCloud's avatar
    OZGCloud committed
    Void configureGit() {
    
    OZGCloud's avatar
    OZGCloud committed
        final email = "jenkins@ozg-sh.de"
        final name = "jenkins"
    
    
    OZGCloud's avatar
    OZGCloud committed
        dir("gitops") {
    
    OZGCloud's avatar
    OZGCloud committed
            sh "git config user.email '${email}'"
            sh "git config user.name '${name}'"
    
    Void sendFailureMessage() {
        def room = ''
        def data = """{"msgtype":"m.text", \
    
                        "body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER} Link: ${BLUE_OCEAN_URL}", \
    
                        "format": "org.matrix.custom.html", \
    
                        "formatted_body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: <a href='${BLUE_OCEAN_URL}'>${env.BUILD_NUMBER}</a>"}"""
    
    OZGCloud's avatar
    OZGCloud committed
        if (isMasterBranch()) {
    
            room = "!iQPAvQIiRwRpNOszjw:matrix.ozg-sh.de"
        }
    
    OZGCloud's avatar
    OZGCloud committed
        else if (isReleaseBranch()) {
    
            room = "!oWZpUGTFsxkJIYNfYg:matrix.ozg-sh.de"
        }
    
        sh "curl -XPOST -H 'authorization: Bearer ${getElementAccessToken()}' -d '${data}' https://matrix.ozg-sh.de/_matrix/client/v3/rooms/$room/send/m.room.message"
    }
    
    String getElementAccessToken() {
        withCredentials([string(credentialsId: 'element-login-json', variable: 'LOGIN_JSON')]) {
            return readJSON ( text: sh (script: '''curl -XPOST -d \"$LOGIN_JSON\" https://matrix.ozg-sh.de/_matrix/client/v3/login''', returnStdout: true)).access_token
        }
    
    Void setNewDevVersion() {
        setNewGitopsVersion("dev")
    
    Void setNewTestVersion() {
        setNewGitopsVersion("test")
    
    Void setNewGitopsVersion(String environment) {
    
        def envFile = "${environment}/application/values/alfa-values.yaml"
        def commitMessage = "jenkins rollout ${environment} alfa version ${IMAGE_TAG}";
    
    OZGCloud's avatar
    OZGCloud committed
        setNewAlfaGitopsVersion(envFile, commitMessage);
    
        envFile = "${environment}/application/values/alfa-client-values.yaml"
        commitMessage = "jenkins rollout ${environment} alfa-client version ${IMAGE_TAG}";
    
    OZGCloud's avatar
    OZGCloud committed
        setNewAlfaClientGitopsVersion(envFile, commitMessage);
    
    Void setNewBarrierefreiheitVersion() {
        def envFile = "dev/namespace/namespaces/by-barrierefreiheit-dev.yaml"
        def commitMessage = "jenkins rollout ${IMAGE_TAG} for Barrierefreiheit Dev"
    
    OZGCloud's avatar
    OZGCloud committed
        setNewAlfaGitopsVersion(envFile, commitMessage);
    
    OZGCloud's avatar
    OZGCloud committed
    Void setNewAlfaGitopsVersion(String envFile, String commitMessage) {
    
    OZGCloud's avatar
    OZGCloud committed
            def envVersions = readYaml file: envFile
    
    
            envVersions.alfa.image.tag = IMAGE_TAG
            envVersions.alfa.helm.version = HELM_CHART_VERSION
    
    OZGCloud's avatar
    OZGCloud committed
    
            writeYaml file: envFile, data: envVersions, overwrite: true
    
    
    OZGCloud's avatar
    OZGCloud committed
                sh "git add ${envFile}"
    
                sh "git commit -m '${commitMessage}'"
    
    OZGCloud's avatar
    OZGCloud committed
            }
    
    OZGCloud's avatar
    OZGCloud committed
        }
    
    OZGCloud's avatar
    OZGCloud committed
    Void setNewAlfaClientGitopsVersion(String envFile, String commitMessage) {
        dir("gitops") {
            def envVersions = readYaml file: envFile
    
            envVersions.alfa_client.image.tag = IMAGE_TAG
            envVersions.alfa_client.helm.version = HELM_CHART_VERSION
    
            writeYaml file: envFile, data: envVersions, overwrite: true
    
            if (hasValuesFileChanged(envFile)) {
                sh "git add ${envFile}"
                sh "git commit -m '${commitMessage}'"
            }
        }
    }
    
    
    String getCommitHash() {
        return "-${env.GIT_COMMIT.take(7)}";
    
    Boolean hasValuesFileChanged(String envFile) {
        return sh (script: "git status | grep '${envFile}'", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean isReleaseBranch() {
        return env.BRANCH_NAME == 'release'
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean isMasterBranch() {
        return env.BRANCH_NAME == 'master'
    
    Boolean isBarrierefreiheitBranch() {
        return env.BRANCH_NAME == 'barrierefreiheit-dev'
    }
    
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean isReleaseVersion(List versions) {
        return matchRegexVersion(versions, RELEASE_REGEX)
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean isSnapshotVersion(List versions) {
        return matchRegexVersion(versions, SNAPSHOT_REGEX)
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean matchRegexVersion(List versions, String regex) {
        for (version in versions) {
            println version
            if ( !(version ==~ regex) ) {
                return false
            }
        }
    
        return true
    
    OZGCloud's avatar
    OZGCloud committed
    Boolean isSameVersion(List versions, String expectedVersion) {
        for (version in versions) {
            if ( version != expectedVersion ) {
                return false
            }
        }
    
        return true
    
    OZGCloud's avatar
    OZGCloud committed
    String getRootPomVersion() {
        def rootPom = readMavenPom file: 'pom.xml'
        return rootPom.version
    
    OZGCloud's avatar
    OZGCloud committed
    }
    
    
    OZGCloud's avatar
    OZGCloud committed
    String getParentPomVersion(String filePath) {
        def pom = readMavenPom file: filePath
        return pom.parent.version
    
    OZGCloud's avatar
    OZGCloud committed
    }