Newer
Older
label 'ozgcloud-jenkins-build-agent-jdk21-node20'
BLUE_OCEAN_URL = "https://jenkins.infra.ozg-cloud.systems/job/alfa/job/${env.BRANCH_NAME}/${env.BUILD_NUMBER}/"
RELEASE_REGEX = /\d+.\d+.\d+/
SNAPSHOT_REGEX = /\d+.\d+.\d+-SNAPSHOT/
options {
timeout(time: 1, unit: 'HOURS')
disableConcurrentBuilds()
stage('Check Version') {
steps {
script {
FAILED_STAGE = env.STAGE_NAME
def serverVersion = getParentPomVersion('alfa-server/pom.xml')
def clientVersion = getParentPomVersion('alfa-client/pom.xml')
if ( !isReleaseVersion([VERSION, serverVersion, clientVersion]) ) {
error("Keine Release Version für Branch ${env.BRANCH_NAME}.")
}
} else {
if ( !isSnapshotVersion([VERSION, serverVersion, clientVersion]) ) {
error("Keine Snapshot Version für Branch ${env.BRANCH_NAME}.")
}
}
if( !isSameVersion([serverVersion, clientVersion], VERSION) ){
error("Versionen sind nicht identisch")
environment {
FORCE_COLOR = 'false'
}
sh 'echo "registry=https://nexus.ozg-sh.de/repository/npm-proxy" >> ~/.npmrc'
sh 'echo "//nexus.ozg-sh.de/:_auth=amVua2luczprTSFnNVUhMVQzNDZxWQ==" >> ~/.npmrc'
sh 'npm cache verify'
if (isMasterBranch()) {
withSonarQubeEnv('sonarqube-ozg-sh'){
sh 'npm run ci-sonar'
if (isReleaseBranch()) {
sh 'npm run ci-prodBuild'
}
else {
sh 'npm run ci-build'
}
// junit testResults: 'alfa-client/test-report.xml', skipPublishingChecks: true
stage('Build and push client container') {
steps {
script {
catchError(buildResult: 'SUCCESS', stageResult: 'FAILURE') {
dir('alfa-client') {
IMAGE_TAG = generateImageTag()
sh 'npm run ci-build-alfa-client-container'
withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'
sh "docker tag docker.ozg-sh.de/alfa-client:build-latest docker.ozg-sh.de/alfa-client:${IMAGE_TAG}"
sh "docker push docker.ozg-sh.de/alfa-client:${IMAGE_TAG}"
}
stage('Set Version') {
when {
not {
anyOf {
branch 'master'
branch 'release'
}
}
}
steps {
script {
FAILED_STAGE=env.STAGE_NAME
JAR_TAG = getRootPomVersion().replace("SNAPSHOT", "${env.BRANCH_NAME}-SNAPSHOT")
}
configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
sh "mvn -s $MAVEN_SETTINGS versions:set -DnewVersion=${JAR_TAG} -DprocessAllModules=true"
}
}
}
stage('Build Server artefacts, build and push docker image') {
IMAGE_TAG = generateImageTag()
configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
sh 'mvn --version'
sh "mvn --no-transfer-progress -s $MAVEN_SETTINGS -pl -alfa-client clean install spring-boot:build-image -Dspring-boot.build-image.imageName=docker.ozg-sh.de/alfa:${IMAGE_TAG} -Dspring-boot.build-image.publish -Dmaven.wagon.http.retryHandler.count=3"
if (isMasterBranch()) {
try {
dir('alfa-service'){
withSonarQubeEnv('sonarqube-ozg-sh'){
sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS sonar:sonar'
}
}
dir('alfa-xdomea'){
withSonarQubeEnv('sonarqube-ozg-sh'){
sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS sonar:sonar'
}
}
}
catch (Exception e) {
unstable("SonarQube failed")
}
}
post {
always{
junit testResults: '**/target/surefire-reports/*.xml', skipPublishingChecks: true
}
}
}
stage('Deploy Maven Artifacts to Nexus') {
steps {
script {
FAILED_STAGE = env.STAGE_NAME
}
configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS -pl -alfa-client -DskipTests deploy'
sh "mvn -s $MAVEN_SETTINGS versions:revert"
stage('Tag and Push Docker Image') {
when {
anyOf {
branch 'master'
branch 'release'
}
}
steps {
script {
FAILED_STAGE = env.STAGE_NAME
tagAndPushDockerImage('snapshot-latest')
tagAndPushDockerImage('latest')
stage('Test, build and deploy Helm Chart') {
steps {
sh "helm package --version=${HELM_CHART_VERSION} ."
stage('Trigger Dev rollout') {
when {
branch 'release'
}
steps {
script {
FAILED_STAGE = env.STAGE_NAME
stage ('Deploy SBOM to DependencyTrack') {
configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
withCredentials([string(credentialsId: 'dependency-track-api-key', variable: 'API_KEY')]) {
dir('alfa-server') {
catchError(buildResult: 'UNSTABLE', stageResult: 'FAILURE') {
sh "mvn --no-transfer-progress -s $MAVEN_SETTINGS io.github.pmckeown:dependency-track-maven-plugin:upload-bom -Ddependency-track.apiKey=$API_KEY -Ddependency-track.projectVersion=${IMAGE_TAG} -Ddependency-track.dependencyTrackBaseUrl=https://dependency-track.ozg-sh.de"
}
stage ('Trigger Barrierefreiheit Rollout') {
when {
}
steps {
script {
FAILED_STAGE = env.STAGE_NAME
cloneGitopsRepo()
setNewBarrierefreiheitVersion()
pushGitopsRepo()
}
}
}
Void deployHelmChart(String helmChartVersion) {
withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USERNAME', passwordVariable: 'PASSWORD')]){
result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps -F file=@alfa-'''+helmChartVersion+'''.tgz''', returnStdout: true
result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps-snapshot -F file=@alfa-'''+helmChartVersion+'''.tgz''', returnStdout: true
}
if (result != '') {
error(result)
}
}
}
String generateHelmChartVersion() {
def chartVersion = "${VERSION}"
chartVersion += getCommitHash()
}
else if (isBarrierefreiheitBranch()) {
chartVersion += "-barrierefreiheit${getCommitHash()}"
return chartVersion.replaceAll("_", "-")
Void tagAndPushDockerImage(String newTag){
withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'
sh "docker tag docker.ozg-sh.de/alfa:${IMAGE_TAG} docker.ozg-sh.de/alfa:${newTag}"
sh "docker push docker.ozg-sh.de/alfa:${newTag}"
}
}
String generateImageTag() {
def imageTag = "${env.BRANCH_NAME}-${VERSION}"
if (isMasterBranch() || isBarrierefreiheitBranch()) {
imageTag += getCommitHash()
}
return imageTag
}
withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
sh 'git clone https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
sh 'git push https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
return sh (script: "git cherry -v | grep .", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
final email = "jenkins@ozg-sh.de"
final name = "jenkins"
sh "git config user.email '${email}'"
sh "git config user.name '${name}'"
Void sendFailureMessage() {
def room = ''
def data = """{"msgtype":"m.text", \
"body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER} Link: ${BLUE_OCEAN_URL}", \
"format": "org.matrix.custom.html", \
"formatted_body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: <a href='${BLUE_OCEAN_URL}'>${env.BUILD_NUMBER}</a>"}"""
room = "!iQPAvQIiRwRpNOszjw:matrix.ozg-sh.de"
}
room = "!oWZpUGTFsxkJIYNfYg:matrix.ozg-sh.de"
}
sh "curl -XPOST -H 'authorization: Bearer ${getElementAccessToken()}' -d '${data}' https://matrix.ozg-sh.de/_matrix/client/v3/rooms/$room/send/m.room.message"
}
String getElementAccessToken() {
withCredentials([string(credentialsId: 'element-login-json', variable: 'LOGIN_JSON')]) {
return readJSON ( text: sh (script: '''curl -XPOST -d \"$LOGIN_JSON\" https://matrix.ozg-sh.de/_matrix/client/v3/login''', returnStdout: true)).access_token
}
Void setNewDevVersion() {
setNewGitopsVersion("dev")
Void setNewTestVersion() {
setNewGitopsVersion("test")
Void setNewGitopsVersion(String environment) {
def envFile = "${environment}/application/values/alfa-values.yaml"
def commitMessage = "jenkins rollout ${environment} alfa version ${IMAGE_TAG}";
setNewGitopsVersion(envFile, commitMessage);
}
Void setNewBarrierefreiheitVersion() {
def envFile = "dev/namespace/namespaces/by-barrierefreiheit-dev.yaml"
def commitMessage = "jenkins rollout ${IMAGE_TAG} for Barrierefreiheit Dev"
setNewGitopsVersion(envFile, commitMessage);
}
Void setNewGitopsVersion(String envFile, String commitMessage) {
dir("gitops") {
envVersions.alfa.image.tag = IMAGE_TAG
envVersions.alfa.helm.version = HELM_CHART_VERSION
writeYaml file: envFile, data: envVersions, overwrite: true
if (hasValuesFileChanged(envFile)) {
sh "git commit -m '${commitMessage}'"
String getCommitHash() {
return "-${env.GIT_COMMIT.take(7)}";
Boolean hasValuesFileChanged(String envFile) {
return sh (script: "git status | grep '${envFile}'", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
Boolean isReleaseBranch() {
return env.BRANCH_NAME == 'release'
Boolean isMasterBranch() {
return env.BRANCH_NAME == 'master'
Boolean isBarrierefreiheitBranch() {
return env.BRANCH_NAME == 'barrierefreiheit-dev'
}
Boolean isReleaseVersion(List versions) {
return matchRegexVersion(versions, RELEASE_REGEX)
Boolean isSnapshotVersion(List versions) {
return matchRegexVersion(versions, SNAPSHOT_REGEX)
Boolean matchRegexVersion(List versions, String regex) {
for (version in versions) {
println version
if ( !(version ==~ regex) ) {
return false
}
}
return true
Boolean isSameVersion(List versions, String expectedVersion) {
for (version in versions) {
if ( version != expectedVersion ) {
return false
}
}
return true
String getRootPomVersion() {
def rootPom = readMavenPom file: 'pom.xml'
return rootPom.version
String getParentPomVersion(String filePath) {
def pom = readMavenPom file: filePath
return pom.parent.version