pipeline { agent { node { label 'ozgcloud-jenkins-build-agent-jdk21-node20' } } environment { BLUE_OCEAN_URL = "https://jenkins.infra.ozg-cloud.systems/job/alfa/job/${env.BRANCH_NAME}/${env.BUILD_NUMBER}/" RELEASE_REGEX = /\d+.\d+.\d+/ SNAPSHOT_REGEX = /\d+.\d+.\d+-SNAPSHOT/ FAILED_STAGE = "" SH_SUCCESS_STATUS_CODE = 0 } options { timeout(time: 1, unit: 'HOURS') disableConcurrentBuilds() buildDiscarder(logRotator(numToKeepStr: '5')) } stages { stage('Check Version') { steps { script { FAILED_STAGE = env.STAGE_NAME VERSION = getRootPomVersion() def serverVersion = getParentPomVersion('alfa-server/pom.xml') def clientVersion = getParentPomVersion('alfa-client/pom.xml') if(isReleaseBranch()){ if ( !isReleaseVersion([VERSION, serverVersion, clientVersion]) ) { error("Keine Release Version für Branch ${env.BRANCH_NAME}.") } } else { if ( !isSnapshotVersion([VERSION, serverVersion, clientVersion]) ) { error("Keine Snapshot Version für Branch ${env.BRANCH_NAME}.") } } if( !isSameVersion([serverVersion, clientVersion], VERSION) ){ error("Versionen sind nicht identisch") } } } } stage('Client') { environment { FORCE_COLOR = 'false' } steps { script { FAILED_STAGE=env.STAGE_NAME sh 'npm --version' sh 'node --version' dir('alfa-client') { sh 'echo "registry=https://nexus.ozg-sh.de/repository/npm-proxy" >> ~/.npmrc' sh 'echo "//nexus.ozg-sh.de/:_auth=amVua2luczprTSFnNVUhMVQzNDZxWQ==" >> ~/.npmrc' sh 'npm cache verify' sh 'npm install' if (isMasterBranch()) { withSonarQubeEnv('sonarqube-ozg-sh'){ sh 'npm run ci-sonar' } } else { sh 'npm run ci-test' } if (isReleaseBranch()) { sh 'npm run ci-prodBuild' } else { sh 'npm run ci-build' } } } } // post { // always{ // junit testResults: 'alfa-client/test-report.xml', skipPublishingChecks: true // } // } } stage('Build and push client container') { steps { script { catchError(buildResult: 'SUCCESS', stageResult: 'FAILURE') { dir('alfa-client') { IMAGE_TAG = generateImageTag() sh 'npm run ci-build-alfa-client-container' withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) { sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}' sh "docker tag docker.ozg-sh.de/alfa-client:build-latest docker.ozg-sh.de/alfa-client:${IMAGE_TAG}" sh "docker push docker.ozg-sh.de/alfa-client:${IMAGE_TAG}" } } } } } } stage('Set Version') { when { not { anyOf { branch 'master' branch 'release' } } } steps { script { FAILED_STAGE=env.STAGE_NAME JAR_TAG = getRootPomVersion().replace("SNAPSHOT", "${env.BRANCH_NAME}-SNAPSHOT") } configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) { sh "mvn -s $MAVEN_SETTINGS versions:set -DnewVersion=${JAR_TAG} -DprocessAllModules=true" } } } stage('Build Server artefacts, build and push docker image') { steps { script { FAILED_STAGE=env.STAGE_NAME IMAGE_TAG = generateImageTag() configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) { sh 'mvn --version' sh "mvn --no-transfer-progress -s $MAVEN_SETTINGS -pl -alfa-client clean install spring-boot:build-image -Dspring-boot.build-image.imageName=docker.ozg-sh.de/alfa:${IMAGE_TAG} -Dspring-boot.build-image.publish -Dmaven.wagon.http.retryHandler.count=3" if (isMasterBranch()) { try { dir('alfa-service'){ withSonarQubeEnv('sonarqube-ozg-sh'){ sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS sonar:sonar' } } } catch (Exception e) { unstable("SonarQube failed") } } } } } post { always{ junit testResults: '**/target/surefire-reports/*.xml', skipPublishingChecks: true } } } stage('Deploy Maven Artifacts to Nexus') { steps { script { FAILED_STAGE = env.STAGE_NAME } configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) { sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS -pl -alfa-client -DskipTests deploy' sh "mvn -s $MAVEN_SETTINGS versions:revert" } } } stage('Tag and Push Docker Image') { when { anyOf { branch 'master' branch 'release' } } steps { script { FAILED_STAGE = env.STAGE_NAME if (isMasterBranch()) { tagAndPushDockerImage('snapshot-latest') } else if (isReleaseBranch()) { tagAndPushDockerImage('latest') } } } } stage('Test, build and deploy Helm Chart') { steps { script { FAILED_STAGE=env.STAGE_NAME HELM_CHART_VERSION = generateHelmChartVersion() sh "./run_helm_test.sh" dir('src/main/helm') { sh "helm package --version=${HELM_CHART_VERSION} ." deployHelmChart(HELM_CHART_VERSION) } } } } stage('Trigger Dev rollout') { when { branch 'master' } steps { script { FAILED_STAGE = env.STAGE_NAME cloneGitopsRepo() setNewDevVersion() pushGitopsRepo() } } } stage('Trigger Test rollout') { when { branch 'release' } steps { script { FAILED_STAGE = env.STAGE_NAME cloneGitopsRepo() setNewTestVersion() pushGitopsRepo() } } } stage ('Deploy SBOM to DependencyTrack') { steps { script { IMAGE_TAG = generateImageTag() configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) { withCredentials([string(credentialsId: 'dependency-track-api-key', variable: 'API_KEY')]) { dir('alfa-server') { catchError(buildResult: 'UNSTABLE', stageResult: 'FAILURE') { sh "mvn --no-transfer-progress -s $MAVEN_SETTINGS io.github.pmckeown:dependency-track-maven-plugin:upload-bom -Ddependency-track.apiKey=$API_KEY -Ddependency-track.projectVersion=${IMAGE_TAG} -Ddependency-track.dependencyTrackBaseUrl=https://dependency-track.ozg-sh.de" } } } } } } } stage ('Trigger Barrierefreiheit Rollout') { when { branch 'barrierefreiheit-dev' } steps { script { FAILED_STAGE = env.STAGE_NAME cloneGitopsRepo() setNewBarrierefreiheitVersion() pushGitopsRepo() } } } } post { failure { script { if (isMasterBranch() || isReleaseBranch()) { sendFailureMessage() } } } } } Void deployHelmChart(String helmChartVersion) { withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USERNAME', passwordVariable: 'PASSWORD')]){ if (isReleaseBranch()) { result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps -F file=@alfa-'''+helmChartVersion+'''.tgz''', returnStdout: true } else { result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps-snapshot -F file=@alfa-'''+helmChartVersion+'''.tgz''', returnStdout: true } if (result != '') { error(result) } } } String generateHelmChartVersion() { def chartVersion = "${VERSION}" if (isMasterBranch()) { chartVersion += getCommitHash() } else if (isBarrierefreiheitBranch()) { chartVersion += "-barrierefreiheit${getCommitHash()}" } else if (!isReleaseBranch()) { chartVersion += "-${env.BRANCH_NAME}" } return chartVersion.replaceAll("_", "-") } Void tagAndPushDockerImage(String newTag){ withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) { sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}' sh "docker tag docker.ozg-sh.de/alfa:${IMAGE_TAG} docker.ozg-sh.de/alfa:${newTag}" sh "docker push docker.ozg-sh.de/alfa:${newTag}" } } String generateImageTag() { def imageTag = "${env.BRANCH_NAME}-${VERSION}" if (isMasterBranch() || isBarrierefreiheitBranch()) { imageTag += getCommitHash() } return imageTag } Void cloneGitopsRepo() { withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) { sh 'git clone https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git' } configureGit() } Void pushGitopsRepo() { withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) { dir("gitops") { if (hasUnpushedCommits()) { sh 'git push https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git' } } } } Boolean hasUnpushedCommits() { return sh (script: "git cherry -v | grep .", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer } Void configureGit() { final email = "jenkins@ozg-sh.de" final name = "jenkins" dir("gitops") { sh "git config user.email '${email}'" sh "git config user.name '${name}'" } } Void sendFailureMessage() { def room = '' def data = """{"msgtype":"m.text", \ "body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER} Link: ${BLUE_OCEAN_URL}", \ "format": "org.matrix.custom.html", \ "formatted_body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: <a href='${BLUE_OCEAN_URL}'>${env.BUILD_NUMBER}</a>"}""" if (isMasterBranch()) { room = "!iQPAvQIiRwRpNOszjw:matrix.ozg-sh.de" } else if (isReleaseBranch()) { room = "!oWZpUGTFsxkJIYNfYg:matrix.ozg-sh.de" } sh "curl -XPOST -H 'authorization: Bearer ${getElementAccessToken()}' -d '${data}' https://matrix.ozg-sh.de/_matrix/client/v3/rooms/$room/send/m.room.message" } String getElementAccessToken() { withCredentials([string(credentialsId: 'element-login-json', variable: 'LOGIN_JSON')]) { return readJSON ( text: sh (script: '''curl -XPOST -d \"$LOGIN_JSON\" https://matrix.ozg-sh.de/_matrix/client/v3/login''', returnStdout: true)).access_token } } Void setNewDevVersion() { setNewGitopsVersion("dev") } Void setNewTestVersion() { setNewGitopsVersion("test") } Void setNewGitopsVersion(String environment) { def envFile = "${environment}/application/values/alfa-values.yaml" def commitMessage = "jenkins rollout ${environment} alfa version ${IMAGE_TAG}"; setNewGitopsVersion(envFile, commitMessage); } Void setNewBarrierefreiheitVersion() { def envFile = "dev/namespace/namespaces/by-barrierefreiheit-dev.yaml" def commitMessage = "jenkins rollout ${IMAGE_TAG} for Barrierefreiheit Dev" setNewGitopsVersion(envFile, commitMessage); } Void setNewGitopsVersion(String envFile, String commitMessage) { dir("gitops") { def envVersions = readYaml file: envFile envVersions.alfa.image.tag = IMAGE_TAG envVersions.alfa.helm.version = HELM_CHART_VERSION writeYaml file: envFile, data: envVersions, overwrite: true if (hasValuesFileChanged(envFile)) { sh "git add ${envFile}" sh "git commit -m '${commitMessage}'" } } } String getCommitHash() { return "-${env.GIT_COMMIT.take(7)}"; } Boolean hasValuesFileChanged(String envFile) { return sh (script: "git status | grep '${envFile}'", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer } Boolean isReleaseBranch() { return env.BRANCH_NAME == 'release' } Boolean isMasterBranch() { return env.BRANCH_NAME == 'master' } Boolean isBarrierefreiheitBranch() { return env.BRANCH_NAME == 'barrierefreiheit-dev' } Boolean isReleaseVersion(List versions) { return matchRegexVersion(versions, RELEASE_REGEX) } Boolean isSnapshotVersion(List versions) { return matchRegexVersion(versions, SNAPSHOT_REGEX) } Boolean matchRegexVersion(List versions, String regex) { for (version in versions) { println version if ( !(version ==~ regex) ) { return false } } return true } Boolean isSameVersion(List versions, String expectedVersion) { for (version in versions) { if ( version != expectedVersion ) { return false } } return true } String getRootPomVersion() { def rootPom = readMavenPom file: 'pom.xml' return rootPom.version } String getParentPomVersion(String filePath) { def pom = readMavenPom file: filePath return pom.parent.version }