Skip to content
Snippets Groups Projects
Select Git revision
  • 1c6e974466de1e6259766c50738575886e7b51a2
  • main default protected
  • OZG-8073-date-component
  • OZG-7985-Statistik-Datenfreigabe
  • OZG-7970-AlfaCodeFlow
  • OZG-8271-fix-date-bug
  • OZG-7856_schadcode_scanner
  • OZG-8305-Create-webpack-sbom
  • tooltip-improvements
  • ods-remove-class-inputs
  • release-info
  • release-administration
  • release
  • OZG-7714-UpgradeKeycloakDependencyTo25
  • OZG-8086-Admin-Datenanfrage-erstellen
  • OZG-8086-Datenanfrage-Umbenennung
  • mongodb-7-0-16-e2e
  • OZG-6220-Bescheid-speichern-ohne-Postfach
  • OZG-7922-KeycloakOperatorExceptions
  • OZG-8142-poc-cards
  • OZG-8086-E2E
  • 1.11.0-info
  • 1.11.0-administration
  • 2.26.0-alfa
  • 1.10.0-info
  • 1.10.0-administration
  • 2.25.0-alfa
  • 1.9.0-info
  • 1.9.0-administration
  • 2.24.0-alfa
  • 1.8.0-info
  • 1.8.0-administration
  • 2.23.0-alfa
  • 1.7.0-info
  • 1.7.0-administration
  • 2.22.0-alfa
  • 1.6.0-info
  • 1.6.0-administration
  • 2.21.0-alfa
  • 1.5.0-info
  • 1.5.0-administration
41 results

Jenkinsfile.admin

Blame
  • Jenkinsfile.admin 9.76 KiB
    /*
     * Copyright (C) 2023 Das Land Schleswig-Holstein vertreten durch den
     * Ministerpräsidenten des Landes Schleswig-Holstein
     * Staatskanzlei
     * Abteilung Digitalisierung und zentrales IT-Management der Landesregierung
     *
     * Lizenziert unter der EUPL, Version 1.2 oder - sobald
     * diese von der Europäischen Kommission genehmigt wurden -
     * Folgeversionen der EUPL ("Lizenz");
     * Sie dürfen dieses Werk ausschließlich gemäß
     * dieser Lizenz nutzen.
     * Eine Kopie der Lizenz finden Sie hier:
     *
     * https://joinup.ec.europa.eu/collection/eupl/eupl-text-eupl-12
     *
     * Sofern nicht durch anwendbare Rechtsvorschriften
     * gefordert oder in schriftlicher Form vereinbart, wird
     * die unter der Lizenz verbreitete Software "so wie sie
     * ist", OHNE JEGLICHE GEWÄHRLEISTUNG ODER BEDINGUNGEN -
     * ausdrücklich oder stillschweigend - verbreitet.
     * Die sprachspezifischen Genehmigungen und Beschränkungen
     * unter der Lizenz sind dem Lizenztext zu entnehmen.
     */
    pipeline {
      agent {
        node {
          label 'ozgcloud-jenkins-build-agent-jdk21-node20'
        }
      }
    
      environment {
            BLUE_OCEAN_URL = "https://jenkins.infra.ozg-cloud.systems/job/admin-client/job/${env.BRANCH_NAME}/${env.BUILD_NUMBER}/"
            RELEASE_REGEX = /\d+.\d+.\d+/
            SNAPSHOT_REGEX = /\d+.\d+.\d+-SNAPSHOT/
            FAILED_STAGE = ""
            SH_SUCCESS_STATUS_CODE = 0
            FORCE_COLOR = 0
            NO_COLOR = 1
            NX_DISABLE_DB = true
        }
    
        options {
            timeout(time: 1, unit: 'HOURS')
            disableConcurrentBuilds()
            buildDiscarder(logRotator(numToKeepStr: '5'))
        }
    
        stages {
            stage('Check Version') {
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
                         dir('alfa-client') {
                        VERSION = getPackagejsonVersion()
                         }
                    }
                }
            }
    
            stage('build admin client and its docker image') {
                steps {
                    script {
    	                FAILED_STAGE=env.STAGE_NAME
    
                        withNPM(npmrcConfig: 'npm-nexus-auth') {
                            dir('alfa-client') {
      	                        sh 'npm cache verify'
                                sh 'npm install'
    
    	                        if (isReleaseBranch()) {
    	                        	sh 'npm run ci-prodBuild-admin'
    	                        } else {
    	                        	sh 'npm run ci-build-admin'
    	                        }
        	                    if (isMasterBranch()) {
                                    withSonarQubeEnv('sonarqube-ozg-sh'){
                                        sh 'npm run ci-sonar'
                                    }
                                } else {
                                    sh 'npm run ci-test'
                                }
    	                    }
                        }
                    }
                }
            }
    
            stage('Tag and Push Docker image') {
                steps {
                    script {
                        FAILED_STAGE=env.STAGE_NAME
                        IMAGE_TAG = generateImageTag()
    
                        tagAndPushDockerImage(IMAGE_TAG)
    
                        if (isMasterBranch()) {
                            tagAndPushDockerImage('snapshot-latest')
                        }
                        else if (isReleaseBranch()) {
                            tagAndPushDockerImage('latest')
                        }
                    }
                }
            }
    
            stage('Test, build and deploy Helm Chart') {
                steps {
                    script {
                        FAILED_STAGE=env.STAGE_NAME
                        HELM_CHART_VERSION = generateHelmChartVersion()
    
                       dir('alfa-client/apps/admin') {
                        sh "./run_helm_test.sh"
                       }
    
                        dir('alfa-client/apps/admin/src/main/helm') {
    
                            sh "helm package --version=${HELM_CHART_VERSION} ."
    
                            deployHelmChart(HELM_CHART_VERSION)
                        }
                    }
                }
            }
    
            stage('Trigger Dev rollout') {
                when {
                    branch 'master'
                }
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
    
                        cloneGitopsRepo()
    
                        setNewDevVersion()
                        pushGitopsRepo()
                    }
                }
            }
    
            stage('Trigger Test rollout') {
                when {
                    branch 'release-admin'
                }
                steps {
                    script {
                        FAILED_STAGE = env.STAGE_NAME
    
                        cloneGitopsRepo()
    
                        setNewTestVersion()
                        pushGitopsRepo()
                    }
                }
            }
        }
    
        post {
            failure {
                script {
                    if (isMasterBranch() || isReleaseBranch()) {
                        sendFailureMessage()
                    }
                }
            }
        }
    }
    
    
    Boolean isReleaseBranch() {
        return env.BRANCH_NAME == 'release-admin'
    }
    
    String generateImageTag() {
        def imageTag = "${env.BRANCH_NAME}-${VERSION}"
    
        if (isMasterBranch()) {
            imageTag += "-${env.GIT_COMMIT.take(7)}"
        }
    
        return imageTag
    }
    
    Void cloneGitopsRepo() {
        withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
            sh 'git clone https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
        }
        configureGit()
    }
    
    Void configureGit() {
        final email = "jenkins@ozg-sh.de"
        final name = "jenkins"
    
        dir("gitops") {
            sh "git config user.email '${email}'"
            sh "git config user.name '${name}'"
        }
    }
    
    Void setNewDevVersion() {
        setNewGitopsVersion("dev")
    }
    
    Void setNewTestVersion() {
        setNewGitopsVersion("test")
    }
    
    Void setNewGitopsVersion(String environment) {
        dir("gitops") {
            def envFile = "${environment}/application/values/admin-client-values.yaml"
    
            def envVersions = readYaml file: envFile
    
            envVersions.admin_client.image.tag = IMAGE_TAG
            envVersions.admin_client.helm.version = HELM_CHART_VERSION
    
            writeYaml file: envFile, data: envVersions, overwrite: true
    
            if (hasValuesFileChanged(environment)) {
                sh "git add ${envFile}"
                sh "git commit -m 'jenkins rollout ${environment} admin_client version ${IMAGE_TAG}'"
            }
        }
    }
    
    Boolean hasValuesFileChanged(String environment) {
        return sh (script: "git status | grep '${environment}/application/values/admin-client-values.yaml'", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
    }
    
    
    Void pushGitopsRepo() {
        withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
            dir("gitops") {
                if (hasUnpushedCommits()) {
                    sh 'git push https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
                }
            }
        }
    }
    
    Boolean hasUnpushedCommits() {
        return sh (script: "git cherry -v | grep .", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
    }
    
    Void tagAndPushDockerImage(String newTag){
        withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
            sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'
    
            sh "docker tag docker.ozg-sh.de/admin-client:build-latest docker.ozg-sh.de/admin-client:${newTag}"
            sh "docker push docker.ozg-sh.de/admin-client:${newTag}"
        }
    }
    String getPackagejsonVersion() {
        def packageJSON = readJSON file: 'package.json'
        def packageJSONVersion = packageJSON.version
        echo packageJSONVersion
        return packageJSONVersion
    }
    
    Void deployHelmChart(String helmChartVersion) {
        withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USERNAME', passwordVariable: 'PASSWORD')]){
            if (isReleaseBranch()) {
                result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps -F file=@admin-client-'''+helmChartVersion+'''.tgz''', returnStdout: true
            }
            else {
                result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps-snapshot -F file=@admin-client-'''+helmChartVersion+'''.tgz''', returnStdout: true
            }
    
            if (result != '') {
                error(result)
            }
        }
    }
    String generateHelmChartVersion() {
        def chartVersion = "${VERSION}"
    
        if (isMasterBranch()) {
            chartVersion += "-${env.GIT_COMMIT.take(7)}"
        }
        else if (!isReleaseBranch()) {
            chartVersion += "-${env.BRANCH_NAME}"
        }
    
        return chartVersion.replaceAll("_", "-")
    }
    
    Boolean isMasterBranch() {
        return env.BRANCH_NAME == 'master'
    }
    
    Void sendFailureMessage() {
        def room = ''
        def data = """{"msgtype":"m.text", \
                        "body":"Admin-Client: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER} Link: ${BLUE_OCEAN_URL}", \
                        "format": "org.matrix.custom.html", \
                        "formatted_body":"Admin-Client: Build Failed. Stage: ${FAILED_STAGE} Build-ID: <a href='${BLUE_OCEAN_URL}'>${env.BUILD_NUMBER}</a>"}"""
    
        if (isMasterBranch()) {
            room = "!iQPAvQIiRwRpNOszjw:matrix.ozg-sh.de"
        }
        else if (isReleaseBranch()) {
            room = "!oWZpUGTFsxkJIYNfYg:matrix.ozg-sh.de"
        }
    
        sh "curl -XPOST -H 'authorization: Bearer ${getElementAccessToken()}' -d '${data}' https://matrix.ozg-sh.de/_matrix/client/v3/rooms/$room/send/m.room.message"
    }
    
    String getElementAccessToken() {
        withCredentials([string(credentialsId: 'element-login-json', variable: 'LOGIN_JSON')]) {
            return readJSON ( text: sh (script: '''curl -XPOST -d \"$LOGIN_JSON\" https://matrix.ozg-sh.de/_matrix/client/v3/login''', returnStdout: true)).access_token
        }
    }