Select Git revision
serviceaccount-keycloakgroup-write.yaml
Jenkinsfile 9.97 KiB
pipeline {
agent {
node {
label 'ozgcloud-jenkins-build-agent'
}
}
tools { go 'go-1.22.0' }
environment {
RELEASE_REGEX = /v\d+.\d+.\d+/
BETA_REGEX = /v\d+.\d+.\d+-beta.\d/
FAILED_STAGE = ""
SH_SUCCESS_STATUS_CODE = 0
}
options {
timeout(time: 1, unit: 'HOURS')
disableConcurrentBuilds()
buildDiscarder(logRotator(numToKeepStr: '5'))
}
stages {
stage('Get and Check Version') {
steps {
script {
FAILED_STAGE = env.STAGE_NAME
// Read the file content
def fileContent = readFile('cmd/antragsraum-proxy/main.go')
// Define the regex pattern to match "version= <version>"
def versionPattern = /var version = \"(.*?)\"/
// Find the line that matches the pattern
def matcher = fileContent =~ versionPattern
if (matcher.find()) {
env.APP_VERSION = matcher[0][1].trim()
echo "Version found: ${env.APP_VERSION}"
} else {
error("Version not found in main.go")
}
if(isReleaseBranch()){
if ( !(env.APP_VERSION ==~ RELEASE_REGEX) ) {
error("Keine Release Version für Branch ${env.BRANCH_NAME}.")
}
} else {
if ( !(env.APP_VERSION ==~ BETA_REGEX) ) {
error("Keine Beta Version für Branch ${env.BRANCH_NAME}.")
}
}
}
}
}
stage('Build Antragsraum-Proxy') {
steps {
script {
FAILED_STAGE=env.STAGE_NAME
sh '''
#export GOPATH so that installed dependencies could be found
export GOPATH=$GOROOT
go mod download
go install \
github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-grpc-gateway \
github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2 \
google.golang.org/protobuf/cmd/protoc-gen-go \
google.golang.org/grpc/cmd/protoc-gen-go-grpc
'''
sh '''
curl -sSL "https://github.com/bufbuild/buf/releases/download/v1.34.0/buf-$(uname -s)-$(uname -m)" -o ./buf
chmod +x ./buf
./buf generate
#to compile go statically with these tags, so that the binary is not dynamically linked and from scratch in Dockerfile will work
go build -tags osusergo,netgo cmd/antragsraum-proxy/main.go
'''
}
}
}
stage('Build and publish Docker image') {
steps {
script {
FAILED_STAGE=env.STAGE_NAME
sh "docker build -t docker.ozg-sh.de/antragsraum-proxy:${env.APP_VERSION} ."
IMAGE_TAG = generateImageTag()
tagAndPushDockerImage('antragsraum-proxy', IMAGE_TAG)
if (env.BRANCH_NAME == 'master') {
tagAndPushDockerImage('antragsraum-proxy', 'snapshot-latest')
}
else if (env.BRANCH_NAME == 'release') {
tagAndPushDockerImage('antragsraum-proxy', 'latest')
}
}
}
}
stage('Test, build and deploy Helm Chart') {
steps {
script {
FAILED_STAGE=env.STAGE_NAME
HELM_CHART_VERSION = generateHelmChartVersion()
sh "./run_helm_test.sh"
dir('src/main/helm') {
sh "helm package --version=${HELM_CHART_VERSION} ."
deployHelmChart(HELM_CHART_VERSION)
}
}
}
}
stage('Trigger Dev rollout') {
when {
branch 'master'
}
steps {
script {
FAILED_STAGE = env.STAGE_NAME
cloneGitopsRepo()
setNewDevAntragsraumProxyVersion()
pushDevGitopsRepo()
}
}
}
stage('Trigger Test rollout') {
when {
branch 'release'
}
steps {
script {
FAILED_STAGE = env.STAGE_NAME
cloneGitopsRepo()
setNewTestAntragsraumProxyVersion()
pushTestGitopsRepo()
}
}
}
}
}
Void deployHelmChart(String helmChartVersion) {
withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USERNAME', passwordVariable: 'PASSWORD')]){
String fileName = '@antragsraum-proxy-' + helmChartVersion + '.tgz'
result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=''' + getHelmRepository() + ''' -F file=''' + fileName, returnStdout: true
if (result != '') {
error(result)
}
}
}
String getHelmRepository(){
if (isReleaseBranch()) {
return 'ozg-base-apps';
}
return 'ozg-base-apps-snapshot';
}
String generateImageTag() {
return "${env.APP_VERSION}-${env.BRANCH_NAME}"
}
String getBuildProfile() {
if (isMasterBranch()) {
return "-P master"
} else if (isReleaseBranch()) {
return "-P release"
} else {
return ""
}
}
Void sendFailureMessage() {
def room = getRoom()
def data = getFailureData()
sh "curl -XPOST -H 'authorization: Bearer ${getElementAccessToken()}' -d '${data}' https://matrix.ozg-sh.de/_matrix/client/v3/rooms/$room/send/m.room.message"
}
String getElementAccessToken() {
withCredentials([string(credentialsId: 'element-login-json', variable: 'LOGIN_JSON')]) {
return readJSON ( text: sh (script: '''curl -XPOST -d \"$LOGIN_JSON\" https://matrix.ozg-sh.de/_matrix/client/v3/login''', returnStdout: true)).access_token
}
}
String getFailureData() {
return """{"msgtype":"m.text", \
"body":"Antragsraum-Proxy: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER}", \
"format": "org.matrix.custom.html", \
"formatted_body":"Antragsraum-Proxy: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER}"}"""
}
String getRoom() {
if (isReleaseBranch()) {
return "!oWZpUGTFsxkJIYNfYg:matrix.ozg-sh.de"
} else {
return "!iQPAvQIiRwRpNOszjw:matrix.ozg-sh.de"
}
}
Void configureGit() {
def email = "jenkins@ozg-sh.de"
def name = "jenkins"
dir("gitops") {
sh "git config user.email '${email}'"
sh "git config user.name '${name}'"
}
}
Void cloneGitopsRepo() {
withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
sh 'git clone https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
}
configureGit()
}
Void setNewDevAntragsraumProxyVersion() {
setNewAntragsraumProxyGitopsVersion("dev")
}
Void setNewTestAntragsraumProxyVersion() {
setNewAntragsraumProxyGitopsVersion("test")
}
Void setNewAntragsraumProxyGitopsVersion(String environment) {
dir("gitops") {
def envFile = "${environment}/application/values/antragraum-proxy-values.yaml"
def envVersions = readYaml file: envFile
envVersions.antragsraum_proxy.image.tag = IMAGE_TAG
envVersions.antragsraum_proxy.helm.version = HELM_CHART_VERSION
writeYaml file: envFile, data: envVersions, overwrite: true
}
}
Void pushDevGitopsRepo() {
pushNewGitopsVersion('dev')
}
Void pushTestGitopsRepo() {
pushNewGitopsVersion('test')
}
Void pushNewGitopsVersion(String environment) {
dir('gitops') {
if (!hasAntragsraumProxyValuesFileChanged(environment)) {
return
}
withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
sh "git add ${environment}/application/values/antragraum-proxy-values.yaml"
sh "git commit -m 'jenkins rollout ${environment} antragsraum-proxy version ${IMAGE_TAG}'"
sh 'git push https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
}
}
}
Boolean hasAntragsraumProxyValuesFileChanged(String environment) {
return sh (script: "git status | grep '${environment}/application/values/antragraum-proxy-values.yaml'", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
}
Boolean isMasterBranch() {
return env.BRANCH_NAME == 'master'
}
Boolean isReleaseBranch() {
return env.BRANCH_NAME == 'release'
}
String generateHelmChartVersion() {
def chartVersion = "${env.APP_VERSION}"
if (isMasterBranch()) {
chartVersion += "-${env.GIT_COMMIT.take(7)}"
}
else if (!isReleaseBranch()) {
chartVersion += "-${env.BRANCH_NAME}"
}
return chartVersion.replaceAll("_", "-")
}
Void tagAndPushDockerImage(String imageName, String newTag){
withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'
sh "docker tag docker.ozg-sh.de/${imageName}:${env.APP_VERSION} docker.ozg-sh.de/${imageName}:${newTag}"
sh "docker push docker.ozg-sh.de/${imageName}:${newTag}"
}
}