Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ROX-20235: build collector-full on Konflux #1441

Merged
merged 124 commits into from
Feb 16, 2024
Merged
Show file tree
Hide file tree
Changes from 98 commits
Commits
Show all changes
124 commits
Select commit Hold shift + click to select a range
7ff08c8
add custom Dockerfile for rhtap
tommartensen Oct 16, 2023
1c6a49d
Red Hat Trusted App Pipeline update collector (#1367)
red-hat-konflux[bot] Oct 16, 2023
69200d7
RHTAP: fix workspace size for checkouts (#1368)
tommartensen Oct 16, 2023
7410e30
broken dnf installs
tommartensen Oct 17, 2023
4399cad
Update RHTAP references (#1375)
red-hat-konflux[bot] Oct 19, 2023
37b0c74
Update RHTAP references (#1378)
red-hat-konflux[bot] Oct 23, 2023
80d6c38
use centos instead of ubi images
tommartensen Oct 25, 2023
8cc0a9a
Merge branch 'tm/rhtap-onboarding' of github.com:stackrox/collector i…
tommartensen Oct 25, 2023
8b4d052
Update RHTAP references (#1387)
red-hat-konflux[bot] Nov 6, 2023
3a55302
Merge branch 'master' into tm/rhtap-onboarding
tommartensen Nov 6, 2023
6945989
update pipelines
tommartensen Nov 6, 2023
a1811d5
increase storage for shared volume in pipeline
tommartensen Nov 6, 2023
157b8d0
falco submodule
tommartensen Nov 6, 2023
b26118c
update TODOs and LABELs
tommartensen Nov 6, 2023
807015c
restore falco
tommartensen Nov 6, 2023
6ade98a
clean up
tommartensen Nov 9, 2023
0d4cef0
Red Hat Trusted App Pipeline update collector-slim (#1414)
red-hat-konflux[bot] Nov 9, 2023
1ea2eb2
rename collector -> collector-slim
tommartensen Nov 9, 2023
3db110e
finish up
tommartensen Nov 13, 2023
56abbd3
Merge branch 'master' into tm/rhtap-onboarding
tommartensen Nov 13, 2023
346e7a4
fix build after rebase
tommartensen Nov 13, 2023
49f6bcd
Update RHTAP references (#1415)
red-hat-konflux[bot] Nov 13, 2023
f4d9d03
more oomph
tommartensen Nov 13, 2023
4f2e97e
Merge branch 'tm/rhtap-onboarding' of github.com:stackrox/collector i…
tommartensen Nov 13, 2023
a225b95
Update RHTAP references (#1420)
red-hat-konflux[bot] Nov 14, 2023
a8c55ee
attempt with default buildah size
tommartensen Nov 14, 2023
4f41bb5
fix task ref
tommartensen Nov 14, 2023
7ec670a
Update RHTAP references (#1421)
red-hat-konflux[bot] Nov 14, 2023
3957e05
Update RHTAP references (#1422)
red-hat-konflux[bot] Nov 15, 2023
a7bff4d
RHTAP Onboarding: 2nd attempt (#1425)
tommartensen Nov 17, 2023
e2bf0b3
move dockerfile
tommartensen Nov 20, 2023
b1eea97
emptyg
tommartensen Nov 20, 2023
780e997
disable prefetch-input
tommartensen Nov 20, 2023
bb8cfa8
remove guard on prefetch-dependencies task
tommartensen Nov 20, 2023
f4512eb
clean up Dockerfile
tommartensen Nov 20, 2023
119ff0a
add CODEOWNERS
tommartensen Nov 20, 2023
4c57a27
Merge branch 'master' into tm/rhtap-onboarding
tommartensen Nov 21, 2023
156c0e1
rename Dockerfile for slim
tommartensen Nov 21, 2023
136c719
add Dockerfile
tommartensen Nov 21, 2023
19f4097
Red Hat Trusted App Pipeline update collector (#1440)
red-hat-konflux[bot] Nov 21, 2023
a927ae5
update pipelines with ACS settings
tommartensen Nov 21, 2023
9481e8d
download support packages
tommartensen Nov 21, 2023
095206f
add pipeline timeout override
tommartensen Nov 21, 2023
67d1366
.
tommartensen Nov 21, 2023
81e42c1
.
tommartensen Nov 21, 2023
765da8a
.
tommartensen Nov 22, 2023
124b2b0
Update RHTAP references (#1445)
red-hat-konflux[bot] Nov 27, 2023
6b393ab
Update RHTAP references (#1444)
red-hat-konflux[bot] Nov 27, 2023
3f5a901
Update .tekton/collector-slim-pull-request.yaml
tommartensen Nov 27, 2023
b867082
some recommendations from PR
tommartensen Nov 27, 2023
e3ea3cc
restrict pipeline for *rhtap* branches
tommartensen Nov 28, 2023
f62607e
cleanup
tommartensen Dec 4, 2023
ce0f293
Update RHTAP references (#1452)
red-hat-konflux[bot] Dec 4, 2023
fc214da
empty
tommartensen Dec 4, 2023
5adbce7
empty to check new pod limits
tommartensen Dec 4, 2023
9e2bcb1
Update RHTAP references (#1455)
red-hat-konflux[bot] Dec 5, 2023
ac2e9d8
empty commit
tommartensen Dec 5, 2023
8d41a38
test with CPU limits
tommartensen Dec 5, 2023
0710d12
Update RHTAP references (#1463)
red-hat-konflux[bot] Dec 6, 2023
b3d9d58
Update RHTAP references (#1451)
red-hat-konflux[bot] Dec 11, 2023
cc2fd34
Update RHTAP references (#1464)
red-hat-konflux[bot] Dec 11, 2023
7a5b8a1
Update RHTAP references (#1467)
red-hat-konflux[bot] Dec 12, 2023
05a86d4
update Dockerfile with midstream changes
tommartensen Dec 12, 2023
bc4405f
Merge branch 'tm/rhtap-onboarding' of github.com:stackrox/collector i…
tommartensen Dec 12, 2023
bda0de0
Apply suggestions from code review
tommartensen Dec 12, 2023
bc5cf90
Merge branch 'master' into tm/rhtap-onboarding
tommartensen Dec 12, 2023
d44cd27
Merge branch 'tm/rhtap-onboarding' of github.com:stackrox/collector i…
tommartensen Dec 12, 2023
fb4ded4
fix comment
tommartensen Dec 12, 2023
1541146
Update RHTAP references (#1471)
red-hat-konflux[bot] Dec 13, 2023
0fbf75f
setup Snyk for collector
tommartensen Dec 13, 2023
be05ea1
bump to get green RHTAP CI
tommartensen Dec 13, 2023
4801067
empty commit for retrigger
tommartensen Dec 14, 2023
27a21a1
update dockerfile
tommartensen Dec 14, 2023
cd82b6f
Merge branch 'tm/rhtap-onboarding' into tm/rhtap-full-collector
tommartensen Dec 14, 2023
0740eab
Merge branch 'master' into tm/rhtap-full-collector
tommartensen Jan 22, 2024
10ce270
update full collector image
tommartensen Jan 22, 2024
d105655
Update RHTAP references (tm/rhtap-full-collector) (#1468)
red-hat-konflux[bot] Jan 22, 2024
82f4b72
Merge branch 'master' into tm/rhtap-full-collector
tommartensen Jan 26, 2024
298ccf6
apply [d6d831d](https://github.com/stackrox/collector/commit/d6d831de…
tommartensen Jan 26, 2024
e790746
use drivers-build image as base for kernel-modules for all archs
tommartensen Jan 26, 2024
93d9e9e
fix?
tommartensen Jan 26, 2024
a11a6da
use RHTAP build image in integration tests
tommartensen Jan 26, 2024
44677f1
update image labels
tommartensen Jan 30, 2024
9eb749e
Update RHTAP references (#1527)
red-hat-konflux[bot] Feb 5, 2024
001d6ac
Update RHTAP references (#1530)
red-hat-konflux[bot] Feb 6, 2024
f668daa
use support packages again for x86 :/
tommartensen Feb 6, 2024
80df925
Merge branch 'tm/rhtap-full-collector' of github.com:stackrox/collect…
tommartensen Feb 6, 2024
bd0fe5c
Update RHTAP references (#1533)
red-hat-konflux[bot] Feb 7, 2024
a275600
clean up pre-review
tommartensen Feb 9, 2024
b9c172f
Merge branch 'tm/rhtap-full-collector' of github.com:stackrox/collect…
tommartensen Feb 9, 2024
65b2ca1
Merge branch 'master' into tm/rhtap-full-collector
tommartensen Feb 9, 2024
ff72a74
make shfmt happy
tommartensen Feb 9, 2024
915152f
also run for this branch
tommartensen Feb 9, 2024
ad0cd11
Update RHTAP references (#1534)
red-hat-konflux[bot] Feb 12, 2024
d689323
Merge branch 'master' into tm/rhtap-full-collector
tommartensen Feb 12, 2024
e162041
remove libinsp wrapper cleanup
tommartensen Feb 12, 2024
8930a66
bump support package version
tommartensen Feb 12, 2024
fc2d30d
update comment
tommartensen Feb 12, 2024
80a4142
Update collector/container/scripts/download-support-package.sh
tommartensen Feb 14, 2024
5c60d2a
Update collector/container/konflux.Dockerfile
tommartensen Feb 14, 2024
eea368d
Update collector/container/konflux.Dockerfile
tommartensen Feb 14, 2024
b1da270
remove timeout increase
tommartensen Feb 14, 2024
0c42fb3
fix comment: central-db -> collector
tommartensen Feb 14, 2024
4f11f1b
update tekton PipelineRun apiVersion to v1
tommartensen Feb 14, 2024
50e7f77
Update collector/container/konflux.Dockerfile
tommartensen Feb 14, 2024
6b32837
Update collector/container/konflux.Dockerfile
tommartensen Feb 14, 2024
eb379f8
Update collector/container/konflux.Dockerfile
tommartensen Feb 14, 2024
c7c67bb
Revert "remove timeout increase"
tommartensen Feb 14, 2024
109e35b
revert: add timeout 1h30m to pipelines
tommartensen Feb 14, 2024
90535d5
simplify conditional for checking if modules are extracted
tommartensen Feb 14, 2024
b688cac
move support package download to pipeline step
tommartensen Feb 14, 2024
0cde4ec
debug
tommartensen Feb 14, 2024
a9e8c02
chore(deps): update rhtap references (#1555)
red-hat-konflux[bot] Feb 15, 2024
7196c68
Update collector/container/scripts/download-support-package.sh
tommartensen Feb 15, 2024
e90c536
update JIRA link
tommartensen Feb 15, 2024
e1db3ed
clean up
tommartensen Feb 15, 2024
1abb618
add parameter for exposing clone-submodules
tommartensen Feb 15, 2024
2105aea
remove comment according to https://gitlab.cee.redhat.com/stackrox/rh…
tommartensen Feb 15, 2024
6f31794
update push pipeline
tommartensen Feb 15, 2024
53e797a
move cd to script
tommartensen Feb 15, 2024
8e4c170
do dir manipulation in script
tommartensen Feb 16, 2024
5be8033
fix path to the download script
tommartensen Feb 16, 2024
40e8fde
move module_version to parameter
tommartensen Feb 16, 2024
e334c3f
cosmetics
tommartensen Feb 16, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
391 changes: 391 additions & 0 deletions .tekton/collector-pull-request.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,391 @@
apiVersion: tekton.dev/v1beta1
msugakov marked this conversation as resolved.
Show resolved Hide resolved
kind: PipelineRun
msugakov marked this conversation as resolved.
Show resolved Hide resolved

metadata:
annotations:
build.appstudio.openshift.io/repo: https://github.com/stackrox/collector?rev={{revision}}
build.appstudio.redhat.com/commit_sha: '{{revision}}'
build.appstudio.redhat.com/pull_request_number: '{{pull_request_number}}'
build.appstudio.redhat.com/target_branch: '{{target_branch}}'
pipelinesascode.tekton.dev/max-keep-runs: "500"
# TODO(ROX-21073): re-enable for all PR branches
pipelinesascode.tekton.dev/on-cel-expression: event == "pull_request" && (source_branch.contains("rhtap") || source_branch.contains("konflux"))
creationTimestamp: null
labels:
appstudio.openshift.io/application: acs
appstudio.openshift.io/component: collector
pipelines.appstudio.openshift.io/type: build
name: collector-on-pull-request
namespace: rh-acs-tenant

spec:

params:
- name: dockerfile
value: collector/container/konflux.Dockerfile
- name: git-url
value: '{{repo_url}}'
- name: image-expires-after
value: '13w'
- name: output-image
value: quay.io/redhat-user-workloads/rh-acs-tenant/acs/collector:on-pr-{{revision}}
- name: path-context
value: .
- name: revision
value: '{{revision}}'
- name: rebuild
value: 'true'
# TODO(ROX-20234): Enable hermetic builds
# - name: hermetic
# value: "true"
# No language dependencies are required for central-db image.
msugakov marked this conversation as resolved.
Show resolved Hide resolved
- name: prefetch-input
value: ''

workspaces:
- name: workspace
volumeClaimTemplate:
metadata:
creationTimestamp: null
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
status: { }
- name: git-auth
secret:
secretName: '{{ git_auth_secret }}'

timeouts:
pipeline: 1h30m0s
msugakov marked this conversation as resolved.
Show resolved Hide resolved

pipelineSpec:

finally:
- name: show-sbom
params:
- name: IMAGE_URL
value: $(tasks.build-container.results.IMAGE_URL)
taskRef:
params:
- name: name
value: show-sbom
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-show-sbom:0.1@sha256:82737c8d365c620295fa526d21a481d4614f657800175ddc0ccd7846c54207f8
- name: kind
value: task
resolver: bundles
- name: show-summary
params:
- name: pipelinerun-name
value: $(context.pipelineRun.name)
- name: git-url
value: $(tasks.clone-repository.results.url)?rev=$(tasks.clone-repository.results.commit)
- name: image-url
value: $(params.output-image)
- name: build-task-status
value: $(tasks.build-container.status)
taskRef:
params:
- name: name
value: summary
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-summary:0.1@sha256:29a64be421fdc203cb26c61b746c650e239ae924a73a825ad93bffb9e7ae7214
- name: kind
value: task
resolver: bundles
params:
- description: Source Repository URL
name: git-url
type: string
- default: ""
description: Revision of the Source Repository
name: revision
type: string
- description: Fully Qualified Output Image
name: output-image
type: string
- default: .
description: Path to the source code of an application's component from where
to build image.
name: path-context
type: string
- default: Dockerfile
description: Path to the Dockerfile inside the context specified by parameter
path-context
name: dockerfile
type: string
- default: "false"
description: Force rebuild image
name: rebuild
type: string
- default: "false"
description: Skip checks against built image
name: skip-checks
type: string
- default: "false"
description: Execute the build with network isolation
name: hermetic
type: string
- default: ""
description: Build dependencies to be prefetched by Cachi2
name: prefetch-input
type: string
- default: "false"
description: Java build
name: java
type: string
- default: ""
description: Image tag expiration time, time values could be something like
1h, 2d, 3w for hours, days, and weeks, respectively.
name: image-expires-after
results:
- description: ""
name: IMAGE_URL
value: $(tasks.build-container.results.IMAGE_URL)
- description: ""
name: IMAGE_DIGEST
value: $(tasks.build-container.results.IMAGE_DIGEST)
- description: ""
name: CHAINS-GIT_URL
value: $(tasks.clone-repository.results.url)
- description: ""
name: CHAINS-GIT_COMMIT
value: $(tasks.clone-repository.results.commit)
- description: ""
name: JAVA_COMMUNITY_DEPENDENCIES
value: $(tasks.build-container.results.JAVA_COMMUNITY_DEPENDENCIES)

workspaces:
- name: workspace
- name: git-auth

tasks:

- name: init
params:
- name: image-url
value: $(params.output-image)
- name: rebuild
value: $(params.rebuild)
taskRef:
params:
- name: name
value: init
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-init:0.2@sha256:3d8f01fa59596a998d30dc700fcf7377f09d60008337290eebaeaf604512ce2b
- name: kind
value: task
resolver: bundles
- name: clone-repository
params:
- name: url
value: $(params.git-url)
- name: revision
value: $(params.revision)
runAfter:
- init
taskRef:
params:
- name: name
value: git-clone
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-git-clone:0.1@sha256:e13f6e9145b876e858d115abac1dc47fb3df891fcf10e8894672958372bd37dd
- name: kind
value: task
resolver: bundles
when:
- input: $(tasks.init.results.build)
operator: in
values: [ "true" ]
workspaces:
- name: output
workspace: workspace
- name: basic-auth
workspace: git-auth
- name: prefetch-dependencies
params:
- name: input
value: $(params.prefetch-input)
runAfter:
- clone-repository
taskRef:
params:
- name: name
value: prefetch-dependencies
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-prefetch-dependencies:0.1@sha256:a0d054aa0f37a3a094cf69ce266a874afbb97522ea62975f0af6ccdbf18caee4
- name: kind
value: task
resolver: bundles
workspaces:
- name: source
workspace: workspace

- name: build-container
params:
- name: IMAGE
value: $(params.output-image)
- name: DOCKERFILE
value: $(params.dockerfile)
- name: CONTEXT
value: $(params.path-context)
- name: HERMETIC
value: $(params.hermetic)
- name: PREFETCH_INPUT
value: $(params.prefetch-input)
- name: IMAGE_EXPIRES_AFTER
value: $(params.image-expires-after)
- name: COMMIT_SHA
value: $(tasks.clone-repository.results.commit)
runAfter:
- prefetch-dependencies
taskRef:
params:
- name: name
value: buildah
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-buildah:0.1@sha256:163009699fca1c5c043516d84986b44f8b6ef25418c97eed51d12518a94d552e
- name: kind
value: task
resolver: bundles
when:
- input: $(tasks.init.results.build)
operator: in
values: [ "true" ]
workspaces:
- name: source
workspace: workspace

- name: inspect-image
params:
- name: IMAGE_URL
value: $(tasks.build-container.results.IMAGE_URL)
- name: IMAGE_DIGEST
value: $(tasks.build-container.results.IMAGE_DIGEST)
runAfter:
- build-container
taskRef:
params:
- name: name
value: inspect-image
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-inspect-image:0.1@sha256:6a9fff4f7485728ebb0dd3f0572a7aedc1e330f588463102ee6bb3182cd24aab
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values: [ "false" ]
workspaces:
- name: source
workspace: workspace

- name: deprecated-base-image-check
params:
- name: BASE_IMAGES_DIGESTS
value: $(tasks.build-container.results.BASE_IMAGES_DIGESTS)
taskRef:
params:
- name: name
value: deprecated-image-check
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-deprecated-image-check:0.3@sha256:d862972471dca80900bbe3a0fbd579cc84e8414bafbd5021bc684b207067c423
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values: [ "false" ]

- name: clair-scan
params:
- name: image-digest
value: $(tasks.build-container.results.IMAGE_DIGEST)
- name: image-url
value: $(tasks.build-container.results.IMAGE_URL)
runAfter:
- build-container
taskRef:
params:
- name: name
value: clair-scan
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-clair-scan:0.1@sha256:cfd4a8350b12900345f341171b3fafe9b1f5eb5eeb6aa773bfb1e88ab99cff4a
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values: [ "false" ]

- name: sast-snyk-check
runAfter:
- clone-repository
taskRef:
params:
- name: name
value: sast-snyk-check
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-sast-snyk-check:0.1@sha256:b3ff528f60b1d1239dc3dd5de89e553364899823220de3db7fdaf696c3288977
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values: [ "false" ]
workspaces:
- name: workspace
workspace: workspace

- name: clamav-scan
params:
- name: image-digest
value: $(tasks.build-container.results.IMAGE_DIGEST)
- name: image-url
value: $(tasks.build-container.results.IMAGE_URL)
runAfter:
- build-container
taskRef:
params:
- name: name
value: clamav-scan
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-clamav-scan:0.1@sha256:429e630d8a9a4f268db52daf4971b08783ebefd20fd2770d27cf75218b6500ba
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values: [ "false" ]

- name: sbom-json-check
params:
- name: IMAGE_URL
value: $(tasks.build-container.results.IMAGE_URL)
- name: IMAGE_DIGEST
value: $(tasks.build-container.results.IMAGE_DIGEST)
runAfter:
- build-container
taskRef:
params:
- name: name
value: sbom-json-check
- name: bundle
value: quay.io/redhat-appstudio-tekton-catalog/task-sbom-json-check:0.1@sha256:9f803c95f59faa75a87b6548506d5aa0df8368e937d40d696e863a0d46be0937
- name: kind
value: task
resolver: bundles
when:
- input: $(params.skip-checks)
operator: in
values: [ "false" ]

status: { }
Loading
Loading