You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

.cirrus.yml 24KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735
  1. env:
  2. GRADLE_OPTS: -Dorg.gradle.jvmargs="-XX:+PrintFlagsFinal -XshowSettings:vm -XX:+HeapDumpOnOutOfMemoryError -XX:+UnlockExperimentalVMOptions -Djava.security.egd=file:/dev/./urandom -Dfile.encoding=UTF8 -Duser.language=en -Duser.country=US"
  3. # to be replaced by other credentials
  4. ARTIFACTORY_PRIVATE_USERNAME: vault-${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader
  5. ARTIFACTORY_PRIVATE_PASSWORD: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader access_token]
  6. ARTIFACTORY_DEPLOY_USERNAME: vault-${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-qa-deployer
  7. ARTIFACTORY_DEPLOY_PASSWORD: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-qa-deployer access_token]
  8. ARTIFACTORY_ACCESS_TOKEN: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader access_token]
  9. ARTIFACTORY_PROMOTE_ACCESS_TOKEN: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-promoter access_token]
  10. # download licenses for testing commercial editions
  11. GITHUB_TOKEN: VAULT[development/github/token/licenses-ro token]
  12. # notifications to burgr
  13. BURGR_URL: VAULT[development/kv/data/burgr data.url]
  14. BURGR_USERNAME: VAULT[development/kv/data/burgr data.cirrus_username]
  15. BURGR_PASSWORD: VAULT[development/kv/data/burgr data.cirrus_password]
  16. # analysis on next.sonarqube.com
  17. SONARQUBE_NEXT_TOKEN: VAULT[development/kv/data/next data.token]
  18. # to trigger docs deployment
  19. ELASTIC_PWD: VAULT[development/team/sonarqube/kv/data/elasticsearch-cloud data.password]
  20. CIRRUS_LOG_TIMESTAMP: true
  21. BRANCH_MAIN: "master"
  22. BRANCH_NIGHTLY: "branch-nightly-build"
  23. BRANCH_PATTERN_MAINTENANCE: "branch-.*"
  24. BRANCH_PATTERN_PUBLIC: "public_.*"
  25. auto_cancellation: $CIRRUS_BRANCH != $BRANCH_MAIN && $CIRRUS_BRANCH !=~ $BRANCH_PATTERN_MAINTENANCE
  26. skip_public_branches_template: &SKIP_PUBLIC_BRANCHES_TEMPLATE
  27. skip: $CIRRUS_BRANCH =~ $BRANCH_PATTERN_PUBLIC
  28. build_dependant_task_template: &BUILD_DEPENDANT_TASK_TEMPLATE
  29. depends_on: build
  30. nightly_task_template: &NIGHTLY_TASK_TEMPLATE
  31. only_if: $CIRRUS_BRANCH == $BRANCH_NIGHTLY
  32. master_and_nightly_task_template: &MASTER_AND_NIGHTLY_TASK_TEMPLATE
  33. only_if: $CIRRUS_BRANCH == $BRANCH_NIGHTLY || $CIRRUS_BRANCH == $BRANCH_MAIN
  34. master_or_nightly_or_maintenance_task_template: &MASTER_OR_NIGHTLY_OR_MAINTENANCE_TASK_TEMPLATE
  35. only_if: $CIRRUS_BRANCH == $BRANCH_NIGHTLY || $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE
  36. except_nightly_task_template: &EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  37. only_if: $CIRRUS_BRANCH != $BRANCH_NIGHTLY
  38. database_related_task_template: &DATABASE_RELATED_TASK_TEMPLATE
  39. only_if: >-
  40. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  41. changesInclude('server/sonar-db-dao/**/*Mapper.xml', 'server/sonar-db-migration/**/DbVersion*.java', 'server/sonar-db-dao/**/*Dao.java', 'server/sonar-db-core/src/main/java/org/sonar/db/*.java')
  42. saml_task_template: &SAML_TASK_TEMPLATE
  43. only_if: >-
  44. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  45. changesInclude('server/sonar-auth-saml/src/main/java/**/*.java', 'server/sonar-auth-saml/src/main/resources/**/*', 'server/sonar-db-dao/src/main/**/SAML*.java', 'private/it-core/src/test/java/org/sonarqube/tests/saml/*.java', 'server/sonar-webserver-webapi/src/main/java/org/sonar/server/saml/**/*.java')
  46. ldap_task_template: &LDAP_TASK_TEMPLATE
  47. only_if: >-
  48. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  49. changesInclude('server/sonar-auth-ldap/src/main/java/**/*.java', 'server/sonar-webserver-auth/src/main/java/org/sonar/server/authentication/LdapCredentialsAuthentication.java', 'private/it-core/src/test/java/org/sonarqube/tests/ldap/*.java')
  50. github_task_template: &GITHUB_TASK_TEMPLATE
  51. only_if: >-
  52. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  53. changesInclude('private/core-extension-developer-server/src/main/java/com/sonarsource/branch/pr/github/*.java', 'private/it-branch/it-tests/src/test/java/com/sonarsource/branch/it/suite/pr/github/*.java')
  54. docker_build_container_template: &CONTAINER_TEMPLATE
  55. region: eu-central-1
  56. cluster_name: ${CIRRUS_CLUSTER_NAME}
  57. namespace: default
  58. builder_subnet_id: ${CIRRUS_AWS_SUBNET}
  59. builder_role: cirrus-builder
  60. builder_image: docker-builder-v*
  61. builder_instance_type: t2.small
  62. dockerfile: private/docker/Dockerfile-build
  63. docker_arguments:
  64. CIRRUS_AWS_ACCOUNT: ${CIRRUS_AWS_ACCOUNT}
  65. cpu: 1
  66. memory: 2Gb
  67. vm_instance_template: &VM_TEMPLATE
  68. experimental: true # see https://github.com/cirruslabs/cirrus-ci-docs/issues/1051
  69. image: docker-builder-v*
  70. type: t2.small
  71. region: eu-central-1
  72. subnet_id: ${CIRRUS_AWS_SUBNET}
  73. disk: 10
  74. cpu: 4
  75. memory: 8G
  76. oracle_additional_container_template: &ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  77. name: oracle
  78. image: gvenzl/oracle-xe:21-faststart
  79. port: 1521
  80. cpu: 2
  81. memory: 5Gb
  82. env:
  83. ORACLE_PASSWORD: sonarqube
  84. APP_USER: sonarqube
  85. APP_USER_PASSWORD: sonarqube
  86. postgres_additional_container_template: &POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  87. name: postgres
  88. image: public.ecr.aws/docker/library/postgres:15
  89. port: 5432
  90. cpu: 1
  91. memory: 1Gb
  92. env:
  93. POSTGRES_USER: postgres
  94. POSTGRES_PASSWORD: postgres
  95. default_artifact_template: &DEFAULT_ARTIFACTS_TEMPLATE
  96. on_failure:
  97. jest_junit_cleanup_script: >
  98. find . -type f -wholename "**/build/test-results/test-jest/junit.xml" -exec
  99. xmlstarlet edit --inplace --delete '//testsuite[@errors=0 and @failures=0]' {} \;
  100. junit_artifacts:
  101. path: "**/build/test-results/**/*.xml"
  102. type: "text/xml"
  103. format: junit
  104. reports_artifacts:
  105. path: "**/build/reports/**/*"
  106. screenshots_artifacts:
  107. path: "**/build/screenshots/**/*"
  108. always:
  109. profile_artifacts:
  110. path: "**/build/reports/profile/**/*"
  111. yarn_cache_template: &YARN_CACHE_TEMPLATE
  112. yarn_cache:
  113. folder: "~/.yarn/berry/cache"
  114. fingerprint_script: |
  115. cat \
  116. server/sonar-web/yarn.lock \
  117. private/core-extension-developer-server/yarn.lock \
  118. private/core-extension-enterprise-server/yarn.lock \
  119. private/core-extension-license/yarn.lock \
  120. private/core-extension-securityreport/yarn.lock
  121. gradle_cache_template: &GRADLE_CACHE_TEMPLATE
  122. gradle_cache:
  123. folder: "~/.gradle/caches"
  124. fingerprint_script: find -type f \( -name "*.gradle*" -or -name "gradle*.properties" \) -exec cat {} +
  125. jar_cache_template: &JAR_CACHE_TEMPLATE
  126. jar_cache:
  127. folder: "**/build/libs/*.jar"
  128. fingerprint_key: jar-cache_$CIRRUS_BUILD_ID
  129. eslint_report_cache_template: &ESLINT_REPORT_CACHE_TEMPLATE
  130. eslint_report_cache:
  131. folders:
  132. - server/sonar-web/eslint-report/
  133. - server/sonar-web/design-system/eslint-report/
  134. - private/core-extension-securityreport/eslint-report/
  135. - private/core-extension-license/eslint-report/
  136. - private/core-extension-enterprise-server/eslint-report/
  137. - private/core-extension-developer-server/eslint-report/
  138. fingerprint_script: echo $CIRRUS_BUILD_ID
  139. jest_report_cache_template: &JEST_REPORT_CACHE_TEMPLATE
  140. jest_report_cache:
  141. folders:
  142. - server/sonar-web/coverage/
  143. - server/sonar-web/design-system/coverage/
  144. - private/core-extension-securityreport/coverage/
  145. - private/core-extension-license/coverage/
  146. - private/core-extension-enterprise-server/coverage/
  147. - private/core-extension-developer-server/coverage/
  148. fingerprint_script: echo $CIRRUS_BUILD_ID
  149. junit_report_cache_template: &JUNIT_REPORT_CACHE_TEMPLATE
  150. junit_report_cache:
  151. folders:
  152. - "**/reports/jacoco"
  153. - "**/test-results/test"
  154. fingerprint_script: echo $CIRRUS_BUILD_ID
  155. default_template: &DEFAULT_TEMPLATE
  156. <<: *SKIP_PUBLIC_BRANCHES_TEMPLATE
  157. clone_script: |
  158. git init
  159. git remote add origin https://x-access-token:${CIRRUS_REPO_CLONE_TOKEN}@github.com/${CIRRUS_REPO_FULL_NAME}.git
  160. git fetch origin $CIRRUS_CHANGE_IN_REPO $FETCH_DEPTH
  161. git reset --hard $CIRRUS_CHANGE_IN_REPO
  162. env:
  163. FETCH_DEPTH: --depth=1
  164. build_task:
  165. <<: *DEFAULT_TEMPLATE
  166. <<: *GRADLE_CACHE_TEMPLATE
  167. <<: *YARN_CACHE_TEMPLATE
  168. <<: *JAR_CACHE_TEMPLATE
  169. eks_container:
  170. <<: *CONTAINER_TEMPLATE
  171. cpu: 7.5
  172. memory: 8Gb
  173. elasticsearch_distribution_cache:
  174. folder: sonar-application/build/elasticsearch-**.tar.gz
  175. script:
  176. - ./private/cirrus/cirrus-build.sh
  177. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  178. publish_task:
  179. <<: *DEFAULT_TEMPLATE
  180. <<: *GRADLE_CACHE_TEMPLATE
  181. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  182. eks_container:
  183. <<: *CONTAINER_TEMPLATE
  184. cpu: 4
  185. memory: 4Gb
  186. env:
  187. ORG_GRADLE_PROJECT_signingKey: VAULT[development/kv/data/sign data.key]
  188. ORG_GRADLE_PROJECT_signingPassword: VAULT[development/kv/data/sign data.passphrase]
  189. ORG_GRADLE_PROJECT_signingKeyId: VAULT[development/kv/data/sign data.key_id]
  190. script:
  191. - ./private/cirrus/cirrus-publish.sh
  192. yarn_lint_task:
  193. <<: *DEFAULT_TEMPLATE
  194. <<: *GRADLE_CACHE_TEMPLATE
  195. <<: *YARN_CACHE_TEMPLATE
  196. <<: *ESLINT_REPORT_CACHE_TEMPLATE
  197. eks_container:
  198. <<: *CONTAINER_TEMPLATE
  199. cpu: 3
  200. memory: 6Gb
  201. script:
  202. - ./private/cirrus/cirrus-yarn-lint-report.sh
  203. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  204. yarn_check_task:
  205. <<: *DEFAULT_TEMPLATE
  206. <<: *GRADLE_CACHE_TEMPLATE
  207. <<: *YARN_CACHE_TEMPLATE
  208. eks_container:
  209. <<: *CONTAINER_TEMPLATE
  210. cpu: 3
  211. memory: 4Gb
  212. script: |
  213. ./private/cirrus/cirrus-env.sh YARN
  214. gradle yarn_check-ci --profile
  215. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  216. yarn_validate_task:
  217. <<: *DEFAULT_TEMPLATE
  218. <<: *GRADLE_CACHE_TEMPLATE
  219. <<: *YARN_CACHE_TEMPLATE
  220. <<: *JEST_REPORT_CACHE_TEMPLATE
  221. eks_container:
  222. <<: *CONTAINER_TEMPLATE
  223. cpu: 7.5
  224. memory: 20Gb
  225. script:
  226. - ./private/cirrus/cirrus-yarn-validate-ci.sh
  227. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  228. junit_task:
  229. <<: *DEFAULT_TEMPLATE
  230. <<: *GRADLE_CACHE_TEMPLATE
  231. <<: *JUNIT_REPORT_CACHE_TEMPLATE
  232. eks_container:
  233. <<: *CONTAINER_TEMPLATE
  234. cpu: 7.5
  235. memory: 10Gb
  236. script:
  237. - ./private/cirrus/cirrus-junit.sh
  238. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  239. sq_analysis_task:
  240. <<: *SKIP_PUBLIC_BRANCHES_TEMPLATE
  241. <<: *EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  242. <<: *GRADLE_CACHE_TEMPLATE
  243. <<: *YARN_CACHE_TEMPLATE
  244. <<: *JEST_REPORT_CACHE_TEMPLATE
  245. <<: *ESLINT_REPORT_CACHE_TEMPLATE
  246. <<: *JUNIT_REPORT_CACHE_TEMPLATE
  247. depends_on:
  248. - yarn_validate
  249. - yarn_lint
  250. - junit
  251. eks_container:
  252. <<: *CONTAINER_TEMPLATE
  253. cpu: 7.5
  254. memory: 15Gb
  255. script:
  256. - ./private/cirrus/cirrus-sq-analysis.sh
  257. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  258. qa_task:
  259. <<: *DEFAULT_TEMPLATE
  260. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  261. <<: *GRADLE_CACHE_TEMPLATE
  262. <<: *JAR_CACHE_TEMPLATE
  263. eks_container:
  264. <<: *CONTAINER_TEMPLATE
  265. cpu: 3
  266. memory: 7Gb
  267. additional_containers:
  268. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  269. name: QA $QA_CATEGORY
  270. alias: qa
  271. env:
  272. matrix:
  273. # QA name should not exceed 13 characters to be properly reported on wallboard by burgr
  274. # QA name cannot contain "_"
  275. - QA_CATEGORY: Cat1
  276. - QA_CATEGORY: Cat2
  277. - QA_CATEGORY: Cat3
  278. - QA_CATEGORY: Cat4
  279. - QA_CATEGORY: Cat5
  280. - QA_CATEGORY: Cat6
  281. - QA_CATEGORY: Analysis
  282. - QA_CATEGORY: Authorization
  283. - QA_CATEGORY: Auth
  284. - QA_CATEGORY: Branch1
  285. - QA_CATEGORY: Branch2
  286. - QA_CATEGORY: CE1
  287. - QA_CATEGORY: CE2
  288. - QA_CATEGORY: ComputeEngine
  289. - QA_CATEGORY: DE1
  290. - QA_CATEGORY: DE2
  291. - QA_CATEGORY: EE1
  292. - QA_CATEGORY: EE2
  293. - QA_CATEGORY: Issues1
  294. - QA_CATEGORY: Issues2
  295. - QA_CATEGORY: License1
  296. - QA_CATEGORY: License2
  297. - QA_CATEGORY: Plugins
  298. - QA_CATEGORY: Project
  299. - QA_CATEGORY: QP
  300. - QA_CATEGORY: Upgrade
  301. script:
  302. - ./private/cirrus/cirrus-qa.sh postgres
  303. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  304. task: #bitbucket
  305. <<: *DEFAULT_TEMPLATE
  306. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  307. <<: *JAR_CACHE_TEMPLATE
  308. <<: *GRADLE_CACHE_TEMPLATE
  309. eks_container:
  310. <<: *CONTAINER_TEMPLATE
  311. cpu: 3
  312. memory: 10Gb
  313. additional_containers:
  314. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  315. maven_cache:
  316. folder: ~/.m2
  317. env:
  318. QA_CATEGORY: BITBUCKET
  319. matrix:
  320. - name: qa_bb_5.15.0
  321. bitbucket_background_script: ./private/cirrus/cirrus-start-bitbucket.sh 5.15.0
  322. - name: qa_bb_latest
  323. bitbucket_background_script: ./private/cirrus/cirrus-start-bitbucket.sh LATEST
  324. wait_for_bitbucket_to_boot_script: secs=3600; endTime=$(( $(date +%s) + secs )); while [[ "$(curl -s -o /dev/null -w ''%{http_code}'' localhost:7990/bitbucket/status)" != "200" ]] || [ $(date +%s) -gt $endTime ]; do sleep 5; done
  325. script:
  326. - ./private/cirrus/cirrus-qa.sh postgres
  327. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  328. qa_bb_cloud_task:
  329. <<: *DEFAULT_TEMPLATE
  330. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  331. <<: *JAR_CACHE_TEMPLATE
  332. <<: *GRADLE_CACHE_TEMPLATE
  333. eks_container:
  334. <<: *CONTAINER_TEMPLATE
  335. cpu: 2.4
  336. memory: 7Gb
  337. env:
  338. QA_CATEGORY: BITBUCKET_CLOUD
  339. BBC_CLIENT_ID: VAULT[development/team/sonarqube/kv/data/bitbucket-cloud data.client_id]
  340. BBC_CLIENT_SECRET: VAULT[development/team/sonarqube/kv/data/bitbucket-cloud data.client_secret]
  341. BBC_USERNAME: VAULT[development/kv/data/bitbucket/sonarqube-its data.username]
  342. BBC_READ_REPOS_APP_PASSWORD: VAULT[development/kv/data/bitbucket/sonarqube-its data.password]
  343. script:
  344. - ./private/cirrus/cirrus-qa.sh h2
  345. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  346. qa_ha_task:
  347. <<: *DEFAULT_TEMPLATE
  348. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  349. <<: *MASTER_OR_NIGHTLY_OR_MAINTENANCE_TASK_TEMPLATE
  350. <<: *JAR_CACHE_TEMPLATE
  351. <<: *GRADLE_CACHE_TEMPLATE
  352. eks_container:
  353. <<: *CONTAINER_TEMPLATE
  354. cpu: 2.4
  355. memory: 10Gb
  356. additional_containers:
  357. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  358. env:
  359. QA_CATEGORY: HA
  360. script:
  361. - ./private/cirrus/cirrus-qa.sh postgres
  362. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  363. qa_performance_task:
  364. <<: *DEFAULT_TEMPLATE
  365. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  366. <<: *MASTER_AND_NIGHTLY_TASK_TEMPLATE
  367. <<: *JAR_CACHE_TEMPLATE
  368. <<: *GRADLE_CACHE_TEMPLATE
  369. eks_container:
  370. <<: *CONTAINER_TEMPLATE
  371. cpu: 2.4
  372. memory: 10Gb
  373. additional_containers:
  374. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  375. env:
  376. QA_CATEGORY: AnalysisPerformance
  377. script:
  378. - ./private/cirrus/cirrus-qa.sh postgres
  379. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  380. # GitLab QA is executed in a dedicated task in order to not slow down the pipeline, as a GitLab on-prem server docker image is required.
  381. qa_gitlab_task:
  382. <<: *DEFAULT_TEMPLATE
  383. <<: *JAR_CACHE_TEMPLATE
  384. <<: *GRADLE_CACHE_TEMPLATE
  385. depends_on:
  386. - build
  387. env:
  388. QA_CATEGORY: GITLAB
  389. matrix:
  390. - name: qa_gitlab_latest
  391. env:
  392. - GITLAB_VERSION: latest
  393. - name: qa_gitlab_oldest
  394. env:
  395. - GITLAB_VERSION: 15.6.2-ce.0
  396. eks_container:
  397. <<: *CONTAINER_TEMPLATE
  398. cpu: 2.4
  399. memory: 7Gb
  400. use_in_memory_disk: true
  401. additional_containers:
  402. - name: gitlab
  403. ports:
  404. - 80
  405. - 443
  406. cpu: 2
  407. memory: 5Gb
  408. image: ${CIRRUS_AWS_ACCOUNT}.dkr.ecr.eu-central-1.amazonaws.com/gitlab:${GITLAB_VERSION}
  409. env:
  410. - GITLAB_POST_RECONFIGURE_SCRIPT: |-
  411. { cat >/tmp/setup.rb <<-'EOF'
  412. token = User.find_by_username('root').personal_access_tokens.create(scopes: [:api], name: 'token');
  413. token.set_token('token-here-456');
  414. token.save!;
  415. token_read = User.find_by_username('root').personal_access_tokens.create(scopes: [:read_user], name: 'token_read');
  416. token_read.set_token('token-read-123');
  417. token_read.save!;
  418. user = User.find_by_username('root');
  419. user.password = 'eng-YTU1ydh6kyt7tjd';
  420. user.password_confirmation = 'eng-YTU1ydh6kyt7tjd';
  421. user.save!;
  422. EOF
  423. } && gitlab-rails runner /tmp/setup.rb && \
  424. echo 'from_file "/etc/gitlab/external_gitlab.rb"' >> /etc/gitlab/gitlab.rb && \
  425. gitlab-ctl reconfigure
  426. script:
  427. - ./private/cirrus/cirrus-qa.sh h2
  428. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  429. qa_gitlab_cloud_task:
  430. <<: *DEFAULT_TEMPLATE
  431. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  432. <<: *JAR_CACHE_TEMPLATE
  433. <<: *GRADLE_CACHE_TEMPLATE
  434. eks_container:
  435. <<: *CONTAINER_TEMPLATE
  436. cpu: 2.4
  437. memory: 7Gb
  438. use_in_memory_disk: true
  439. env:
  440. QA_CATEGORY: GITLAB_CLOUD
  441. GITLAB_API_TOKEN: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.api_token]
  442. GITLAB_READ_ONLY_TOKEN: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.api_token_ro]
  443. GITLAB_ADMIN_USERNAME: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.username]
  444. GITLAB_ADMIN_PASSWORD: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.password]
  445. script:
  446. - ./private/cirrus/cirrus-qa.sh h2
  447. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  448. # Azure QA is executed in a dedicated task in order to not slow down the pipeline.
  449. qa_azure_task:
  450. <<: *DEFAULT_TEMPLATE
  451. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  452. <<: *JAR_CACHE_TEMPLATE
  453. <<: *GRADLE_CACHE_TEMPLATE
  454. eks_container:
  455. <<: *CONTAINER_TEMPLATE
  456. cpu: 2.4
  457. memory: 7Gb
  458. env:
  459. QA_CATEGORY: AZURE
  460. AZURE_USERNAME_LOGIN: VAULT[development/team/sonarqube/kv/data/azure-instance data.username]
  461. AZURE_CODE_READ_AND_WRITE_TOKEN: VAULT[development/team/sonarqube/kv/data/azure-instance data.token_code_read_write]
  462. AZURE_FULL_ACCESS_TOKEN: VAULT[development/team/sonarqube/kv/data/azure-instance data.token_full_access]
  463. script:
  464. - ./private/cirrus/cirrus-qa.sh h2
  465. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  466. qa_github_task:
  467. <<: *DEFAULT_TEMPLATE
  468. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  469. <<: *GITHUB_TASK_TEMPLATE
  470. <<: *JAR_CACHE_TEMPLATE
  471. <<: *GRADLE_CACHE_TEMPLATE
  472. eks_container:
  473. <<: *CONTAINER_TEMPLATE
  474. cpu: 2.4
  475. memory: 7Gb
  476. env:
  477. QA_CATEGORY: GITHUB
  478. GITHUB_COM_CODE_SCANNING_ALERTS_TECHNICAL_USER_USERNAME: QA-task
  479. GITHUB_COM_CODE_SCANNING_ALERTS_TECHNICAL_USER_TOKEN: VAULT[development/github/token/SonarSource-sonar-enterprise-code-scanning token]
  480. script:
  481. - ./private/cirrus/cirrus-qa.sh h2
  482. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  483. # SAML QA is executed in a dedicated task in order to not slow down the pipeline, as a Keycloak server docker image is required.
  484. qa_saml_task:
  485. <<: *DEFAULT_TEMPLATE
  486. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  487. <<: *SAML_TASK_TEMPLATE
  488. <<: *JAR_CACHE_TEMPLATE
  489. <<: *GRADLE_CACHE_TEMPLATE
  490. eks_container:
  491. <<: *CONTAINER_TEMPLATE
  492. cpu: 2.4
  493. memory: 10Gb
  494. additional_containers:
  495. - name: keycloak
  496. image: quay.io/keycloak/keycloak:21.0.2
  497. port: 8080
  498. cpu: 1
  499. memory: 1Gb
  500. command: "/opt/keycloak/bin/kc.sh start-dev --http-relative-path /auth"
  501. env:
  502. KEYCLOAK_ADMIN: admin
  503. KEYCLOAK_ADMIN_PASSWORD: admin
  504. env:
  505. QA_CATEGORY: SAML
  506. script:
  507. - ./private/cirrus/cirrus-qa.sh h2
  508. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  509. # LDAP QA is executed in a dedicated task in order to not slow down the pipeline, as a LDAP server and SonarQube server are re-started on each test.
  510. qa_ldap_task:
  511. <<: *DEFAULT_TEMPLATE
  512. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  513. <<: *LDAP_TASK_TEMPLATE
  514. <<: *JAR_CACHE_TEMPLATE
  515. <<: *GRADLE_CACHE_TEMPLATE
  516. eks_container:
  517. <<: *CONTAINER_TEMPLATE
  518. cpu: 2.4
  519. memory: 10Gb
  520. env:
  521. QA_CATEGORY: LDAP
  522. script:
  523. - ./private/cirrus/cirrus-qa.sh h2
  524. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  525. promote_task:
  526. <<: *DEFAULT_TEMPLATE
  527. <<: *EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  528. depends_on:
  529. - build
  530. - sq_analysis
  531. - qa
  532. - qa_saml
  533. - qa_ldap
  534. - publish
  535. eks_container:
  536. <<: *CONTAINER_TEMPLATE
  537. memory: 512M
  538. stateful: true
  539. script:
  540. - ./private/cirrus/cirrus-promote.sh
  541. package_docker_task:
  542. <<: *DEFAULT_TEMPLATE
  543. depends_on: promote
  544. only_if: $CIRRUS_BRANCH == $BRANCH_MAIN
  545. ec2_instance:
  546. <<: *VM_TEMPLATE
  547. clone_script: |
  548. git clone --recursive --branch=$CIRRUS_BRANCH https://x-access-token:${CIRRUS_REPO_CLONE_TOKEN}@github.com/${CIRRUS_REPO_FULL_NAME}.git $CIRRUS_WORKING_DIR --depth=1
  549. git fetch origin $CIRRUS_CHANGE_IN_REPO --depth=1
  550. git reset --hard $CIRRUS_CHANGE_IN_REPO
  551. install_tooling_script:
  552. - ./private/cirrus/cirrus-tooling-for-package-docker.sh
  553. package_script:
  554. - ./private/cirrus/cirrus-package-docker.sh
  555. sql_mssql_task:
  556. <<: *DEFAULT_TEMPLATE
  557. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  558. <<: *DATABASE_RELATED_TASK_TEMPLATE
  559. <<: *GRADLE_CACHE_TEMPLATE
  560. eks_container:
  561. <<: *CONTAINER_TEMPLATE
  562. memory: 5Gb
  563. additional_containers:
  564. - name: mssql
  565. image: mcr.microsoft.com/mssql/server:2019-GA-ubuntu-16.04
  566. port: 1433
  567. cpu: 2
  568. memory: 5Gb
  569. env:
  570. MSSQL_PID: Developer # this is the default edition
  571. ACCEPT_EULA: Y
  572. SA_PASSWORD: sonarqube!1
  573. script:
  574. - ./private/cirrus/cirrus-db-unit-test.sh mssql
  575. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  576. sql_postgres_task:
  577. <<: *DEFAULT_TEMPLATE
  578. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  579. <<: *DATABASE_RELATED_TASK_TEMPLATE
  580. <<: *GRADLE_CACHE_TEMPLATE
  581. eks_container:
  582. <<: *CONTAINER_TEMPLATE
  583. memory: 5Gb
  584. additional_containers:
  585. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  586. script:
  587. - ./private/cirrus/cirrus-db-unit-test.sh postgres
  588. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  589. # this is the oldest compatible version of PostgreSQL
  590. sql_postgres11_task:
  591. <<: *DEFAULT_TEMPLATE
  592. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  593. <<: *DATABASE_RELATED_TASK_TEMPLATE
  594. <<: *GRADLE_CACHE_TEMPLATE
  595. eks_container:
  596. <<: *CONTAINER_TEMPLATE
  597. memory: 5Gb
  598. additional_containers:
  599. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  600. image: public.ecr.aws/docker/library/postgres:11
  601. script:
  602. - ./private/cirrus/cirrus-db-unit-test.sh postgres
  603. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  604. sql_oracle21_task:
  605. <<: *DEFAULT_TEMPLATE
  606. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  607. <<: *DATABASE_RELATED_TASK_TEMPLATE
  608. <<: *GRADLE_CACHE_TEMPLATE
  609. eks_container:
  610. <<: *CONTAINER_TEMPLATE
  611. memory: 5Gb
  612. additional_containers:
  613. - <<: *ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  614. script:
  615. - ./private/cirrus/cirrus-db-unit-test.sh oracle21
  616. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  617. upgd_mssql_task:
  618. <<: *DEFAULT_TEMPLATE
  619. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  620. <<: *DATABASE_RELATED_TASK_TEMPLATE
  621. <<: *JAR_CACHE_TEMPLATE
  622. <<: *GRADLE_CACHE_TEMPLATE
  623. eks_container:
  624. <<: *CONTAINER_TEMPLATE
  625. cpu: 1.5
  626. memory: 6Gb
  627. additional_containers:
  628. - name: mssql
  629. image: mcr.microsoft.com/mssql/server:2022-latest
  630. port: 1433
  631. cpu: 2
  632. memory: 5Gb
  633. env:
  634. MSSQL_PID: Developer # this is the default edition
  635. ACCEPT_EULA: Y
  636. SA_PASSWORD: sonarqube!1
  637. env:
  638. QA_CATEGORY: Upgrade
  639. script:
  640. - ./private/cirrus/cirrus-qa.sh mssql
  641. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  642. upgd_oracle21_task:
  643. <<: *DEFAULT_TEMPLATE
  644. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  645. <<: *DATABASE_RELATED_TASK_TEMPLATE
  646. <<: *JAR_CACHE_TEMPLATE
  647. <<: *GRADLE_CACHE_TEMPLATE
  648. eks_container:
  649. <<: *CONTAINER_TEMPLATE
  650. cpu: 1.5
  651. memory: 6Gb
  652. additional_containers:
  653. - <<: *ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  654. env:
  655. QA_CATEGORY: Upgrade
  656. script:
  657. - ./private/cirrus/cirrus-qa.sh oracle21
  658. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  659. ws_scan_task:
  660. <<: *DEFAULT_TEMPLATE
  661. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  662. only_if: >-
  663. $CIRRUS_BRANCH == $BRANCH_MAIN ||
  664. ($CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE && $CIRRUS_BRANCH != $BRANCH_NIGHTLY)
  665. <<: *YARN_CACHE_TEMPLATE
  666. <<: *GRADLE_CACHE_TEMPLATE
  667. timeout_in: 30m
  668. eks_container:
  669. <<: *CONTAINER_TEMPLATE
  670. cpu: 2
  671. memory: 4Gb
  672. env:
  673. WS_APIKEY: VAULT[development/kv/data/mend data.apikey]
  674. WS_WSS_URL: VAULT[development/kv/data/mend data.url]
  675. WS_USERKEY: VAULT[development/kv/data/mend data.userKey]
  676. SLACK_WEBHOOK_SQ: VAULT[development/kv/data/slack data.webhook]
  677. whitesource_script:
  678. - ./private/cirrus/cirrus-whitesource-scan.sh
  679. allow_failures: "true"
  680. on_failure:
  681. slack_notification_script:
  682. - ./private/cirrus/cirrus-whitesource-notifications.sh
  683. always:
  684. ws_artifacts:
  685. path: "whitesource/**/*"