You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

.cirrus.yml 26KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781
  1. env:
  2. GRADLE_OPTS: -Dorg.gradle.jvmargs="-XX:+PrintFlagsFinal -XshowSettings:vm -XX:+HeapDumpOnOutOfMemoryError -XX:+UnlockExperimentalVMOptions -Djava.security.egd=file:/dev/./urandom -Dfile.encoding=UTF8 -Duser.language=en -Duser.country=US"
  3. # to be replaced by other credentials
  4. ARTIFACTORY_PRIVATE_USERNAME: vault-${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader
  5. ARTIFACTORY_PRIVATE_PASSWORD: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader access_token]
  6. ARTIFACTORY_DEPLOY_USERNAME: vault-${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-qa-deployer
  7. ARTIFACTORY_DEPLOY_PASSWORD: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-qa-deployer access_token]
  8. ARTIFACTORY_ACCESS_TOKEN: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader access_token]
  9. ARTIFACTORY_PROMOTE_ACCESS_TOKEN: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-promoter access_token]
  10. # download licenses for testing commercial editions
  11. GITHUB_TOKEN: VAULT[development/github/token/licenses-ro token]
  12. # notifications to burgr
  13. BURGR_URL: VAULT[development/kv/data/burgr data.url]
  14. BURGR_USERNAME: VAULT[development/kv/data/burgr data.cirrus_username]
  15. BURGR_PASSWORD: VAULT[development/kv/data/burgr data.cirrus_password]
  16. # analysis on next.sonarqube.com
  17. SONARQUBE_NEXT_TOKEN: VAULT[development/kv/data/next data.token]
  18. # to trigger docs deployment
  19. ELASTIC_PWD: VAULT[development/team/sonarqube/kv/data/elasticsearch-cloud data.password]
  20. CIRRUS_LOG_TIMESTAMP: true
  21. BRANCH_MAIN: "master"
  22. BRANCH_NIGHTLY: "branch-nightly-build"
  23. BRANCH_PATTERN_MAINTENANCE: "branch-.*"
  24. BRANCH_PATTERN_PUBLIC: "public_.*"
  25. auto_cancellation: $CIRRUS_BRANCH != $BRANCH_MAIN && $CIRRUS_BRANCH !=~ $BRANCH_PATTERN_MAINTENANCE
  26. skip_public_branches_template: &SKIP_PUBLIC_BRANCHES_TEMPLATE
  27. skip: $CIRRUS_BRANCH =~ $BRANCH_PATTERN_PUBLIC
  28. cache_dependencies_dependant_task_template:
  29. &CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  30. depends_on: cache_dependencies
  31. build_dependant_task_template: &BUILD_DEPENDANT_TASK_TEMPLATE
  32. depends_on: build
  33. master_and_nightly_task_template: &MASTER_AND_NIGHTLY_TASK_TEMPLATE
  34. only_if: $CIRRUS_BRANCH == $BRANCH_NIGHTLY || $CIRRUS_BRANCH == $BRANCH_MAIN
  35. master_or_nightly_or_maintenance_task_template:
  36. &MASTER_OR_NIGHTLY_OR_MAINTENANCE_TASK_TEMPLATE
  37. only_if: $CIRRUS_BRANCH == $BRANCH_NIGHTLY || $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE
  38. except_nightly_task_template: &EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  39. only_if: $CIRRUS_BRANCH != $BRANCH_NIGHTLY
  40. database_related_task_template: &DATABASE_RELATED_TASK_TEMPLATE
  41. only_if: >-
  42. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  43. changesInclude('server/sonar-db-dao/**/*Mapper.xml', 'server/sonar-db-migration/**/DbVersion*.java', 'server/sonar-db-dao/**/*Dao.java', 'server/sonar-db-core/src/main/java/org/sonar/db/*.java')
  44. saml_task_template: &SAML_TASK_TEMPLATE
  45. only_if: >-
  46. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  47. changesInclude('server/sonar-auth-saml/src/main/java/**/*.java', 'server/sonar-auth-saml/src/main/resources/**/*', 'server/sonar-db-dao/src/main/**/SAML*.java', 'private/it-core/src/test/java/org/sonarqube/tests/saml/*.java', 'server/sonar-webserver-webapi/src/main/java/org/sonar/server/saml/**/*.java')
  48. ldap_task_template: &LDAP_TASK_TEMPLATE
  49. only_if: >-
  50. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  51. changesInclude('server/sonar-auth-ldap/src/main/java/**/*.java', 'server/sonar-webserver-auth/src/main/java/org/sonar/server/authentication/LdapCredentialsAuthentication.java', 'private/it-core/src/test/java/org/sonarqube/tests/ldap/*.java')
  52. github_task_template: &GITHUB_TASK_TEMPLATE
  53. only_if: >-
  54. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  55. changesInclude('private/core-extension-developer-server/src/main/java/com/sonarsource/branch/pr/github/**/*.java',
  56. 'private/core-extension-developer-server/src/main/java/com/sonarsource/github/**/*.java',
  57. 'private/it-branch/it-tests/src/test/java/com/sonarsource/branch/it/suite/pr/github/**/*.java')
  58. gitlab_task_template: &GITLAB_TASK_TEMPLATE
  59. only_if: >-
  60. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  61. changesInclude('private/core-extension-developer-server/src/main/java/com/sonarsource/branch/pr/gitlab/**/*.java', 'private/it-branch/it-tests/src/test/java/com/sonarsource/branch/it/suite/pr/gitlab/**/*.java')
  62. azure_task_template: &AZURE_TASK_TEMPLATE
  63. only_if: >-
  64. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  65. changesInclude('private/core-extension-developer-server/src/main/java/com/sonarsource/branch/pr/azuredevops/**/*.java', 'private/it-branch/it-tests/src/test/java/com/sonarsource/branch/it/suite/pr/azure/**/*.java')
  66. bitbucket_server_task_template: &BITBUCKET_SERVER_TASK_TEMPLATE
  67. only_if: >-
  68. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  69. changesInclude('private/core-extension-developer-server/src/main/java/com/sonarsource/branch/pr/bitbucketserver/**/*.java', 'private/it-branch/it-tests/src/test/java/com/sonarsource/branch/it/suite/pr/bitbucketserver/**/*.java')
  70. bitbucket_cloud_task_template: &BITBUCKET_CLOUD_TASK_TEMPLATE
  71. only_if: >-
  72. $CIRRUS_BRANCH == $BRANCH_MAIN || $CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE || $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  73. changesInclude('private/core-extension-developer-server/src/main/java/com/sonarsource/branch/pr/bitbucket/**/*.java', 'private/it-branch/it-tests/src/test/java/com/sonarsource/branch/it/suite/pr/bitbucketcloud/**/*.java')
  74. docker_build_container_template: &CONTAINER_TEMPLATE
  75. region: eu-central-1
  76. cluster_name: ${CIRRUS_CLUSTER_NAME}
  77. namespace: default
  78. builder_subnet_id: ${CIRRUS_AWS_SUBNET}
  79. builder_role: cirrus-builder
  80. builder_image: docker-builder-v*
  81. builder_instance_type: t2.small
  82. dockerfile: private/docker/Dockerfile-build
  83. docker_arguments:
  84. CIRRUS_AWS_ACCOUNT: ${CIRRUS_AWS_ACCOUNT}
  85. cpu: 1
  86. memory: 2Gb
  87. vm_instance_template: &VM_TEMPLATE
  88. experimental: true # see https://github.com/cirruslabs/cirrus-ci-docs/issues/1051
  89. image: docker-builder-v*
  90. type: t2.small
  91. region: eu-central-1
  92. subnet_id: ${CIRRUS_AWS_SUBNET}
  93. disk: 10
  94. cpu: 4
  95. memory: 8G
  96. oracle_additional_container_template: &ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  97. name: oracle
  98. image: gvenzl/oracle-xe:21-faststart
  99. port: 1521
  100. cpu: 2
  101. memory: 5Gb
  102. env:
  103. ORACLE_PASSWORD: sonarqube
  104. APP_USER: sonarqube
  105. APP_USER_PASSWORD: sonarqube
  106. postgres_additional_container_template: &POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  107. name: postgres
  108. image: public.ecr.aws/docker/library/postgres:15
  109. port: 5432
  110. cpu: 1
  111. memory: 1Gb
  112. env:
  113. POSTGRES_USER: postgres
  114. POSTGRES_PASSWORD: postgres
  115. default_artifact_template: &DEFAULT_ARTIFACTS_TEMPLATE
  116. on_failure:
  117. jest_junit_cleanup_script: >
  118. find . -type f -wholename "**/build/test-results/test-jest/junit.xml" -exec
  119. xmlstarlet edit --inplace --delete '//testsuite[@errors=0 and @failures=0]' {} \;
  120. junit_artifacts:
  121. path: "**/build/test-results/**/*.xml"
  122. type: "text/xml"
  123. format: junit
  124. reports_artifacts:
  125. path: "**/build/reports/**/*"
  126. screenshots_artifacts:
  127. path: "**/build/screenshots/**/*"
  128. always:
  129. profile_artifacts:
  130. path: "**/build/reports/profile/**/*"
  131. yarn_cache_template: &YARN_CACHE_TEMPLATE
  132. yarn_cache:
  133. folder: "~/.yarn/berry/cache"
  134. fingerprint_script: |
  135. cat \
  136. server/sonar-web/yarn.lock \
  137. private/core-extension-developer-server/yarn.lock \
  138. private/core-extension-enterprise-server/yarn.lock \
  139. private/core-extension-license/yarn.lock \
  140. private/core-extension-securityreport/yarn.lock
  141. gradle_cache_template: &GRADLE_CACHE_TEMPLATE
  142. gradle_cache:
  143. folder: "~/.gradle/caches"
  144. fingerprint_script: find -type f \( -name "*.gradle*" -or -name "gradle*.properties" \) | sort | xargs cat
  145. jar_cache_template: &JAR_CACHE_TEMPLATE
  146. jar_cache:
  147. folder: "**/build/libs/*.jar"
  148. fingerprint_key: jar-cache_$CIRRUS_BUILD_ID
  149. eslint_report_cache_template: &ESLINT_REPORT_CACHE_TEMPLATE
  150. eslint_report_cache:
  151. folders:
  152. - server/sonar-web/eslint-report/
  153. - server/sonar-web/design-system/eslint-report/
  154. - private/core-extension-securityreport/eslint-report/
  155. - private/core-extension-license/eslint-report/
  156. - private/core-extension-enterprise-server/eslint-report/
  157. - private/core-extension-developer-server/eslint-report/
  158. fingerprint_script: echo $CIRRUS_BUILD_ID
  159. jest_report_cache_template: &JEST_REPORT_CACHE_TEMPLATE
  160. jest_report_cache:
  161. folders:
  162. - server/sonar-web/coverage/
  163. - server/sonar-web/design-system/coverage/
  164. - private/core-extension-securityreport/coverage/
  165. - private/core-extension-license/coverage/
  166. - private/core-extension-enterprise-server/coverage/
  167. - private/core-extension-developer-server/coverage/
  168. fingerprint_script: echo $CIRRUS_BUILD_ID
  169. junit_report_cache_template: &JUNIT_REPORT_CACHE_TEMPLATE
  170. junit_report_cache:
  171. folders:
  172. - "**/reports/jacoco"
  173. - "**/test-results/test"
  174. fingerprint_script: echo $CIRRUS_BUILD_ID
  175. default_template: &DEFAULT_TEMPLATE
  176. <<: *SKIP_PUBLIC_BRANCHES_TEMPLATE
  177. clone_script: |
  178. git init
  179. git remote add origin https://x-access-token:${CIRRUS_REPO_CLONE_TOKEN}@github.com/${CIRRUS_REPO_FULL_NAME}.git
  180. git fetch origin $CIRRUS_CHANGE_IN_REPO $FETCH_DEPTH
  181. git reset --hard $CIRRUS_CHANGE_IN_REPO
  182. env:
  183. FETCH_DEPTH: --depth=1
  184. cache_dependencies_task:
  185. <<: *DEFAULT_TEMPLATE
  186. <<: *GRADLE_CACHE_TEMPLATE
  187. eks_container:
  188. <<: *CONTAINER_TEMPLATE
  189. cpu: 2
  190. memory: 4Gb
  191. script:
  192. - ./private/cirrus/cirrus-cache-dependencies.sh
  193. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  194. build_task:
  195. <<: *DEFAULT_TEMPLATE
  196. <<: *GRADLE_CACHE_TEMPLATE
  197. <<: *YARN_CACHE_TEMPLATE
  198. <<: *JAR_CACHE_TEMPLATE
  199. <<: *CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  200. eks_container:
  201. <<: *CONTAINER_TEMPLATE
  202. cpu: 7.5
  203. memory: 8Gb
  204. script:
  205. - ./private/cirrus/cirrus-build.sh
  206. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  207. publish_task:
  208. <<: *DEFAULT_TEMPLATE
  209. <<: *GRADLE_CACHE_TEMPLATE
  210. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  211. eks_container:
  212. <<: *CONTAINER_TEMPLATE
  213. cpu: 4
  214. memory: 4Gb
  215. env:
  216. ORG_GRADLE_PROJECT_signingKey: VAULT[development/kv/data/sign data.key]
  217. ORG_GRADLE_PROJECT_signingPassword: VAULT[development/kv/data/sign data.passphrase]
  218. ORG_GRADLE_PROJECT_signingKeyId: VAULT[development/kv/data/sign data.key_id]
  219. script:
  220. - ./private/cirrus/cirrus-publish.sh
  221. yarn_lint_task:
  222. <<: *DEFAULT_TEMPLATE
  223. <<: *GRADLE_CACHE_TEMPLATE
  224. <<: *YARN_CACHE_TEMPLATE
  225. <<: *ESLINT_REPORT_CACHE_TEMPLATE
  226. <<: *CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  227. eks_container:
  228. <<: *CONTAINER_TEMPLATE
  229. cpu: 3
  230. memory: 6Gb
  231. script:
  232. - ./private/cirrus/cirrus-yarn-lint-report.sh
  233. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  234. yarn_check_task:
  235. <<: *DEFAULT_TEMPLATE
  236. <<: *GRADLE_CACHE_TEMPLATE
  237. <<: *YARN_CACHE_TEMPLATE
  238. <<: *CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  239. eks_container:
  240. <<: *CONTAINER_TEMPLATE
  241. cpu: 3
  242. memory: 4Gb
  243. script: |
  244. ./private/cirrus/cirrus-env.sh YARN
  245. gradle yarn_check-ci --profile
  246. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  247. yarn_validate_task:
  248. <<: *DEFAULT_TEMPLATE
  249. <<: *GRADLE_CACHE_TEMPLATE
  250. <<: *YARN_CACHE_TEMPLATE
  251. <<: *JEST_REPORT_CACHE_TEMPLATE
  252. <<: *CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  253. eks_container:
  254. <<: *CONTAINER_TEMPLATE
  255. cpu: 7.5
  256. memory: 25Gb
  257. script:
  258. - ./private/cirrus/cirrus-yarn-validate-ci.sh
  259. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  260. junit_task:
  261. <<: *DEFAULT_TEMPLATE
  262. <<: *GRADLE_CACHE_TEMPLATE
  263. <<: *JUNIT_REPORT_CACHE_TEMPLATE
  264. <<: *CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  265. eks_container:
  266. <<: *CONTAINER_TEMPLATE
  267. cpu: 7.5
  268. memory: 10Gb
  269. script:
  270. - ./private/cirrus/cirrus-junit.sh
  271. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  272. sq_analysis_task:
  273. <<: *SKIP_PUBLIC_BRANCHES_TEMPLATE
  274. <<: *EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  275. <<: *GRADLE_CACHE_TEMPLATE
  276. <<: *YARN_CACHE_TEMPLATE
  277. <<: *JEST_REPORT_CACHE_TEMPLATE
  278. <<: *ESLINT_REPORT_CACHE_TEMPLATE
  279. <<: *JUNIT_REPORT_CACHE_TEMPLATE
  280. depends_on:
  281. - yarn_validate
  282. - yarn_lint
  283. - junit
  284. eks_container:
  285. <<: *CONTAINER_TEMPLATE
  286. cpu: 7.5
  287. memory: 15Gb
  288. script:
  289. - ./private/cirrus/cirrus-sq-analysis.sh
  290. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  291. qa_task:
  292. <<: *DEFAULT_TEMPLATE
  293. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  294. <<: *CACHE_DEPENDENCIES_DEPENDANT_TASK_TEMPLATE
  295. <<: *GRADLE_CACHE_TEMPLATE
  296. <<: *JAR_CACHE_TEMPLATE
  297. eks_container:
  298. <<: *CONTAINER_TEMPLATE
  299. cpu: 3
  300. memory: 7Gb
  301. additional_containers:
  302. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  303. name: QA $QA_CATEGORY
  304. alias: qa
  305. env:
  306. matrix:
  307. # QA name should not exceed 13 characters to be properly reported on wallboard by burgr
  308. # QA name cannot contain "_"
  309. - QA_CATEGORY: Cat1
  310. - QA_CATEGORY: Cat2
  311. - QA_CATEGORY: Cat3
  312. - QA_CATEGORY: Cat4
  313. - QA_CATEGORY: Cat5
  314. - QA_CATEGORY: Cat6
  315. - QA_CATEGORY: Analysis
  316. - QA_CATEGORY: Authorization
  317. - QA_CATEGORY: Auth
  318. - QA_CATEGORY: Branch1
  319. - QA_CATEGORY: Branch2
  320. - QA_CATEGORY: CE1
  321. - QA_CATEGORY: CE2
  322. - QA_CATEGORY: ComputeEngine
  323. - QA_CATEGORY: DE1
  324. - QA_CATEGORY: DE2
  325. - QA_CATEGORY: EE1
  326. - QA_CATEGORY: EE2
  327. - QA_CATEGORY: Issues1
  328. - QA_CATEGORY: Issues2
  329. - QA_CATEGORY: License1
  330. - QA_CATEGORY: License2
  331. - QA_CATEGORY: Plugins
  332. - QA_CATEGORY: Project
  333. - QA_CATEGORY: QP
  334. - QA_CATEGORY: Upgrade
  335. script:
  336. - ./private/cirrus/cirrus-qa.sh postgres
  337. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  338. task: #bitbucket
  339. <<: *DEFAULT_TEMPLATE
  340. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  341. <<: *JAR_CACHE_TEMPLATE
  342. <<: *GRADLE_CACHE_TEMPLATE
  343. <<: *BITBUCKET_SERVER_TASK_TEMPLATE
  344. eks_container:
  345. <<: *CONTAINER_TEMPLATE
  346. cpu: 3
  347. memory: 10Gb
  348. additional_containers:
  349. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  350. maven_cache:
  351. folder: ~/.m2
  352. env:
  353. QA_CATEGORY: BITBUCKET
  354. matrix:
  355. - name: qa_bb_5.15.0
  356. bitbucket_background_script: ./private/cirrus/cirrus-start-bitbucket.sh 5.15.0
  357. - name: qa_bb_latest
  358. bitbucket_background_script: ./private/cirrus/cirrus-start-bitbucket.sh LATEST
  359. wait_for_bitbucket_to_boot_script: secs=3600; endTime=$(( $(date +%s) + secs )); while [[ "$(curl -s -o /dev/null -w ''%{http_code}'' localhost:7990/bitbucket/status)" != "200" ]] || [ $(date +%s) -gt $endTime ]; do sleep 5; done
  360. script:
  361. - ./private/cirrus/cirrus-qa.sh postgres
  362. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  363. qa_bb_cloud_task:
  364. <<: *DEFAULT_TEMPLATE
  365. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  366. <<: *JAR_CACHE_TEMPLATE
  367. <<: *GRADLE_CACHE_TEMPLATE
  368. <<: *BITBUCKET_CLOUD_TASK_TEMPLATE
  369. eks_container:
  370. <<: *CONTAINER_TEMPLATE
  371. cpu: 2.4
  372. memory: 7Gb
  373. env:
  374. QA_CATEGORY: BITBUCKET_CLOUD
  375. BBC_CLIENT_ID: VAULT[development/team/sonarqube/kv/data/bitbucket-cloud data.client_id]
  376. BBC_CLIENT_SECRET: VAULT[development/team/sonarqube/kv/data/bitbucket-cloud data.client_secret]
  377. BBC_USERNAME: VAULT[development/kv/data/bitbucket/sonarqube-its data.username]
  378. BBC_READ_REPOS_APP_PASSWORD: VAULT[development/kv/data/bitbucket/sonarqube-its data.password]
  379. script:
  380. - ./private/cirrus/cirrus-qa.sh h2
  381. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  382. qa_ha_task:
  383. <<: *DEFAULT_TEMPLATE
  384. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  385. <<: *MASTER_OR_NIGHTLY_OR_MAINTENANCE_TASK_TEMPLATE
  386. <<: *JAR_CACHE_TEMPLATE
  387. <<: *GRADLE_CACHE_TEMPLATE
  388. eks_container:
  389. <<: *CONTAINER_TEMPLATE
  390. cpu: 2.4
  391. memory: 10Gb
  392. additional_containers:
  393. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  394. env:
  395. QA_CATEGORY: HA
  396. script:
  397. - ./private/cirrus/cirrus-qa.sh postgres
  398. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  399. qa_performance_task:
  400. <<: *DEFAULT_TEMPLATE
  401. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  402. <<: *MASTER_AND_NIGHTLY_TASK_TEMPLATE
  403. <<: *JAR_CACHE_TEMPLATE
  404. <<: *GRADLE_CACHE_TEMPLATE
  405. eks_container:
  406. <<: *CONTAINER_TEMPLATE
  407. cpu: 2.4
  408. memory: 10Gb
  409. additional_containers:
  410. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  411. env:
  412. QA_CATEGORY: AnalysisPerformance
  413. script:
  414. - ./private/cirrus/cirrus-qa.sh postgres
  415. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  416. # GitLab QA is executed in a dedicated task in order to not slow down the pipeline, as a GitLab on-prem server docker image is required.
  417. qa_gitlab_task:
  418. <<: *DEFAULT_TEMPLATE
  419. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  420. <<: *JAR_CACHE_TEMPLATE
  421. <<: *GRADLE_CACHE_TEMPLATE
  422. <<: *GITLAB_TASK_TEMPLATE
  423. depends_on:
  424. - build
  425. env:
  426. QA_CATEGORY: GITLAB
  427. matrix:
  428. - name: qa_gitlab_latest
  429. env:
  430. - GITLAB_VERSION: latest
  431. - name: qa_gitlab_oldest
  432. env:
  433. - GITLAB_VERSION: 15.6.2-ce.0
  434. eks_container:
  435. <<: *CONTAINER_TEMPLATE
  436. cpu: 2.4
  437. memory: 7Gb
  438. use_in_memory_disk: true
  439. additional_containers:
  440. - name: gitlab
  441. ports:
  442. - 80
  443. - 443
  444. cpu: 2
  445. memory: 8Gb
  446. image: ${CIRRUS_AWS_ACCOUNT}.dkr.ecr.eu-central-1.amazonaws.com/gitlab:${GITLAB_VERSION}
  447. env:
  448. - GITLAB_POST_RECONFIGURE_SCRIPT: |-
  449. { cat >/tmp/setup.rb <<-'EOF'
  450. token = User.find_by_username('root').personal_access_tokens.create(scopes: [:api], name: 'token');
  451. token.set_token('token-here-456');
  452. token.expires_at = Date.today+10.day
  453. token.save!;
  454. token_read = User.find_by_username('root').personal_access_tokens.create(scopes: [:read_user], name: 'token_read');
  455. token_read.set_token('token-read-123');
  456. token_read.expires_at = Date.today+10.day
  457. token_read.save!;
  458. user = User.find_by_username('root');
  459. user.password = 'eng-YTU1ydh6kyt7tjd';
  460. user.password_confirmation = 'eng-YTU1ydh6kyt7tjd';
  461. user.save!;
  462. EOF
  463. } && gitlab-rails runner /tmp/setup.rb && \
  464. echo 'from_file "/etc/gitlab/external_gitlab.rb"' >> /etc/gitlab/gitlab.rb && \
  465. gitlab-ctl reconfigure
  466. script:
  467. - ./private/cirrus/cirrus-qa.sh h2
  468. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  469. qa_gitlab_cloud_task:
  470. <<: *DEFAULT_TEMPLATE
  471. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  472. <<: *JAR_CACHE_TEMPLATE
  473. <<: *GRADLE_CACHE_TEMPLATE
  474. <<: *GITLAB_TASK_TEMPLATE
  475. eks_container:
  476. <<: *CONTAINER_TEMPLATE
  477. cpu: 2.4
  478. memory: 7Gb
  479. use_in_memory_disk: true
  480. env:
  481. QA_CATEGORY: GITLAB_CLOUD
  482. GITLAB_API_TOKEN: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.api_token]
  483. GITLAB_READ_ONLY_TOKEN: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.api_token_ro]
  484. GITLAB_ADMIN_USERNAME: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.username]
  485. GITLAB_ADMIN_PASSWORD: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.password]
  486. script:
  487. - ./private/cirrus/cirrus-qa.sh h2
  488. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  489. # Azure QA is executed in a dedicated task in order to not slow down the pipeline.
  490. qa_azure_task:
  491. <<: *DEFAULT_TEMPLATE
  492. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  493. <<: *JAR_CACHE_TEMPLATE
  494. <<: *GRADLE_CACHE_TEMPLATE
  495. <<: *AZURE_TASK_TEMPLATE
  496. eks_container:
  497. <<: *CONTAINER_TEMPLATE
  498. cpu: 2.4
  499. memory: 7Gb
  500. env:
  501. QA_CATEGORY: AZURE
  502. AZURE_USERNAME_LOGIN: VAULT[development/team/sonarqube/kv/data/azure-instance data.username]
  503. AZURE_CODE_READ_AND_WRITE_TOKEN: VAULT[development/team/sonarqube/kv/data/azure-instance data.token_code_read_write]
  504. AZURE_FULL_ACCESS_TOKEN: VAULT[development/team/sonarqube/kv/data/azure-instance data.token_full_access]
  505. script:
  506. - ./private/cirrus/cirrus-qa.sh h2
  507. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  508. qa_github_task:
  509. <<: *DEFAULT_TEMPLATE
  510. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  511. <<: *GITHUB_TASK_TEMPLATE
  512. <<: *JAR_CACHE_TEMPLATE
  513. <<: *GRADLE_CACHE_TEMPLATE
  514. eks_container:
  515. <<: *CONTAINER_TEMPLATE
  516. cpu: 2.4
  517. memory: 7Gb
  518. env:
  519. QA_CATEGORY: GITHUB
  520. GITHUB_COM_CODE_SCANNING_ALERTS_TECHNICAL_USER_USERNAME: QA-task
  521. GITHUB_COM_CODE_SCANNING_ALERTS_TECHNICAL_USER_TOKEN: VAULT[development/github/token/SonarSource-sonar-enterprise-code-scanning token]
  522. script:
  523. - ./private/cirrus/cirrus-qa.sh h2
  524. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  525. # SAML QA is executed in a dedicated task in order to not slow down the pipeline, as a Keycloak server docker image is required.
  526. qa_saml_task:
  527. <<: *DEFAULT_TEMPLATE
  528. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  529. <<: *SAML_TASK_TEMPLATE
  530. <<: *JAR_CACHE_TEMPLATE
  531. <<: *GRADLE_CACHE_TEMPLATE
  532. eks_container:
  533. <<: *CONTAINER_TEMPLATE
  534. cpu: 2.4
  535. memory: 10Gb
  536. additional_containers:
  537. - name: keycloak
  538. image: quay.io/keycloak/keycloak:21.1.1
  539. port: 8080
  540. cpu: 1
  541. memory: 1Gb
  542. command: "/opt/keycloak/bin/kc.sh start-dev --http-relative-path /auth"
  543. env:
  544. KEYCLOAK_ADMIN: admin
  545. KEYCLOAK_ADMIN_PASSWORD: admin
  546. env:
  547. QA_CATEGORY: SAML
  548. script:
  549. - ./private/cirrus/cirrus-qa.sh h2
  550. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  551. # LDAP QA is executed in a dedicated task in order to not slow down the pipeline, as a LDAP server and SonarQube server are re-started on each test.
  552. qa_ldap_task:
  553. <<: *DEFAULT_TEMPLATE
  554. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  555. <<: *LDAP_TASK_TEMPLATE
  556. <<: *JAR_CACHE_TEMPLATE
  557. <<: *GRADLE_CACHE_TEMPLATE
  558. eks_container:
  559. <<: *CONTAINER_TEMPLATE
  560. cpu: 2.4
  561. memory: 10Gb
  562. env:
  563. QA_CATEGORY: LDAP
  564. script:
  565. - ./private/cirrus/cirrus-qa.sh h2
  566. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  567. promote_task:
  568. <<: *DEFAULT_TEMPLATE
  569. <<: *EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  570. depends_on:
  571. - build
  572. - sq_analysis
  573. - qa
  574. - qa_saml
  575. - qa_ldap
  576. - publish
  577. eks_container:
  578. <<: *CONTAINER_TEMPLATE
  579. memory: 512M
  580. stateful: true
  581. script:
  582. - ./private/cirrus/cirrus-promote.sh
  583. package_docker_task:
  584. <<: *DEFAULT_TEMPLATE
  585. depends_on: promote
  586. only_if: $CIRRUS_BRANCH == $BRANCH_MAIN
  587. ec2_instance:
  588. <<: *VM_TEMPLATE
  589. clone_script: |
  590. git clone --recursive --branch=$CIRRUS_BRANCH https://x-access-token:${CIRRUS_REPO_CLONE_TOKEN}@github.com/${CIRRUS_REPO_FULL_NAME}.git $CIRRUS_WORKING_DIR --depth=1
  591. git fetch origin $CIRRUS_CHANGE_IN_REPO --depth=1
  592. git reset --hard $CIRRUS_CHANGE_IN_REPO
  593. install_tooling_script:
  594. - ./private/cirrus/cirrus-tooling-for-package-docker.sh
  595. package_script:
  596. - ./private/cirrus/cirrus-package-docker.sh
  597. sql_mssql_task:
  598. <<: *DEFAULT_TEMPLATE
  599. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  600. <<: *DATABASE_RELATED_TASK_TEMPLATE
  601. <<: *GRADLE_CACHE_TEMPLATE
  602. eks_container:
  603. <<: *CONTAINER_TEMPLATE
  604. memory: 5Gb
  605. additional_containers:
  606. - name: mssql
  607. image: mcr.microsoft.com/mssql/server:2019-GA-ubuntu-16.04
  608. port: 1433
  609. cpu: 2
  610. memory: 5Gb
  611. env:
  612. MSSQL_PID: Developer # this is the default edition
  613. ACCEPT_EULA: Y
  614. SA_PASSWORD: sonarqube!1
  615. script:
  616. - ./private/cirrus/cirrus-db-unit-test.sh mssql
  617. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  618. sql_postgres_task:
  619. <<: *DEFAULT_TEMPLATE
  620. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  621. <<: *DATABASE_RELATED_TASK_TEMPLATE
  622. <<: *GRADLE_CACHE_TEMPLATE
  623. eks_container:
  624. <<: *CONTAINER_TEMPLATE
  625. memory: 5Gb
  626. additional_containers:
  627. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  628. script:
  629. - ./private/cirrus/cirrus-db-unit-test.sh postgres
  630. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  631. # this is the oldest compatible version of PostgreSQL
  632. sql_postgres11_task:
  633. <<: *DEFAULT_TEMPLATE
  634. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  635. <<: *DATABASE_RELATED_TASK_TEMPLATE
  636. <<: *GRADLE_CACHE_TEMPLATE
  637. eks_container:
  638. <<: *CONTAINER_TEMPLATE
  639. memory: 5Gb
  640. additional_containers:
  641. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  642. image: public.ecr.aws/docker/library/postgres:11
  643. script:
  644. - ./private/cirrus/cirrus-db-unit-test.sh postgres
  645. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  646. sql_oracle21_task:
  647. <<: *DEFAULT_TEMPLATE
  648. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  649. <<: *DATABASE_RELATED_TASK_TEMPLATE
  650. <<: *GRADLE_CACHE_TEMPLATE
  651. eks_container:
  652. <<: *CONTAINER_TEMPLATE
  653. memory: 5Gb
  654. additional_containers:
  655. - <<: *ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  656. script:
  657. - ./private/cirrus/cirrus-db-unit-test.sh oracle21
  658. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  659. upgd_mssql_task:
  660. <<: *DEFAULT_TEMPLATE
  661. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  662. <<: *DATABASE_RELATED_TASK_TEMPLATE
  663. <<: *JAR_CACHE_TEMPLATE
  664. <<: *GRADLE_CACHE_TEMPLATE
  665. eks_container:
  666. <<: *CONTAINER_TEMPLATE
  667. cpu: 1.5
  668. memory: 6Gb
  669. additional_containers:
  670. - name: mssql
  671. image: mcr.microsoft.com/mssql/server:2022-latest
  672. port: 1433
  673. cpu: 2
  674. memory: 5Gb
  675. env:
  676. MSSQL_PID: Developer # this is the default edition
  677. ACCEPT_EULA: Y
  678. SA_PASSWORD: sonarqube!1
  679. env:
  680. QA_CATEGORY: Upgrade
  681. script:
  682. - ./private/cirrus/cirrus-qa.sh mssql
  683. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  684. upgd_oracle21_task:
  685. <<: *DEFAULT_TEMPLATE
  686. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  687. <<: *DATABASE_RELATED_TASK_TEMPLATE
  688. <<: *JAR_CACHE_TEMPLATE
  689. <<: *GRADLE_CACHE_TEMPLATE
  690. eks_container:
  691. <<: *CONTAINER_TEMPLATE
  692. cpu: 1.5
  693. memory: 6Gb
  694. additional_containers:
  695. - <<: *ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  696. env:
  697. QA_CATEGORY: Upgrade
  698. script:
  699. - ./private/cirrus/cirrus-qa.sh oracle21
  700. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  701. mend_scan_task:
  702. <<: *DEFAULT_TEMPLATE
  703. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  704. only_if: >-
  705. $CIRRUS_BRANCH == $BRANCH_MAIN || ($CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE && $CIRRUS_BRANCH != $BRANCH_NIGHTLY)
  706. <<: *YARN_CACHE_TEMPLATE
  707. <<: *GRADLE_CACHE_TEMPLATE
  708. timeout_in: 30m
  709. eks_container:
  710. <<: *CONTAINER_TEMPLATE
  711. cpu: 2
  712. memory: 4Gb
  713. env:
  714. WS_APIKEY: VAULT[development/kv/data/mend data.apikey]
  715. WS_WSS_URL: VAULT[development/kv/data/mend data.url]
  716. WS_USERKEY: VAULT[development/kv/data/mend data.userKey]
  717. SLACK_WEBHOOK_SQ: VAULT[development/kv/data/slack data.webhook]
  718. mend_script:
  719. - ./private/cirrus/cirrus-mend-scan.sh
  720. allow_failures: "true"
  721. on_failure:
  722. slack_notification_script:
  723. - ./private/cirrus/cirrus-mend-notifications.sh
  724. always:
  725. ws_artifacts:
  726. path: "whitesource/**/*"