You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

.cirrus.yml 22KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691
  1. # content of service-account-credentials.json, used to access to Google Cloud Platform
  2. gcp_credentials: ENCRYPTED[!e5f7207bd8d02d383733bef47e18296ac32e3b7d22eb480354e8dd8fdc0004be45a8a4e72c797bd66ee94eb3340fa363!]
  3. env:
  4. GRADLE_OPTS: -Dorg.gradle.jvmargs="-XX:+PrintFlagsFinal -XshowSettings:vm -XX:+HeapDumpOnOutOfMemoryError -XX:+UnlockExperimentalVMOptions -Djava.security.egd=file:/dev/./urandom -Dfile.encoding=UTF8 -Duser.language=en -Duser.country=US"
  5. # to be replaced by other credentials
  6. ARTIFACTORY_PRIVATE_USERNAME: vault-${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader
  7. ARTIFACTORY_PRIVATE_PASSWORD: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader access_token]
  8. ARTIFACTORY_DEPLOY_USERNAME: vault-${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-qa-deployer
  9. ARTIFACTORY_DEPLOY_PASSWORD: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-qa-deployer access_token]
  10. ARTIFACTORY_ACCESS_TOKEN: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-private-reader access_token]
  11. ARTIFACTORY_PROMOTE_ACCESS_TOKEN: VAULT[development/artifactory/token/${CIRRUS_REPO_OWNER}-${CIRRUS_REPO_NAME}-promoter access_token]
  12. # download licenses for testing commercial editions
  13. GITHUB_TOKEN: VAULT[development/github/token/licenses-ro token]
  14. # notifications to burgr
  15. BURGR_URL: VAULT[development/kv/data/burgr data.url]
  16. BURGR_USERNAME: VAULT[development/kv/data/burgr data.cirrus_username]
  17. BURGR_PASSWORD: VAULT[development/kv/data/burgr data.cirrus_password]
  18. # analysis on next.sonarqube.com
  19. SONARQUBE_NEXT_TOKEN: VAULT[development/kv/data/next data.token]
  20. # to trigger docs deployment
  21. ELASTIC_PWD: VAULT[development/team/sonarqube/kv/data/elasticsearch-cloud data.password]
  22. CIRRUS_LOG_TIMESTAMP: true
  23. BRANCH_MAIN: 'master'
  24. BRANCH_NIGHTLY: 'branch-nightly-build'
  25. BRANCH_PATTERN_MAINTENANCE: 'branch-.*'
  26. BRANCH_PATTERN_PUBLIC: 'public_.*'
  27. auto_cancellation: $CIRRUS_BRANCH != $BRANCH_MAIN && $CIRRUS_BRANCH !=~ $BRANCH_PATTERN_MAINTENANCE
  28. skip_public_branches_template: &SKIP_PUBLIC_BRANCHES_TEMPLATE
  29. skip: $CIRRUS_BRANCH =~ $BRANCH_PATTERN_PUBLIC
  30. build_dependant_task_template: &BUILD_DEPENDANT_TASK_TEMPLATE
  31. depends_on: build
  32. nightly_task_template: &NIGHTLY_TASK_TEMPLATE
  33. only_if: $CIRRUS_BRANCH == $BRANCH_NIGHTLY
  34. except_nightly_task_template: &EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  35. only_if: $CIRRUS_BRANCH != $BRANCH_NIGHTLY
  36. database_related_nightly_task_template: &DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  37. only_if: >-
  38. $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  39. changesInclude('server/sonar-db-dao/**/*Mapper.xml', 'server/sonar-db-migration/**/DbVersion*.java', 'server/sonar-db-dao/**/*Dao.java')
  40. saml_nightly_task_template: &SAML_NIGHTLY_TASK_TEMPLATE
  41. only_if: >-
  42. $CIRRUS_BRANCH == $BRANCH_NIGHTLY ||
  43. changesInclude('server/sonar-auth-saml/src/main/java/**/*.java', 'server/sonar-auth-saml/src/main/resources/**/*', 'server/sonar-db-dao/src/main/**/SAML*.java', 'private/it-core/src/test/java/org/sonarqube/tests/saml/*.java', 'server/sonar-webserver-webapi/src/main/java/org/sonar/server/saml/**/*.java')
  44. docker_build_container_template: &GKE_CONTAINER_TEMPLATE
  45. dockerfile: private/docker/Dockerfile-build
  46. builder_image_project: sonarqube-team
  47. builder_image_name: family/docker-builder
  48. cluster_name: cirrus-ci-cluster
  49. zone: us-central1-a
  50. namespace: default
  51. cpu: 1
  52. memory: 2Gb
  53. oracle_additional_container_template: &ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  54. name: oracle
  55. image: us.gcr.io/sonarqube-team/oracle12:0.0.1 # see https://github.com/SonarSource/vms/blob/master/docker/README.md#oracle-12c to build it
  56. port: 1521
  57. cpu: 2
  58. memory: 5Gb
  59. env:
  60. ORACLE_PWD: sonarqube
  61. postgres_additional_container_template: &POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  62. name: postgres
  63. image: postgres:15
  64. port: 5432
  65. cpu: 1
  66. memory: 1Gb
  67. env:
  68. POSTGRES_USER: postgres
  69. POSTGRES_PASSWORD: postgres
  70. default_artifact_template: &DEFAULT_ARTIFACTS_TEMPLATE
  71. on_failure:
  72. jest_junit_cleanup_script: >
  73. find . -type f -wholename "**/build/test-results/test-jest/junit.xml" -exec
  74. xmlstarlet edit --inplace --delete '//testsuite[@errors=0 and @failures=0]' {} \;
  75. junit_artifacts:
  76. path: "**/build/test-results/**/*.xml"
  77. type: "text/xml"
  78. format: junit
  79. reports_artifacts:
  80. path: "**/build/reports/**/*"
  81. screenshots_artifacts:
  82. path: "**/build/screenshots/**/*"
  83. always:
  84. profile_artifacts:
  85. path: "**/build/reports/profile/**/*"
  86. yarn_cache_template: &YARN_CACHE_TEMPLATE
  87. yarn_cache:
  88. folder: "~/.yarn/berry/cache"
  89. fingerprint_script: |
  90. cat \
  91. server/sonar-web/yarn.lock \
  92. server/sonar-docs/yarn.lock \
  93. private/core-extension-enterprise-server/yarn.lock \
  94. private/core-extension-license/yarn.lock \
  95. private/core-extension-securityreport/yarn.lock
  96. gradle_cache_template: &GRADLE_CACHE_TEMPLATE
  97. gradle_cache:
  98. folder: "~/.gradle/caches"
  99. fingerprint_script: find -type f \( -name "*.gradle*" -or -name "gradle*.properties" \) -exec cat {} +
  100. jar_cache_template: &JAR_CACHE_TEMPLATE
  101. jar_cache:
  102. folder: "**/build/libs/*.jar"
  103. fingerprint_key: jar-cache_$CIRRUS_BUILD_ID
  104. eslint_report_cache_template: &ESLINT_REPORT_CACHE_TEMPLATE
  105. eslint_report_cache:
  106. folders:
  107. - server/sonar-web/eslint-report/
  108. - private/core-extension-securityreport/eslint-report/
  109. - private/core-extension-license/eslint-report/
  110. - private/core-extension-enterprise-server/eslint-report/
  111. - private/core-extension-developer-server/eslint-report/
  112. fingerprint_script: echo $CIRRUS_BUILD_ID
  113. jest_report_cache_template: &JEST_REPORT_CACHE_TEMPLATE
  114. jest_report_cache:
  115. folders:
  116. - server/sonar-web/coverage/
  117. - private/core-extension-securityreport/coverage/
  118. - private/core-extension-license/coverage/
  119. - private/core-extension-enterprise-server/coverage/
  120. - private/core-extension-developer-server/coverage/
  121. fingerprint_script: echo $CIRRUS_BUILD_ID
  122. junit_report_cache_template: &JUNIT_REPORT_CACHE_TEMPLATE
  123. junit_report_cache:
  124. folders:
  125. - "**/reports/jacoco"
  126. - "**/test-results/test"
  127. fingerprint_script: echo $CIRRUS_BUILD_ID
  128. default_template: &DEFAULT_TEMPLATE
  129. <<: *SKIP_PUBLIC_BRANCHES_TEMPLATE
  130. clone_script: |
  131. git init
  132. git remote add origin https://x-access-token:${CIRRUS_REPO_CLONE_TOKEN}@github.com/${CIRRUS_REPO_FULL_NAME}.git
  133. git fetch origin $CIRRUS_CHANGE_IN_REPO $FETCH_DEPTH
  134. git reset --hard $CIRRUS_CHANGE_IN_REPO
  135. env:
  136. FETCH_DEPTH: --depth=1
  137. build_task:
  138. <<: *DEFAULT_TEMPLATE
  139. <<: *GRADLE_CACHE_TEMPLATE
  140. <<: *YARN_CACHE_TEMPLATE
  141. <<: *JAR_CACHE_TEMPLATE
  142. gke_container:
  143. <<: *GKE_CONTAINER_TEMPLATE
  144. cpu: 7.5
  145. memory: 8Gb
  146. elasticsearch_distribution_cache:
  147. folder: sonar-application/build/elasticsearch-**.tar.gz
  148. script:
  149. - ./private/cirrus/cirrus-build.sh
  150. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  151. publish_task:
  152. <<: *DEFAULT_TEMPLATE
  153. <<: *GRADLE_CACHE_TEMPLATE
  154. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  155. gke_container:
  156. <<: *GKE_CONTAINER_TEMPLATE
  157. cpu: 4
  158. memory: 4Gb
  159. env:
  160. ORG_GRADLE_PROJECT_signingKey: VAULT[development/kv/data/sign data.key]
  161. ORG_GRADLE_PROJECT_signingPassword: VAULT[development/kv/data/sign data.passphrase]
  162. ORG_GRADLE_PROJECT_signingKeyId: VAULT[development/kv/data/sign data.key_id]
  163. script:
  164. - ./private/cirrus/cirrus-publish.sh
  165. yarn_lint_task:
  166. <<: *DEFAULT_TEMPLATE
  167. <<: *GRADLE_CACHE_TEMPLATE
  168. <<: *YARN_CACHE_TEMPLATE
  169. <<: *ESLINT_REPORT_CACHE_TEMPLATE
  170. gke_container:
  171. <<: *GKE_CONTAINER_TEMPLATE
  172. cpu: 2
  173. memory: 4Gb
  174. script:
  175. - ./private/cirrus/cirrus-yarn-lint-report.sh
  176. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  177. yarn_check_task:
  178. <<: *DEFAULT_TEMPLATE
  179. <<: *GRADLE_CACHE_TEMPLATE
  180. <<: *YARN_CACHE_TEMPLATE
  181. gke_container:
  182. <<: *GKE_CONTAINER_TEMPLATE
  183. cpu: 3
  184. memory: 4Gb
  185. script: |
  186. ./private/cirrus/cirrus-env.sh YARN
  187. gradle yarn_check-ci --profile
  188. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  189. yarn_validate_task:
  190. <<: *DEFAULT_TEMPLATE
  191. <<: *GRADLE_CACHE_TEMPLATE
  192. <<: *YARN_CACHE_TEMPLATE
  193. <<: *JEST_REPORT_CACHE_TEMPLATE
  194. gke_container:
  195. <<: *GKE_CONTAINER_TEMPLATE
  196. cpu: 7.5
  197. memory: 20Gb
  198. script:
  199. - ./private/cirrus/cirrus-yarn-validate-ci.sh
  200. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  201. junit_task:
  202. <<: *DEFAULT_TEMPLATE
  203. <<: *GRADLE_CACHE_TEMPLATE
  204. <<: *JUNIT_REPORT_CACHE_TEMPLATE
  205. gke_container:
  206. <<: *GKE_CONTAINER_TEMPLATE
  207. cpu: 7.5
  208. memory: 10Gb
  209. script:
  210. - ./private/cirrus/cirrus-junit.sh
  211. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  212. sq_analysis_task:
  213. <<: *SKIP_PUBLIC_BRANCHES_TEMPLATE
  214. <<: *EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  215. <<: *GRADLE_CACHE_TEMPLATE
  216. <<: *YARN_CACHE_TEMPLATE
  217. <<: *JEST_REPORT_CACHE_TEMPLATE
  218. <<: *ESLINT_REPORT_CACHE_TEMPLATE
  219. <<: *JUNIT_REPORT_CACHE_TEMPLATE
  220. depends_on:
  221. - yarn_validate
  222. - yarn_lint
  223. - junit
  224. gke_container:
  225. <<: *GKE_CONTAINER_TEMPLATE
  226. cpu: 7.5
  227. memory: 15Gb
  228. script:
  229. - ./private/cirrus/cirrus-sq-analysis.sh
  230. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  231. qa_task:
  232. <<: *DEFAULT_TEMPLATE
  233. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  234. <<: *GRADLE_CACHE_TEMPLATE
  235. <<: *JAR_CACHE_TEMPLATE
  236. gke_container:
  237. <<: *GKE_CONTAINER_TEMPLATE
  238. cpu: 2
  239. memory: 6Gb
  240. additional_containers:
  241. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  242. env:
  243. matrix:
  244. - QA_CATEGORY: Cat1
  245. - QA_CATEGORY: Cat2
  246. - QA_CATEGORY: Cat3
  247. - QA_CATEGORY: Cat4
  248. - QA_CATEGORY: Cat5
  249. - QA_CATEGORY: Cat6
  250. - QA_CATEGORY: Analysis
  251. - QA_CATEGORY: Authorization
  252. - QA_CATEGORY: Authentication
  253. - QA_CATEGORY: Branch1
  254. - QA_CATEGORY: Branch2
  255. - QA_CATEGORY: CommunityEdition
  256. - QA_CATEGORY: CommunityEditionWithPlugins
  257. - QA_CATEGORY: ComputeEngine
  258. - QA_CATEGORY: Dev1
  259. - QA_CATEGORY: Dev2
  260. - QA_CATEGORY: Enterprise
  261. - QA_CATEGORY: EnterprisePortfolio
  262. - QA_CATEGORY: Issues1
  263. - QA_CATEGORY: Issues2
  264. - QA_CATEGORY: License1
  265. - QA_CATEGORY: License2
  266. - QA_CATEGORY: Plugins
  267. - QA_CATEGORY: Project
  268. - QA_CATEGORY: QualityProfile
  269. - QA_CATEGORY: Upgrade
  270. script:
  271. - ./private/cirrus/cirrus-qa.sh postgres
  272. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  273. task: #bitbucket
  274. <<: *DEFAULT_TEMPLATE
  275. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  276. <<: *NIGHTLY_TASK_TEMPLATE
  277. <<: *JAR_CACHE_TEMPLATE
  278. <<: *GRADLE_CACHE_TEMPLATE
  279. gke_container:
  280. <<: *GKE_CONTAINER_TEMPLATE
  281. cpu: 3
  282. memory: 10Gb
  283. additional_containers:
  284. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  285. maven_cache:
  286. folder: ~/.m2
  287. env:
  288. QA_CATEGORY: BITBUCKET
  289. matrix:
  290. - name: qa_bb_5.15.0
  291. bitbucket_background_script: ./private/cirrus/cirrus-start-bitbucket.sh 5.15.0
  292. - name: qa_bb_latest
  293. bitbucket_background_script: ./private/cirrus/cirrus-start-bitbucket.sh LATEST
  294. wait_for_bitbucket_to_boot_script: secs=3600; endTime=$(( $(date +%s) + secs )); while [[ "$(curl -s -o /dev/null -w ''%{http_code}'' localhost:7990/bitbucket/status)" != "200" ]] || [ $(date +%s) -gt $endTime ]; do sleep 5; done
  295. script:
  296. - ./private/cirrus/cirrus-qa.sh postgres
  297. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  298. qa_bb_cloud_task:
  299. <<: *DEFAULT_TEMPLATE
  300. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  301. <<: *NIGHTLY_TASK_TEMPLATE
  302. <<: *JAR_CACHE_TEMPLATE
  303. <<: *GRADLE_CACHE_TEMPLATE
  304. gke_container:
  305. <<: *GKE_CONTAINER_TEMPLATE
  306. cpu: 2.4
  307. memory: 5Gb
  308. env:
  309. QA_CATEGORY: BITBUCKET_CLOUD
  310. BBC_CLIENT_ID: VAULT[development/team/sonarqube/kv/data/bitbucket-cloud data.client_id]
  311. BBC_CLIENT_SECRET: VAULT[development/team/sonarqube/kv/data/bitbucket-cloud data.client_secret]
  312. BBC_USERNAME: VAULT[development/kv/data/bitbucket/sonarqube-its data.username]
  313. BBC_READ_REPOS_APP_PASSWORD: VAULT[development/kv/data/bitbucket/sonarqube-its data.password]
  314. script:
  315. - ./private/cirrus/cirrus-qa.sh h2
  316. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  317. qa_ha_task:
  318. <<: *DEFAULT_TEMPLATE
  319. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  320. <<: *NIGHTLY_TASK_TEMPLATE
  321. <<: *JAR_CACHE_TEMPLATE
  322. <<: *GRADLE_CACHE_TEMPLATE
  323. gke_container:
  324. <<: *GKE_CONTAINER_TEMPLATE
  325. cpu: 2.4
  326. memory: 10Gb
  327. additional_containers:
  328. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  329. env:
  330. QA_CATEGORY: HA
  331. script:
  332. - ./private/cirrus/cirrus-qa.sh postgres
  333. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  334. docker_gitlab_container_build_task:
  335. <<: *DEFAULT_TEMPLATE
  336. <<: *NIGHTLY_TASK_TEMPLATE
  337. gce_instance:
  338. image_project: sonarqube-team
  339. image_family: docker-builder
  340. zone: us-central1-a
  341. preemptible: true
  342. disk: 10
  343. cpu: 4
  344. memory: 8G
  345. env:
  346. matrix:
  347. - GITLAB_TAG: latest
  348. - GITLAB_TAG: 11.7.0-ce.0
  349. build_script:
  350. - docker pull "us.gcr.io/sonarqube-team/sq-gitlab:${GITLAB_TAG}" || true
  351. - docker build --build-arg "GITLAB_TAG=${GITLAB_TAG}" --cache-from "us.gcr.io/sonarqube-team/sq-gitlab:${GITLAB_TAG}" -t "us.gcr.io/sonarqube-team/sq-gitlab:${GITLAB_TAG}" private/docker/gitlab/
  352. - docker push "us.gcr.io/sonarqube-team/sq-gitlab:${GITLAB_TAG}"
  353. # GitLab QA is executed in a dedicated task in order to not slow down the pipeline, as a GitLab on-prem server docker image is required.
  354. qa_gitlab_task:
  355. <<: *DEFAULT_TEMPLATE
  356. <<: *NIGHTLY_TASK_TEMPLATE
  357. <<: *JAR_CACHE_TEMPLATE
  358. <<: *GRADLE_CACHE_TEMPLATE
  359. depends_on:
  360. - build
  361. - docker_gitlab_container_build
  362. gke_container:
  363. <<: *GKE_CONTAINER_TEMPLATE
  364. cpu: 2.4
  365. memory: 5Gb
  366. use_in_memory_disk: true
  367. additional_containers:
  368. - name: gitlab
  369. ports:
  370. - 80
  371. - 443
  372. cpu: 2
  373. memory: 5Gb
  374. matrix:
  375. - image: us.gcr.io/sonarqube-team/sq-gitlab:latest
  376. - image: us.gcr.io/sonarqube-team/sq-gitlab:11.7.0-ce.0
  377. env:
  378. QA_CATEGORY: GITLAB
  379. script:
  380. - ./private/cirrus/cirrus-qa.sh h2
  381. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  382. qa_gitlab_cloud_task:
  383. <<: *DEFAULT_TEMPLATE
  384. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  385. <<: *NIGHTLY_TASK_TEMPLATE
  386. <<: *JAR_CACHE_TEMPLATE
  387. <<: *GRADLE_CACHE_TEMPLATE
  388. gke_container:
  389. <<: *GKE_CONTAINER_TEMPLATE
  390. cpu: 2.4
  391. memory: 5Gb
  392. use_in_memory_disk: true
  393. env:
  394. QA_CATEGORY: GITLAB_CLOUD
  395. GITLAB_API_TOKEN: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.api_token]
  396. GITLAB_READ_ONLY_TOKEN: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.api_token_ro]
  397. GITLAB_ADMIN_USERNAME: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.username]
  398. GITLAB_ADMIN_PASSWORD: VAULT[development/team/sonarqube/kv/data/gitlab-cloud data.password]
  399. script:
  400. - ./private/cirrus/cirrus-qa.sh h2
  401. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  402. # Azure QA is executed in a dedicated task in order to not slow down the pipeline.
  403. qa_azure_task:
  404. <<: *DEFAULT_TEMPLATE
  405. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  406. <<: *NIGHTLY_TASK_TEMPLATE
  407. <<: *JAR_CACHE_TEMPLATE
  408. <<: *GRADLE_CACHE_TEMPLATE
  409. gke_container:
  410. <<: *GKE_CONTAINER_TEMPLATE
  411. cpu: 2.4
  412. memory: 5Gb
  413. env:
  414. QA_CATEGORY: AZURE
  415. AZURE_USERNAME_LOGIN: VAULT[development/team/sonarqube/kv/data/azure-instance data.username]
  416. AZURE_CODE_READ_AND_WRITE_TOKEN: VAULT[development/team/sonarqube/kv/data/azure-instance data.token_code_read_write]
  417. AZURE_FULL_ACCESS_TOKEN: VAULT[development/team/sonarqube/kv/data/azure-instance data.token_full_access]
  418. script:
  419. - ./private/cirrus/cirrus-qa.sh h2
  420. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  421. qa_github_task:
  422. <<: *DEFAULT_TEMPLATE
  423. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  424. <<: *NIGHTLY_TASK_TEMPLATE
  425. <<: *JAR_CACHE_TEMPLATE
  426. <<: *GRADLE_CACHE_TEMPLATE
  427. gke_container:
  428. <<: *GKE_CONTAINER_TEMPLATE
  429. cpu: 2.4
  430. memory: 5Gb
  431. env:
  432. QA_CATEGORY: GITHUB
  433. GITHUB_COM_CODE_SCANNING_ALERTS_TECHNICAL_USER_USERNAME: ENCRYPTED[ac65bdcd84c5e5ff164bfffdea5f77b886a8be7f8586a9a9a41f5a648d9fcb33cc2fd5cd7aa6fcda3aa7f0372ccb007b]
  434. GITHUB_COM_CODE_SCANNING_ALERTS_TECHNICAL_USER_TOKEN: ENCRYPTED[ac3877b534eb925c2c7989074a283a6eac83f1e54858e9ff5b97764a78857028dc21added63100cc730b0bb2b8ec4727]
  435. script:
  436. - ./private/cirrus/cirrus-qa.sh h2
  437. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  438. # SAML QA is executed in a dedicated task in order to not slow down the pipeline, as a Keycloak server docker image is required.
  439. qa_saml_task:
  440. <<: *DEFAULT_TEMPLATE
  441. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  442. <<: *SAML_NIGHTLY_TASK_TEMPLATE
  443. <<: *JAR_CACHE_TEMPLATE
  444. <<: *GRADLE_CACHE_TEMPLATE
  445. gke_container:
  446. <<: *GKE_CONTAINER_TEMPLATE
  447. cpu: 2.4
  448. memory: 10Gb
  449. additional_containers:
  450. - name: keycloak
  451. image: quay.io/keycloak/keycloak:17.0.1
  452. port: 8080
  453. cpu: 1
  454. memory: 1Gb
  455. command: "/opt/keycloak/bin/kc.sh start-dev --http-relative-path /auth"
  456. env:
  457. KEYCLOAK_ADMIN: admin
  458. KEYCLOAK_ADMIN_PASSWORD: admin
  459. env:
  460. QA_CATEGORY: SAML
  461. script:
  462. - ./private/cirrus/cirrus-qa.sh h2
  463. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  464. # LDAP QA is executed in a dedicated task in order to not slow down the pipeline, as a LDAP server and SonarQube server are re-started on each test.
  465. qa_ldap_task:
  466. <<: *DEFAULT_TEMPLATE
  467. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  468. <<: *NIGHTLY_TASK_TEMPLATE
  469. <<: *JAR_CACHE_TEMPLATE
  470. <<: *GRADLE_CACHE_TEMPLATE
  471. gke_container:
  472. <<: *GKE_CONTAINER_TEMPLATE
  473. cpu: 2.4
  474. memory: 10Gb
  475. env:
  476. QA_CATEGORY: LDAP
  477. script:
  478. - ./private/cirrus/cirrus-qa.sh h2
  479. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  480. promote_task:
  481. <<: *DEFAULT_TEMPLATE
  482. <<: *EXCEPT_ON_NIGHTLY_TASK_TEMPLATE
  483. depends_on:
  484. - build
  485. - sq_analysis
  486. - qa
  487. - qa_saml
  488. - qa_ldap
  489. - publish
  490. gke_container:
  491. <<: *GKE_CONTAINER_TEMPLATE
  492. memory: 512M
  493. stateful: true
  494. script:
  495. - ./private/cirrus/cirrus-promote.sh
  496. package_docker_task:
  497. <<: *DEFAULT_TEMPLATE
  498. depends_on: promote
  499. only_if: $CIRRUS_BRANCH == $BRANCH_MAIN
  500. gce_instance:
  501. image_project: sonarqube-team
  502. image_family: docker-builder
  503. zone: us-central1-a
  504. disk: 10
  505. cpu: 4
  506. memory: 8G
  507. clone_script: |
  508. git clone --recursive --branch=$CIRRUS_BRANCH https://x-access-token:${CIRRUS_REPO_CLONE_TOKEN}@github.com/${CIRRUS_REPO_FULL_NAME}.git $CIRRUS_WORKING_DIR --depth=1
  509. git fetch origin $CIRRUS_CHANGE_IN_REPO --depth=1
  510. git reset --hard $CIRRUS_CHANGE_IN_REPO
  511. install_tooling_script:
  512. - ./private/cirrus/cirrus-tooling-for-package-docker.sh
  513. package_script:
  514. - ./private/cirrus/cirrus-package-docker.sh
  515. sql_mssql_task:
  516. <<: *DEFAULT_TEMPLATE
  517. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  518. <<: *DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  519. <<: *GRADLE_CACHE_TEMPLATE
  520. gke_container:
  521. <<: *GKE_CONTAINER_TEMPLATE
  522. memory: 5Gb
  523. additional_containers:
  524. - name: mssql
  525. image: mcr.microsoft.com/mssql/server:2019-GA-ubuntu-16.04
  526. port: 1433
  527. cpu: 2
  528. memory: 5Gb
  529. env:
  530. MSSQL_PID: Developer # this is the default edition
  531. ACCEPT_EULA: Y
  532. SA_PASSWORD: sonarqube!1
  533. script:
  534. - ./private/cirrus/cirrus-db-unit-test.sh mssql
  535. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  536. sql_postgres_task:
  537. <<: *DEFAULT_TEMPLATE
  538. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  539. <<: *DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  540. <<: *GRADLE_CACHE_TEMPLATE
  541. gke_container:
  542. <<: *GKE_CONTAINER_TEMPLATE
  543. memory: 5Gb
  544. additional_containers:
  545. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  546. script:
  547. - ./private/cirrus/cirrus-db-unit-test.sh postgres
  548. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  549. # this is the oldest compatible version of PostgreSQL
  550. sql_postgres11_task:
  551. <<: *DEFAULT_TEMPLATE
  552. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  553. <<: *DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  554. <<: *GRADLE_CACHE_TEMPLATE
  555. gke_container:
  556. <<: *GKE_CONTAINER_TEMPLATE
  557. memory: 5Gb
  558. additional_containers:
  559. - <<: *POSTGRES_ADDITIONAL_CONTAINER_TEMPLATE
  560. image: postgres:11
  561. script:
  562. - ./private/cirrus/cirrus-db-unit-test.sh postgres
  563. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  564. sql_oracle12_task:
  565. <<: *DEFAULT_TEMPLATE
  566. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  567. <<: *DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  568. <<: *GRADLE_CACHE_TEMPLATE
  569. gke_container:
  570. <<: *GKE_CONTAINER_TEMPLATE
  571. memory: 5Gb
  572. additional_containers:
  573. - <<: *ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  574. script:
  575. - ./private/cirrus/cirrus-db-unit-test.sh oracle12
  576. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  577. upgd_mssql_task:
  578. <<: *DEFAULT_TEMPLATE
  579. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  580. <<: *DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  581. <<: *JAR_CACHE_TEMPLATE
  582. <<: *GRADLE_CACHE_TEMPLATE
  583. gke_container:
  584. <<: *GKE_CONTAINER_TEMPLATE
  585. cpu: 1.5
  586. memory: 6Gb
  587. additional_containers:
  588. - name: mssql
  589. image: mcr.microsoft.com/mssql/server:2019-GA-ubuntu-16.04
  590. port: 1433
  591. cpu: 2
  592. memory: 5Gb
  593. env:
  594. MSSQL_PID: Developer # this is the default edition
  595. ACCEPT_EULA: Y
  596. SA_PASSWORD: sonarqube!1
  597. env:
  598. QA_CATEGORY: Upgrade
  599. script:
  600. - ./private/cirrus/cirrus-qa.sh mssql
  601. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  602. upgd_oracle12_task:
  603. <<: *DEFAULT_TEMPLATE
  604. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  605. <<: *DATABASE_RELATED_NIGHTLY_TASK_TEMPLATE
  606. <<: *JAR_CACHE_TEMPLATE
  607. <<: *GRADLE_CACHE_TEMPLATE
  608. gke_container:
  609. <<: *GKE_CONTAINER_TEMPLATE
  610. cpu: 1.5
  611. memory: 6Gb
  612. additional_containers:
  613. - <<: *ORACLE_ADDITIONAL_CONTAINER_TEMPLATE
  614. env:
  615. QA_CATEGORY: Upgrade
  616. script:
  617. - ./private/cirrus/cirrus-qa.sh oracle12
  618. <<: *DEFAULT_ARTIFACTS_TEMPLATE
  619. ws_scan_task:
  620. <<: *DEFAULT_TEMPLATE
  621. <<: *BUILD_DEPENDANT_TASK_TEMPLATE
  622. only_if: >-
  623. $CIRRUS_BRANCH == $BRANCH_MAIN ||
  624. ($CIRRUS_BRANCH =~ $BRANCH_PATTERN_MAINTENANCE && $CIRRUS_BRANCH != $BRANCH_NIGHTLY)
  625. <<: *YARN_CACHE_TEMPLATE
  626. <<: *GRADLE_CACHE_TEMPLATE
  627. timeout_in: 30m
  628. gke_container:
  629. <<: *GKE_CONTAINER_TEMPLATE
  630. cpu: 2
  631. memory: 4Gb
  632. env:
  633. WS_APIKEY: VAULT[development/kv/data/mend data.apikey]
  634. WS_WSS_URL: VAULT[development/kv/data/mend data.url]
  635. WS_USERKEY: VAULT[development/kv/data/mend data.userKey]
  636. SLACK_WEBHOOK_SQ: VAULT[development/kv/data/slack data.webhook]
  637. whitesource_script:
  638. - ./private/cirrus/cirrus-whitesource-scan.sh
  639. allow_failures: "true"
  640. on_failure:
  641. slack_notification_script:
  642. - ./private/cirrus/cirrus-whitesource-notifications.sh
  643. always:
  644. ws_artifacts:
  645. path: "whitesource/**/*"