ci: every push is tracked in GLPI
This commit is contained in:
1 parent
ffe6ae1a2c
commit
74c0fdf934
2 files changed
+182
No files matched your search
@@ -0,0 +1,61 @@
|
||||
#!/usr/bin/env bash
|
||||
# The tracking of this run in GLPI: a Change for every push, a release for
|
||||
# every version (warda-docs, ci/README.md). This file is the same in every
|
||||
# repository (its source: warda-dns/warda-ci, .gitea/scripts/glpi-track.sh).
|
||||
# It fetches the tracker, branch main of <owner>/warda-ci, into a temporary
|
||||
# directory outside the workspace, and runs it in the checkout of the job:
|
||||
# glpi-track.sh start | failed <job> | passed
|
||||
# It never fails and never waits long (a fetch is stopped after 20 seconds,
|
||||
# then come the bounds of the tracker): what goes wrong is told in a line
|
||||
# "::warning::GLPI tracking: ..." and the status is 0.
|
||||
# Environment: GLPI_API_URL, GLPI_APP_TOKEN, GLPI_USER_TOKEN (organization
|
||||
# settings; one missing: nothing is done); WARDA_CI_READ_TOKEN, a token that
|
||||
# reads warda-ci (needed when that repository is private); WARDA_CI_URL and
|
||||
# WARDA_CI_REF, to fetch the tracker elsewhere (its own tests, or a tag of
|
||||
# warda-ci in place of its branch main).
|
||||
set -u
|
||||
if [ -z "${GLPI_API_URL:-}" ] || [ -z "${GLPI_APP_TOKEN:-}" ] || [ -z "${GLPI_USER_TOKEN:-}" ]; then
|
||||
echo "::notice::GLPI tracking: skipped, organization settings missing (variable GLPI_API_URL, secrets GLPI_APP_TOKEN and GLPI_USER_TOKEN)"
|
||||
exit 0
|
||||
fi
|
||||
owner="${GITHUB_REPOSITORY_OWNER:-}"
|
||||
if [ -z "$owner" ]; then
|
||||
case "${GITHUB_REPOSITORY:-}" in */*) owner="${GITHUB_REPOSITORY%%/*}" ;; esac
|
||||
fi
|
||||
url="${WARDA_CI_URL:-${GITHUB_SERVER_URL:-}/${owner:-warda-dns}/warda-ci.git}"
|
||||
ref="${WARDA_CI_REF:-main}"
|
||||
dir="$(mktemp -d)" || { echo "::warning::GLPI tracking: no temporary directory: nothing is written by this step"; exit 0; }
|
||||
trap 'rm -rf "$dir"' EXIT
|
||||
export GIT_TERMINAL_PROMPT=0
|
||||
fetch=(git clone --quiet --depth=1 --branch "$ref" "$url" "$dir/warda-ci")
|
||||
if command -v timeout >/dev/null 2>&1; then fetch=(timeout -k 5 20 "${fetch[@]}"); fi
|
||||
status=1
|
||||
auth=""
|
||||
if [ -n "${WARDA_CI_READ_TOKEN:-}" ]; then
|
||||
auth="$(printf 'ci:%s' "$WARDA_CI_READ_TOKEN" | base64 2>/dev/null | tr -d '\n')" || auth=""
|
||||
fi
|
||||
unset WARDA_CI_READ_TOKEN
|
||||
if [ -n "$auth" ]; then
|
||||
# Gitea takes the token as the password. The header is masked and goes
|
||||
# through the environment of git, neither in the log nor on its command line.
|
||||
echo "::add-mask::$auth"
|
||||
status=0
|
||||
GIT_CONFIG_COUNT=1 GIT_CONFIG_KEY_0=http.extraHeader GIT_CONFIG_VALUE_0="Authorization: Basic $auth" \
|
||||
"${fetch[@]}" >/dev/null 2>&1 || status=$?
|
||||
fi
|
||||
if [ "$status" != 0 ] && [ "$status" != 124 ] && [ "$status" != 137 ]; then
|
||||
# Without a token; or once more without it: a token that Gitea refuses
|
||||
# (expired, unknown) is refused for a public repository too. Not after a
|
||||
# fetch that was stopped for its time: Gitea does not answer.
|
||||
rm -rf "$dir/warda-ci"
|
||||
status=0
|
||||
"${fetch[@]}" >/dev/null 2>&1 || status=$?
|
||||
fi
|
||||
if [ "$status" != 0 ]; then
|
||||
echo "::warning::GLPI tracking: the tracker (branch $ref of ${url%.git}) could not be fetched (git clone: status $status): nothing is written by this step"
|
||||
elif [ ! -f "$dir/warda-ci/glpi/glpi-track.sh" ]; then
|
||||
echo "::warning::GLPI tracking: no glpi/glpi-track.sh in the branch $ref of ${url%.git}: nothing is written by this step"
|
||||
else
|
||||
GLPI_TRACK_STUB="${BASH_SOURCE[0]}" bash "$dir/warda-ci/glpi/glpi-track.sh" "$@" || true
|
||||
fi
|
||||
exit 0
|
||||
@@ -28,6 +28,24 @@
|
||||
#
|
||||
# Promotion: every push of develop whose checks pass is pushed on main
|
||||
# (fast-forward only) with the secret RELEASE_TOKEN.
|
||||
#
|
||||
# GLPI: every push is a Change of the support platform, closed when the
|
||||
# CI of main passes (no numbered version: no release). Steps of the jobs
|
||||
# below say it, each for its own job: the first step of the job test, that
|
||||
# the push is received and the tests start; the last step of a job that
|
||||
# failed, that it failed; the last step of the last job (promote on
|
||||
# develop, build on main), that the run passed. They run
|
||||
# .gitea/scripts/glpi-track.sh, which fetches the tracker shared by every
|
||||
# repository (branch main of warda-dns/warda-ci; warda-docs, ci/README.md).
|
||||
# The pushes only: neither the daily build, a run by hand nor a pull
|
||||
# request. GLPI never fails nor blocks a run: these steps always end well
|
||||
# (a warning at most, in a time of their own), no job waits for them, and
|
||||
# without the organization settings below nothing is done. A run that is
|
||||
# cancelled says nothing: the next push completes its Change.
|
||||
# Organization settings: variable GLPI_API_URL (the REST API of GLPI),
|
||||
# secrets GLPI_APP_TOKEN and GLPI_USER_TOKEN (the API client and the
|
||||
# account of the CI in GLPI); secret WARDA_CI_READ_TOKEN, optional (a
|
||||
# token that reads warda-ci: needed when that repository is private).
|
||||
name: CI
|
||||
|
||||
on:
|
||||
@@ -62,6 +80,10 @@ env:
|
||||
# Raise it if the build is killed (exit code 137).
|
||||
BUILD_MEMORY: 3g
|
||||
LISTS_URL: https://gitea.tips-of-mine.com/warda-dns/warda-lists/raw/branch/dist
|
||||
# The tracking of this repository in GLPI: no numbered version, and what
|
||||
# its branch main delivers.
|
||||
GLPI_TRACK_RELEASES: "false"
|
||||
GLPI_TRACK_PUBLISHED: listes publiées
|
||||
|
||||
jobs:
|
||||
test:
|
||||
@@ -76,6 +98,24 @@ jobs:
|
||||
with:
|
||||
ref: ${{ (github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && 'main' || '' }}
|
||||
|
||||
# GLPI: the Change of this push (a new one, or the open one of the
|
||||
# repository), moved to "En test". Not on main: its Changes were
|
||||
# written by the run of develop, and move when the run ends; never for
|
||||
# the daily build nor a run by hand. Never fails the job; 9 seconds
|
||||
# when GLPI does not answer, 25 at most when it answers slowly
|
||||
# (measured: warda-docs, ci/README.md).
|
||||
- name: "GLPI: the push is received, the tests start"
|
||||
if: github.event_name == 'push' && github.ref != 'refs/heads/main'
|
||||
continue-on-error: true
|
||||
timeout-minutes: 3
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh start || true
|
||||
|
||||
# The tests of the builder: names read as Warda reads them, the three
|
||||
# plain formats, a UT1-style archive, exceptions, allow.txt,
|
||||
# protect.txt, the files of warda-analyst, the figures of the
|
||||
@@ -125,6 +165,20 @@ jobs:
|
||||
test -s /tmp/dist/licenses/GPL-3.0-only.txt
|
||||
echo "offline build checked"'
|
||||
|
||||
# GLPI: the last step of each job says the job failed (the Change
|
||||
# back to "En attente"); it never fails nor blocks anything itself.
|
||||
- name: "GLPI: this job failed"
|
||||
if: failure() && github.event_name == 'push'
|
||||
continue-on-error: true
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh failed test || true
|
||||
|
||||
# Security: secrets committed by mistake. A finding stops the promotion
|
||||
# and the publication of the lists, as a failed test does.
|
||||
security:
|
||||
@@ -148,6 +202,18 @@ jobs:
|
||||
--entrypoint sh "$GITLEAKS_IMAGE" \
|
||||
-c 'mkdir /repo && tar -x -C /repo && gitleaks dir /repo --redact -v --no-banner'
|
||||
|
||||
- name: "GLPI: this job failed"
|
||||
if: failure() && github.event_name == 'push'
|
||||
continue-on-error: true
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh failed security || true
|
||||
|
||||
build:
|
||||
name: Build and publish the lists
|
||||
needs: [test, security]
|
||||
@@ -245,6 +311,36 @@ jobs:
|
||||
git push --force --quiet "${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}.git" HEAD:refs/heads/dist
|
||||
echo "published: $LISTS_URL/"
|
||||
|
||||
# The steps of GLPI run for a push of main only: the daily build and a
|
||||
# run by hand write nothing. The commit of the run is the one of the
|
||||
# event (GITHUB_SHA), not the head of main checked out above.
|
||||
- name: "GLPI: this job failed"
|
||||
if: failure() && github.event_name == 'push'
|
||||
continue-on-error: true
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh failed build || true
|
||||
|
||||
# GLPI: the last job of a run of main (the lists are published: its
|
||||
# Changes "Appliqué", then closed). On develop the last word is the
|
||||
# promotion's.
|
||||
- name: "GLPI: the run passed"
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
continue-on-error: true
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh passed || true
|
||||
|
||||
# Promotion: a commit of develop that passed the checks is pushed on main
|
||||
# (fast-forward only, never forced); the CI of main runs on it and
|
||||
# publishes the lists. If main holds a commit that develop does not have,
|
||||
@@ -282,3 +378,28 @@ jobs:
|
||||
GIT_CONFIG_KEY_0=http.extraHeader \
|
||||
GIT_CONFIG_VALUE_0="Authorization: Basic $auth" \
|
||||
git push origin "$GITHUB_SHA:refs/heads/main"
|
||||
|
||||
- name: "GLPI: this job failed"
|
||||
if: failure() && github.event_name == 'push'
|
||||
continue-on-error: true
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh failed promote || true
|
||||
|
||||
# GLPI: the last job of a run of develop: tested, promoted
|
||||
# ("Qualification"); the run of main says the rest.
|
||||
- name: "GLPI: the tests passed, the commit is promoted"
|
||||
continue-on-error: true
|
||||
timeout-minutes: 5
|
||||
env:
|
||||
GLPI_API_URL: ${{ vars.GLPI_API_URL }}
|
||||
GLPI_APP_TOKEN: ${{ secrets.GLPI_APP_TOKEN }}
|
||||
GLPI_USER_TOKEN: ${{ secrets.GLPI_USER_TOKEN }}
|
||||
GLPI_TRACK_BEFORE: ${{ github.event.before }}
|
||||
WARDA_CI_READ_TOKEN: ${{ secrets.WARDA_CI_READ_TOKEN || github.token }}
|
||||
run: bash .gitea/scripts/glpi-track.sh passed || true
|
||||
Reference in new issue
Block a user