vulnerability python upgrade fix #257
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Branch Build clouddriver 1.33.x | |
on: | |
workflow_call: | |
push: | |
branches: | |
- bugfix/OP-22785-OES-1.33.x | |
env: | |
GRADLE_OPTS: -Dorg.gradle.daemon=false -Xmx6g -Xms6g | |
CONTAINER_REGISTRY: quay.io/opsmxpublic | |
jobs: | |
build-clouddriver: | |
runs-on: ubuntu-latest | |
outputs: | |
clouddriver: ${{ steps.get-build-name.outputs.clouddriver }} | |
steps: | |
- uses: actions/checkout@v2 | |
with: | |
fetch-depth: 0 | |
- name: Set up QEMU | |
uses: docker/setup-qemu-action@v2 | |
- name: Set up Docker Buildx | |
uses: docker/setup-buildx-action@v2 | |
- uses: actions/setup-java@v2 | |
with: | |
java-version: 17 | |
distribution: 'temurin' | |
- name: Prepare build variables | |
id: build_variables | |
run: | | |
echo ::set-output name=REPO::ubi8-clouddriver-cve | |
#echo ::set-output name=VERSION::"1.33.0$(date --utc +'%Y%m%d')" | |
echo ::set-output name=VERSION::"1.33.3" | |
echo "::set-output name=GITHASH::$(git rev-parse --short HEAD)" | |
echo "::set-output name=BUILDDATE::$(date -u +"%Y%m%d%H%M")" | |
- name: Login to Quay | |
uses: docker/login-action@v1 | |
# use service account flow defined at: https://github.com/docker/login-action#service-account-based-authentication-1 | |
with: | |
registry: quay.io | |
username: ${{ secrets.QUAY_USERNAME }} | |
password: ${{ secrets.QUAY_KEY }} | |
- name: Build | |
env: | |
ORG_GRADLE_PROJECT_version: ${{ steps.build_variables.outputs.VERSION }} | |
run: | | |
sed -e 's|NEXUS_USERNAME|${{ secrets.NEXUS_USERNAME }}|' -i settings.gradle | |
sed -e 's|NEXUS_PASSWORD|${{ secrets.NEXUS_PASSWORD }}|' -i settings.gradle | |
sed -e 's|NEXUS_USERNAME|${{ secrets.NEXUS_USERNAME }}|' -i build.gradle | |
sed -e 's|NEXUS_PASSWORD|${{ secrets.NEXUS_PASSWORD }}|' -i build.gradle | |
sed -e 's|NEXUS_URL|${{ secrets.NEXUS_URL }}|' -i settings.gradle | |
sed -e 's|NEXUS_URL|${{ secrets.NEXUS_URL }}|' -i build.gradle | |
./gradlew --no-daemon -PenableCrossCompilerPlugin=true clouddriver-web:installDist -x test | |
#./gradlew --no-daemon clouddriver-web:installDist -x test | |
#extra_opts='"--add-opens=java.base/sun.net=ALL-UNNAMED" "--add-exports=java.base/sun.net=ALL-UNNAMED" "--add-opens=java.base/java.time=ALL-UNNAMED"' | |
extra_opts='"-Djava.security.egd=file:/dev/./urandom" "-Dspring.config.import=optional:/opt/spinnaker/config/" "--add-opens=java.base/sun.net=ALL-UNNAMED" "--add-exports=java.base/sun.net=ALL-UNNAMED" "--add-opens=java.base/java.time=ALL-UNNAMED" "--add-exports=java.base/sun.security.rsa=ALL-UNNAMED" "--add-exports=java.base/sun.security.pkcs=ALL-UNNAMED" "--add-exports=java.base/sun.security.x509=ALL-UNNAMED"' | |
extra_opts_escaped=$(sed 's/[\/&]/\\&/g' <<< "$extra_opts") | |
echo $extra_opts_escaped | |
#sed "s/^\(DEFAULT_JVM_OPTS=\'.*\)\'$/\1 $extra_opts_escaped\'/" -i clouddriver-web/build/install/clouddriver/bin/clouddriver | |
sed "s/^\(DEFAULT_JVM_OPTS\)\s*=\s*'.*'\$/\1='$extra_opts_escaped'/" -i clouddriver-web/build/install/clouddriver/bin/clouddriver | |
cat clouddriver-web/build/install/clouddriver/bin/clouddriver | |
- name: dockerBuildpush | |
uses: docker/build-push-action@v2 | |
with: | |
context: . | |
build-args: | | |
TARGETARCH=amd64 | |
CUSTOMPLUGIN_RELEASEORG=opsmx | |
CUSTOMPLUGIN_RELEASEREPO=armory-observability-plugin | |
CUSTOMPLUGIN_RELEASE_VERSION=1.0.1 | |
file: docker/ubi8/Dockerfile-fips | |
#file: Dockerfile.slim | |
push: true | |
tags: | | |
"${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}" | |
- name: dockerBuildpushjaeger | |
uses: docker/build-push-action@v2 | |
with: | |
context: . | |
build-args: | | |
TARGETARCH=amd64 | |
CUSTOMPLUGIN_RELEASEORG=opsmx | |
CUSTOMPLUGIN_RELEASEREPO=armory-observability-plugin | |
CUSTOMPLUGIN_RELEASE_VERSION=1.0.1 | |
file: docker/ubi8/Dockerfile-dev | |
push: true | |
tags: | | |
"${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}-dev" | |
- id: get-build-name | |
run: | | |
imageName="${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}" | |
echo "clouddriver=$imageName" >> $GITHUB_OUTPUT | |
outputs: | |
runs-on: ubuntu-latest | |
needs: [build-clouddriver] | |
steps: | |
- name: Che4ck out repository code | |
uses: actions/checkout@v3 | |
# with: | |
# repository: opsmx/cve-target | |
# ref: refs/heads/main | |
- run: | | |
echo " " | |
# echo artifactId: ${{ needs.build-clouddriver.outputs.clouddriver }} > default/service-settings/clouddriver.yml | |
# git config user.name github-actions | |
# git config user.email [email protected] | |
# git add . | |
# git commit -m "updating master Branch images into service settings" | |
env: | |
GITHUB_TOKEN: ${{ secrets.GIT_TOKEN }} |