Skip to content

vulnerability python upgrade fix #257

vulnerability python upgrade fix

vulnerability python upgrade fix #257

name: Branch Build clouddriver 1.33.x
on:
workflow_call:
push:
branches:
- bugfix/OP-22785-OES-1.33.x
env:
GRADLE_OPTS: -Dorg.gradle.daemon=false -Xmx6g -Xms6g
CONTAINER_REGISTRY: quay.io/opsmxpublic
jobs:
build-clouddriver:
runs-on: ubuntu-latest
outputs:
clouddriver: ${{ steps.get-build-name.outputs.clouddriver }}
steps:
- uses: actions/checkout@v2
with:
fetch-depth: 0
- name: Set up QEMU
uses: docker/setup-qemu-action@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- uses: actions/setup-java@v2
with:
java-version: 17
distribution: 'temurin'
- name: Prepare build variables
id: build_variables
run: |
echo ::set-output name=REPO::ubi8-clouddriver-cve
#echo ::set-output name=VERSION::"1.33.0$(date --utc +'%Y%m%d')"
echo ::set-output name=VERSION::"1.33.3"
echo "::set-output name=GITHASH::$(git rev-parse --short HEAD)"
echo "::set-output name=BUILDDATE::$(date -u +"%Y%m%d%H%M")"
- name: Login to Quay
uses: docker/login-action@v1
# use service account flow defined at: https://github.com/docker/login-action#service-account-based-authentication-1
with:
registry: quay.io
username: ${{ secrets.QUAY_USERNAME }}
password: ${{ secrets.QUAY_KEY }}
- name: Build
env:
ORG_GRADLE_PROJECT_version: ${{ steps.build_variables.outputs.VERSION }}
run: |
sed -e 's|NEXUS_USERNAME|${{ secrets.NEXUS_USERNAME }}|' -i settings.gradle
sed -e 's|NEXUS_PASSWORD|${{ secrets.NEXUS_PASSWORD }}|' -i settings.gradle
sed -e 's|NEXUS_USERNAME|${{ secrets.NEXUS_USERNAME }}|' -i build.gradle
sed -e 's|NEXUS_PASSWORD|${{ secrets.NEXUS_PASSWORD }}|' -i build.gradle
sed -e 's|NEXUS_URL|${{ secrets.NEXUS_URL }}|' -i settings.gradle
sed -e 's|NEXUS_URL|${{ secrets.NEXUS_URL }}|' -i build.gradle
./gradlew --no-daemon -PenableCrossCompilerPlugin=true clouddriver-web:installDist -x test
#./gradlew --no-daemon clouddriver-web:installDist -x test
#extra_opts='"--add-opens=java.base/sun.net=ALL-UNNAMED" "--add-exports=java.base/sun.net=ALL-UNNAMED" "--add-opens=java.base/java.time=ALL-UNNAMED"'
extra_opts='"-Djava.security.egd=file:/dev/./urandom" "-Dspring.config.import=optional:/opt/spinnaker/config/" "--add-opens=java.base/sun.net=ALL-UNNAMED" "--add-exports=java.base/sun.net=ALL-UNNAMED" "--add-opens=java.base/java.time=ALL-UNNAMED" "--add-exports=java.base/sun.security.rsa=ALL-UNNAMED" "--add-exports=java.base/sun.security.pkcs=ALL-UNNAMED" "--add-exports=java.base/sun.security.x509=ALL-UNNAMED"'
extra_opts_escaped=$(sed 's/[\/&]/\\&/g' <<< "$extra_opts")
echo $extra_opts_escaped
#sed "s/^\(DEFAULT_JVM_OPTS=\'.*\)\'$/\1 $extra_opts_escaped\'/" -i clouddriver-web/build/install/clouddriver/bin/clouddriver
sed "s/^\(DEFAULT_JVM_OPTS\)\s*=\s*'.*'\$/\1='$extra_opts_escaped'/" -i clouddriver-web/build/install/clouddriver/bin/clouddriver
cat clouddriver-web/build/install/clouddriver/bin/clouddriver
- name: dockerBuildpush
uses: docker/build-push-action@v2
with:
context: .
build-args: |
TARGETARCH=amd64
CUSTOMPLUGIN_RELEASEORG=opsmx
CUSTOMPLUGIN_RELEASEREPO=armory-observability-plugin
CUSTOMPLUGIN_RELEASE_VERSION=1.0.1
file: docker/ubi8/Dockerfile-fips
#file: Dockerfile.slim
push: true
tags: |
"${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}"
- name: dockerBuildpushjaeger
uses: docker/build-push-action@v2
with:
context: .
build-args: |
TARGETARCH=amd64
CUSTOMPLUGIN_RELEASEORG=opsmx
CUSTOMPLUGIN_RELEASEREPO=armory-observability-plugin
CUSTOMPLUGIN_RELEASE_VERSION=1.0.1
file: docker/ubi8/Dockerfile-dev
push: true
tags: |
"${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}-dev"
- id: get-build-name
run: |
imageName="${{ env.CONTAINER_REGISTRY }}/${{ steps.build_variables.outputs.REPO }}:${{ steps.build_variables.outputs.VERSION }}-${{ steps.build_variables.outputs.GITHASH }}-${{ steps.build_variables.outputs.BUILDDATE }}"
echo "clouddriver=$imageName" >> $GITHUB_OUTPUT
outputs:
runs-on: ubuntu-latest
needs: [build-clouddriver]
steps:
- name: Che4ck out repository code
uses: actions/checkout@v3
# with:
# repository: opsmx/cve-target
# ref: refs/heads/main
- run: |
echo " "
# echo artifactId: ${{ needs.build-clouddriver.outputs.clouddriver }} > default/service-settings/clouddriver.yml
# git config user.name github-actions
# git config user.email [email protected]
# git add .
# git commit -m "updating master Branch images into service settings"
env:
GITHUB_TOKEN: ${{ secrets.GIT_TOKEN }}