Skip to content

[main] Update common Docker engineering infrastructure with latest #1256

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions eng/common/templates/1es-official.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
# do the following:
#
# - Do not rely on any source code from the versions repo so as to not circumvent SDL and CG guidelines
# - The versions repo resource must be named `InternalVersionsRepo` or `PublicVersionsRepo` to avoid SDL scans
# - The versions repo resource must be named `VersionsRepo` to avoid SDL scans
# - The versions repo must be checked out to `$(Build.SourcesDirectory)/versions` to avoid CG scans
#
# If the pipeline is not using a separate repository resource, ensure that there is no source code checked out in
Expand Down Expand Up @@ -57,14 +57,14 @@ extends:
enabled: true
sourceRepositoriesToScan:
exclude:
- repository: InternalVersionsRepo
- repository: PublicVersionsRepo
- repository: VersionsRepo
sourceAnalysisPool: ${{ parameters.sourceAnalysisPool }}
tsa:
enabled: true
stages:
- template: /eng/common/templates/stages/setup-service-connections.yml@self
parameters:
pool: ${{ parameters.pool }}
serviceConnections: ${{ parameters.serviceConnections }}
- ${{ if gt(length(parameters.serviceConnections), 0) }}:
- template: /eng/common/templates/stages/setup-service-connections.yml@self
parameters:
pool: ${{ parameters.pool }}
serviceConnections: ${{ parameters.serviceConnections }}
- ${{ parameters.stages }}
9 changes: 5 additions & 4 deletions eng/common/templates/1es-unofficial.yml
Original file line number Diff line number Diff line change
Expand Up @@ -71,8 +71,9 @@ extends:
tsa:
enabled: true
stages:
- template: /eng/common/templates/stages/setup-service-connections.yml@self
parameters:
pool: ${{ parameters.pool }}
serviceConnections: ${{ parameters.serviceConnections }}
- ${{ if gt(length(parameters.serviceConnections), 0) }}:
- template: /eng/common/templates/stages/setup-service-connections.yml@self
parameters:
pool: ${{ parameters.pool }}
serviceConnections: ${{ parameters.serviceConnections }}
- ${{ parameters.stages }}
13 changes: 9 additions & 4 deletions eng/common/templates/jobs/build-images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ jobs:
# all we need is for that value to be in a PowerShell variable, we can get that by the fact that AzDO automatically creates
# the environment variable for us.
$imageBuilderBuildArgs = "$env:IMAGEBUILDERBUILDARGS $(imageBuilder.queueArgs) --image-info-output-path $(imageInfoContainerDir)/$(legName)-image-info.json $(commonMatrixAndBuildOptions)"
if ($env:SYSTEM_TEAMPROJECT -eq "${{ parameters.internalProjectName }}" -and $env:BUILD_REASON -ne "PullRequest" -and "${{ parameters.isInternalServicingValidation }}" -ne "true") {
if ($env:SYSTEM_TEAMPROJECT -eq "${{ parameters.internalProjectName }}" -and $env:BUILD_REASON -ne "PullRequest") {
$imageBuilderBuildArgs = "$imageBuilderBuildArgs --repo-prefix $(stagingRepoPrefix) --push"
}

Expand All @@ -70,6 +70,11 @@ jobs:
id: $(build.serviceConnection.id)
tenantId: $(build.serviceConnection.tenantId)
clientId: $(build.serviceConnection.clientId)
- ${{ if eq(parameters.isInternalServicingValidation, true) }}:
- name: storage
id: $(dotnetstaging.serviceConnection.id)
tenantId: $(dotnetstaging.serviceConnection.tenantId)
clientId: $(dotnetstaging.serviceConnection.clientId)
internalProjectName: ${{ parameters.internalProjectName }}
dockerClientOS: ${{ parameters.dockerClientOS }}
args: >-
Expand All @@ -92,7 +97,7 @@ jobs:
displayName: Publish Image Info File Artifact
internalProjectName: ${{ parameters.internalProjectName }}
publicProjectName: ${{ parameters.publicProjectName }}
- ${{ if and(eq(variables['System.TeamProject'], parameters.internalProjectName), ne(variables['Build.Reason'], 'PullRequest'), eq(parameters.isInternalServicingValidation, 'false')) }}:
- ${{ if and(eq(variables['System.TeamProject'], parameters.internalProjectName), ne(variables['Build.Reason'], 'PullRequest')) }}:
# The following task depends on the SBOM Manifest Generator task installed on the agent.
# This task is auto-injected by 1ES Pipeline Templates so we don't need to install it ourselves.
- powershell: |
Expand Down Expand Up @@ -144,11 +149,11 @@ jobs:
}
displayName: Generate SBOMs
condition: and(succeeded(), ne(variables['BuildImages.builtImages'], ''))
- ${{ if or(eq(variables['Build.Reason'], 'PullRequest'), eq(parameters.isInternalServicingValidation, 'true')) }}:
- ${{ if eq(variables['Build.Reason'], 'PullRequest') }}:
- template: /eng/common/templates/jobs/${{ format('../steps/test-images-{0}-client.yml', parameters.dockerClientOS) }}@self
parameters:
condition: ne(variables.testScriptPath, '')
- ${{ if and(eq(variables['System.TeamProject'], parameters.internalProjectName), ne(variables['Build.Reason'], 'PullRequest'), eq(parameters.isInternalServicingValidation, 'false')) }}:
- ${{ if and(eq(variables['System.TeamProject'], parameters.internalProjectName), ne(variables['Build.Reason'], 'PullRequest')) }}:
- template: /eng/common/templates/steps/publish-artifact.yml@self
parameters:
path: $(sbomDirectory)
Expand Down
33 changes: 27 additions & 6 deletions eng/common/templates/jobs/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,11 @@ parameters:
customPublishVariables: []
sourceBuildPipelineDefinitionId: ""
sourceBuildPipelineRunId: ""
versionsRepoRef: null
versionsRepoPath: ""
# When true, overrides the commit SHA in merged image info files to use the current repository commit.
# This ensures that updated images reference the correct commit in their commitUrl properties.
overrideImageInfoCommit: false

jobs:
- job: Publish
Expand All @@ -31,16 +36,28 @@ jobs:
value: $(artifactsPath)/imageInfo
- name: sourceBuildIdOutputDir
value: $(Build.ArtifactStagingDirectory)/sourceBuildId
- name: commitOverrideArg
${{ if eq(parameters.overrideImageInfoCommit, true) }}:
value: --commit-override $(Build.SourceVersion)
${{ else }}:
value: ''
- ${{ parameters.customPublishVariables }}

steps:
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
cloneVersionsRepo: ${{ variables.publishImageInfo }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}

- template: /eng/common/templates/steps/retain-build.yml@self

- template: /eng/common/templates/steps/init-docker-linux.yml@self

- pwsh: |
$azdoOrgName = Split-Path -Leaf $Env:SYSTEM_COLLECTIONURI
echo "##vso[task.setvariable variable=azdoOrgName]$azdoOrgName"
$versionsRepoRoot = "$(Pipeline.Workspace)/s/${{ parameters.versionsRepoPath }}"
echo "##vso[task.setvariable variable=versionsRepoRoot]$versionsRepoRoot"
displayName: Set Publish Variables

- ${{ parameters.customInitSteps }}
Expand Down Expand Up @@ -138,13 +155,16 @@ jobs:
- script: mkdir -p $(Build.ArtifactStagingDirectory)/eol-annotation-data
displayName: Create EOL Annotation Data Directory

- powershell: >-
$(engCommonPath)/Invoke-WithRetry.ps1
"curl -fSL
--output $(imageInfoHostDir)/full-image-info-orig.json
https://raw.githubusercontent.com/$(gitHubVersionsRepoInfo.org)/$(gitHubVersionsRepoInfo.repo)/refs/heads/$(gitHubVersionsRepoInfo.branch)/$(gitHubImageInfoVersionsPath)"
- script: |-
cd $(versionsRepoRoot)
git pull origin $(gitHubVersionsRepoInfo.branch)
condition: and(succeeded(), eq(variables['publishImageInfo'], 'true'))
displayName: Pull Latest Changes from Versions Repo

- script: >-
cp $(versionsRepoRoot)/$(gitHubImageInfoVersionsPath) $(imageInfoHostDir)/full-image-info-orig.json
condition: and(succeeded(), eq(variables['publishImageInfo'], 'true'))
displayName: Download Latest Image Info
displayName: Copy Latest Image Info from Versions Repo

- script: >
$(runImageBuilderCmd) mergeImageInfo
Expand All @@ -155,6 +175,7 @@ jobs:
--manifest $(manifest)
--publish
--initial-image-info-path $(imageInfoContainerDir)/full-image-info-orig.json
$(commitOverrideArg)
condition: and(succeeded(), eq(variables['publishImageInfo'], 'true'))
displayName: Merge Image Info

Expand Down
74 changes: 25 additions & 49 deletions eng/common/templates/stages/build-and-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,7 @@ parameters:
internalProjectName: null
publicProjectName: null

internalVersionsRepoRef: null
publicVersionsRepoRef: null
versionsRepoRef: ""

isInternalServicingValidation: false

Expand Down Expand Up @@ -51,6 +50,7 @@ stages:
condition: and(succeeded(), contains(variables['stages'], 'build'))
dependsOn: []
jobs:

- template: /eng/common/templates/jobs/test-images-linux-client.yml@self
parameters:
name: PreBuildValidation
Expand All @@ -69,12 +69,14 @@ stages:
echo "##vso[task.setvariable variable=osVersions]"
echo "##vso[task.setvariable variable=architecture]"
displayName: Initialize Test Variables

- template: /eng/common/templates/jobs/copy-base-images-staging.yml@self
parameters:
name: CopyBaseImages
pool: ${{ parameters.linuxAmd64Pool }}
additionalOptions: "--manifest '$(manifest)' $(imageBuilder.pathArgs) $(manifestVariables)"
customInitSteps: ${{ parameters.customCopyBaseImagesInitSteps }}

- template: /eng/common/templates/jobs/generate-matrix.yml@self
parameters:
matrixType: ${{ parameters.buildMatrixType }}
Expand All @@ -85,12 +87,10 @@ stages:
noCache: ${{ parameters.noCache }}
customInitSteps: ${{ parameters.customGenerateMatrixInitSteps }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}

- template: /eng/common/templates/jobs/build-images.yml@self
parameters:
name: Linux_amd64
Expand All @@ -99,12 +99,9 @@ stages:
dockerClientOS: linux
buildJobTimeout: ${{ parameters.linuxAmdBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
Expand All @@ -118,12 +115,9 @@ stages:
dockerClientOS: linux
buildJobTimeout: ${{ parameters.linuxArmBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
Expand All @@ -137,12 +131,9 @@ stages:
dockerClientOS: linux
buildJobTimeout: ${{ parameters.linuxArmBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
Expand All @@ -156,12 +147,9 @@ stages:
dockerClientOS: windows
buildJobTimeout: ${{ parameters.windowsAmdBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
Expand All @@ -175,12 +163,9 @@ stages:
dockerClientOS: windows
buildJobTimeout: ${{ parameters.windowsAmdBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
Expand All @@ -194,18 +179,14 @@ stages:
dockerClientOS: windows
buildJobTimeout: ${{ parameters.windowsAmdBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
publicProjectName: ${{ parameters.publicProjectName }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
- template: /eng/common/templates/jobs/build-images.yml@self
parameters:
Expand All @@ -215,12 +196,9 @@ stages:
dockerClientOS: windows
buildJobTimeout: ${{ parameters.windowsAmdBuildJobTimeout }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
isInternalServicingValidation: ${{ parameters.isInternalServicingValidation }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
customInitSteps: ${{ parameters.customBuildInitSteps }}
noCache: ${{ parameters.noCache }}
internalProjectName: ${{ parameters.internalProjectName }}
Expand All @@ -243,7 +221,7 @@ stages:
################################################################################
# Test Images
################################################################################
- ${{ if and(eq(variables['System.TeamProject'], parameters.internalProjectName), ne(variables['Build.Reason'], 'PullRequest'), eq(parameters.isInternalServicingValidation, 'false')) }}:
- ${{ if and(eq(variables['System.TeamProject'], parameters.internalProjectName), ne(variables['Build.Reason'], 'PullRequest')) }}:
- stage: Test
dependsOn: Post_Build
condition: "
Expand All @@ -270,11 +248,9 @@ stages:
customInitSteps: ${{ parameters.customGenerateMatrixInitSteps }}
sourceBuildPipelineRunId: ${{ parameters.sourceBuildPipelineRunId }}
commonInitStepsForMatrixAndBuild:
- template: /eng/common/templates/steps/common-init-for-matrix-and-build.yml@self
- template: /eng/common/templates/steps/init-matrix-build-publish.yml@self
parameters:
noCache: ${{ parameters.noCache }}
internalVersionsRepoRef: ${{ parameters.internalVersionsRepoRef }}
publicVersionsRepoRef: ${{ parameters.publicVersionsRepoRef }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
- template: /eng/common/templates/jobs/test-images-linux-client.yml@self
parameters:
name: Linux_amd64
Expand Down
7 changes: 5 additions & 2 deletions eng/common/templates/stages/dotnet/build-and-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,8 @@ parameters:
internalProjectName: null
publicProjectName: null

versionsRepoRef: null

stages:
- template: /eng/common/templates/stages/build-and-test.yml@self
parameters:
Expand All @@ -51,8 +53,9 @@ stages:
testMatrixType: ${{ parameters.testMatrixType }}
sourceBuildPipelineRunId: ${{ parameters.sourceBuildPipelineRunId }}

internalVersionsRepoRef: InternalVersionsRepo
publicVersionsRepoRef: PublicVersionsRepo
# Only clone versions repo if we need to reference it during the build in order to cache images.
${{ if eq(parameters.noCache, false) }}:
versionsRepoRef: ${{ parameters.versionsRepoRef }}

# Linux AMD64
linuxAmd64Pool:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@ parameters:
# Other common parameters
internalProjectName: null
publicProjectName: null
versionsRepoRef: null


stages:
Expand Down Expand Up @@ -61,6 +62,7 @@ stages:
# Other
internalProjectName: ${{ parameters.internalProjectName }}
publicProjectName: ${{ parameters.publicProjectName }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}

- template: /eng/common/templates/stages/dotnet/publish.yml@self
parameters:
Expand All @@ -70,3 +72,4 @@ stages:
internalProjectName: ${{ parameters.internalProjectName }}
publicProjectName: ${{ parameters.publicProjectName }}
sourceBuildPipelineRunId: ${{ parameters.sourceBuildPipelineRunId }}
versionsRepoRef: ${{ parameters.versionsRepoRef }}
Loading