diff --git a/.github/ISSUE_TEMPLATE/documentation.md b/.github/ISSUE_TEMPLATE/documentation.md
index a0ed0b42..9e5505f3 100644
--- a/.github/ISSUE_TEMPLATE/documentation.md
+++ b/.github/ISSUE_TEMPLATE/documentation.md
@@ -7,7 +7,7 @@ projects: ''
assignees: ''
---
-**Relevant links*
+**Relevant links**
Link(s) to the section(s) of documentation that are outdated or otherwise wrong
**Description**
diff --git a/.github/stale.yml b/.github/stale.yml
index ea6a07f2..30867b8b 100644
--- a/.github/stale.yml
+++ b/.github/stale.yml
@@ -5,7 +5,7 @@ daysUntilStale: 30
# Number of days of inactivity before a stale Issue or Pull Request is closed.
# Set to false to disable. If disabled, issues still need to be closed manually, but will remain marked as stale.
-daysUntilClose: 60
+daysUntilClose: 30
# Issues with these labels will never be considered stale
exemptLabels:
diff --git a/.github/workflows/auto-gen-docs.yaml b/.github/workflows/auto-gen-docs.yaml
index 5d7462d8..e56ec635 100644
--- a/.github/workflows/auto-gen-docs.yaml
+++ b/.github/workflows/auto-gen-docs.yaml
@@ -55,6 +55,12 @@ jobs:
sudo npm install -D --save postcss-cli
cd ../
+ - name: Update last modified date in modified docs
+ if: env.IS_CHANGED == 'true'
+ run: |
+ git diff --name-only --diff-filter=d ${{ github.event.before }} ${{ github.sha }} | grep -E "^website*" \
+ | sed -e 's/\(.*\)/"\1"/' | xargs sed -i "/date:/c\date: $(date +'%Y-%m-%d')"
+
# Runs makefile goal - checks changes to /website folder and generates docs
- name: Run Makefile goal
if: env.IS_CHANGED == 'true'
diff --git a/.github/workflows/release-helm-chart.yaml b/.github/workflows/release-helm-chart.yaml
new file mode 100644
index 00000000..ece667f0
--- /dev/null
+++ b/.github/workflows/release-helm-chart.yaml
@@ -0,0 +1,40 @@
+name: Release Helm chart
+
+# Run this workflow manually
+on:
+ workflow_dispatch:
+ inputs:
+ chartVersion:
+ description: "Helm chart version to release. eg. 0.4.1"
+ required: true
+ appVersion:
+ description: "Operator app version without quotes, eg. 0.5.1 . If not provided, the one in Chart.yaml won't be overwritten."
+ required: false
+
+jobs:
+ release-helm-chart:
+ runs-on: ubuntu-latest
+
+ steps:
+ - name: Checkout code
+ uses: actions/checkout@v2
+
+ - name: Deploy Helm chart
+ run: |
+ sed -i "/version:/c\version: ${{ github.event.inputs.chartVersion }}" chart/jenkins-operator/Chart.yaml
+
+ if [ ${{ github.event.inputs.appVersion }} ] ; then
+ sed -i "/appVersion:/c\appVersion: \"${{ github.event.inputs.appVersion }}\"" chart/jenkins-operator/Chart.yaml
+ fi
+
+ make helm-release-latest
+
+ # Creates pull request with new chart version
+ - name: Create Pull Request
+ uses: peter-evans/create-pull-request@v3
+ with:
+ commit-message: Release Helm chart ${{ github.event.inputs.chartVersion }}
+ branch: helm-chart-release-${{ github.event.inputs.chartVersion }}
+ title: Release ${{ github.event.inputs.chartVersion }} Helm Chart
+ body: |
+ Release ${{ github.event.inputs.chartVersion }} Helm Chart
\ No newline at end of file
diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md
index d23cf3a6..ce608511 100644
--- a/CODE_OF_CONDUCT.md
+++ b/CODE_OF_CONDUCT.md
@@ -2,5 +2,4 @@
You can find the Jenkins Code of Conduct [on jenkins.io](https://jenkins.io/project/conduct/).
-It applies to the entire `jenkinsci` GitHub organization, among other community spaces.
-[version]: http://contributor-covenant.org/version/1/4/
\ No newline at end of file
+It applies to the entire `jenkinsci` GitHub organization, among other community spaces.
\ No newline at end of file
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 267761f1..5979cb3e 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -4,7 +4,7 @@ Thanks for taking the time to contribute!
## Code of Conduct
-This project and everyone participating in it is governed by the [Atom Code of Conduct](CODE_OF_CONDUCT.md). By participating, you are expected to uphold this code.
+This project and everyone participating in it is governed by the [Jenkins Code of Conduct](CODE_OF_CONDUCT.md). By participating, you are expected to uphold this code.
## We Develop with GitHub
We use GitHub to host code, to track issues and feature requests, as well as accept pull requests.
@@ -41,3 +41,10 @@ Design proposal is simply a document that states what you propose to do includin
- Breaking changes
Keep in mind that a proposal is not a pitch, it needs to be technical.
+
+### Proposing changes to Helm Chart
+When issuing a PR that modifies the project's Helm Chart, please do not include in your PR changes that would release a new package version when merged.
+
+Specifically, please do not update `chart/index.yaml` and `chart/jenkins-operator/Chart.yaml` files and do not build chart archive package.
+
+For the sake of PR's brevity and security, Project's maintainers will issue a separate PR that releases new version of the Chart after your PR has been merged.
\ No newline at end of file
diff --git a/Makefile b/Makefile
index 658928eb..201d3679 100644
--- a/Makefile
+++ b/Makefile
@@ -408,21 +408,15 @@ helm-lint: helm
@echo "+ $@"
bin/helm lint chart/jenkins-operator
-.PHONY: helm-package
-helm-package: helm
+.PHONY: helm-release-latest
+helm-release-latest: helm
@echo "+ $@"
mkdir -p /tmp/jenkins-operator-charts
mv chart/jenkins-operator/*.tgz /tmp/jenkins-operator-charts
cd chart && ../bin/helm package jenkins-operator
+ mv chart/jenkins-operator-*.tgz chart/jenkins-operator/
+ bin/helm repo index chart/ --url https://raw.githubusercontent.com/jenkinsci/kubernetes-operator/master/chart/ --merge chart/index.yaml
mv /tmp/jenkins-operator-charts/*.tgz chart/jenkins-operator/
- rm -rf /tmp/jenkins-operator-charts/
- git add chart/jenkins-operator-*.tgz
-
-.PHONY: helm-deploy
-helm-deploy: helm-package
- @echo "+ $@"
- bin/helm repo index chart/ --url https://raw.githubusercontent.com/jenkinsci/kubernetes-operator/master/chart/jenkins-operator/
- cd chart/ && mv jenkins-operator-*.tgz jenkins-operator
# Download and build hugo extended locally if necessary
HUGO_PATH = $(shell pwd)/bin/hugo
diff --git a/README.md b/README.md
index 45d5b74f..23c457da 100644
--- a/README.md
+++ b/README.md
@@ -28,7 +28,7 @@ Jenkins uses [plugins](https://plugins.jenkins.io/) like CasC to extend it's sol
- Integration with Kubernetes ([Jenkins kubernetes-plugin](https://github.com/jenkinsci/kubernetes-plugin))
- Pipelines as Code ([Jenkins pipelines](https://jenkins.io/doc/book/pipeline/))
- Extensibility via Groovy Scripts (similar to [Jenkins script console](https://wiki.jenkins.io/display/JENKINS/Jenkins+Script+Console)) or ([configuration as code plugin](https://github.com/jenkinsci/configuration-as-code-plugin))
-- Secure Defaults and Hardening (see [the security section](https://jenkinsci.github.io/kubernetes-operator/docs/security/) of the documentation)
+- Secure Defaults and Hardening (see [the security section](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/security/) of the documentation)
## Problem statement and goals
@@ -36,11 +36,10 @@ The main reason why we decided to implement the **Jenkins Operator** is the fact
We want to make Jenkins more robust, suitable for dynamic and multi-tenant environments.
Some of the problems we want to solve:
-- [installing plugins with incompatible versions or security vulnerabilities](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/customization/#install-plugins)
-- [better configuration as code](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/customization/)
-- [security and hardening out of the box](https://jenkinsci.github.io/kubernetes-operator/docs/security/)
-- [make errors more visible for end users](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/diagnostics/)
-- [backup and restore for jobs history](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/configure-backup-and-restore/)
+- [installing plugins with incompatible versions or security vulnerabilities](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/customizing-jenkins/#install-plugins/)
+- [better configuration as code](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/customizing-jenkins/)
+- [security and hardening out of the box](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/security/)
+- [make errors more visible for end users](https://jenkinsci.github.io/kubernetes-operator/docs/troubleshooting/)
- orphaned jobs with no JNLP connection
- handle graceful shutdown properly
- proper end to end tests for Jenkins lifecycle
@@ -50,26 +49,30 @@ Some of the problems we want to solve:
Go to [**our documentation website**](https://jenkinsci.github.io/kubernetes-operator/) for more information.
Selected content:
-1. [Installation](https://jenkinsci.github.io/kubernetes-operator/docs/installation/)
+1. [How it works](https://jenkinsci.github.io/kubernetes-operator/docs/how-it-works/)
2. [Getting Started](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/)
-3. [How it works](https://jenkinsci.github.io/kubernetes-operator/docs/how-it-works/)
-4. [Security](https://jenkinsci.github.io/kubernetes-operator/docs/security/)
+3. [Security](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/security/)
+4. [Troubleshooting](https://jenkinsci.github.io/kubernetes-operator/docs/troubleshooting/)
5. [Developer Guide](https://jenkinsci.github.io/kubernetes-operator/docs/developer-guide/)
-5. [Jenkins Custom Resource Definition Schema](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/schema/)
+6. [FAQ](https://jenkinsci.github.io/kubernetes-operator/docs/faq/)
+7. [Jenkins Custom Resource Definition Schema](https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/schema/)
## Common Issues and Workarounds
- Multibranch Pipelines and Backup Issues: https://github.com/jenkinsci/kubernetes-operator/issues/104#issuecomment-554289768
## Community
+Main channel of communication on topics related to Jenkins Operator is [Jenkins Operator Category](https://community.jenkins.io/c/contributing/jenkins-operator/20) on [Jenkins Community Discourse](https://community.jenkins.io/).
-We have a dedicated channel called `#jenkins-operator` on [virtuslab-oss.slack.com](https://virtuslab-oss.slack.com)
+Here you can ask questions about the project, discuss best practices on using it, and talk to other users of the Operator, contributors and project's maintainers.
+
+We also have a dedicated channel called `#jenkins-operator` on [virtuslab-oss.slack.com](https://virtuslab-oss.slack.com).
Fill out ([Invite form](https://forms.gle/X3X8qA1XMirdBuEH7)) and come say hi!
## Snapshots between releases
-We are trying our best to resolve issues quickly, but they have to wait to be released. If you can't wait for an official
-docker image release and acknowledge the risk, you can use our unofficial images, which are built nightly.
+We are trying our best to resolve issues quickly, but they have to wait to be released. If you can't wait for an official
+docker image release and acknowledge the risk, you can use our unofficial images, which are built nightly.
You can find the project's Docker Hub repository [here](https://hub.docker.com/r/virtuslab/jenkins-operator).
@@ -77,7 +80,8 @@ Look for the images with tag "{git-hash}", where {git-hash} is the hash of the m
## Contribution
-Feel free to file [issues](https://github.com/jenkinsci/kubernetes-operator/issues) or [pull requests](https://github.com/jenkinsci/kubernetes-operator/pulls).
+Feel free to file [issues](https://github.com/jenkinsci/kubernetes-operator/issues) or [pull requests](https://github.com/jenkinsci/kubernetes-operator/pulls),
+but please consult [CONTRIBUTING](https://github.com/jenkinsci/kubernetes-operator/blob/master/CONTRIBUTING.md) document beforehand.
Before any big pull request please consult the maintainers to ensure a common direction.
@@ -85,6 +89,7 @@ Before any big pull request please consult the maintainers to ensure a common di
- [Jenkins World 2019 Lisbon](assets/Jenkins_World_Lisbon_2019%20-Jenkins_Kubernetes_Operator.pdf)
- [Jenkins Online Meetup 2020](assets/Jenkins_Online_Meetup-Jenkins_Kubernetes_Operator.pdf)
+- [Jenkins Online Meetup 2021](https://www.youtube.com/watch?v=BsYYVkophsk)
## About the authors
diff --git a/ROADMAP.md b/ROADMAP.md
index 4fea3c4d..fc9d66d1 100644
--- a/ROADMAP.md
+++ b/ROADMAP.md
@@ -4,37 +4,28 @@ This document outlines the vision and technical roadmap for [jenkinsci/kubernete
## Project Vision
-With Jenkins Operator project we want to enable our community to run Jenkins in cloud-native environments like Kubernetes, OpenShift and others. Also, support most of the public cloud providers (AWS, Azure, GCP) in terms of additional capabilities like backups, observability and cloud security.
-
+With Jenkins Operator project we want to enable our community to run Jenkins in cloud-native environments. Also, support most of the public cloud providers (AWS, Azure, GCP) in terms of additional capabilities like backups, observability and cloud security.
With declarative configuration and full lifecycle management based on [Operator Framework](https://operatorframework.io/) this can become the de facto standard for running Jenkins on top of Kubernetes.
-
-Now, we have a dedicated team which can bring more engineering effort to the project.
-
## Technical Roadmap
-
-- Upgrade Operator SDK [#494](https://github.com/jenkinsci/kubernetes-operator/issues/494)
- - https://github.com/operator-framework/operator-sdk/releases/tag/v1.3.0
-- Modularise codebase and define areas of responsibility (AWS, Azure, OpenShift)
- Break down Jenkins Custom Resource into smaller parts, support multiple Custom Resource Definitions [#495](https://github.com/jenkinsci/kubernetes-operator/issues/495)
- Introduce more granular schema for configuring Jenkins
- Introduce independent reconciliation controllers
- - Refactor e2e tests to support testing individual reconciliation controller
+ - Refactor e2e tests to support testing individual reconciliation controllers
+- Migrate Jenkins instance from Pod to Deployment [#497](https://github.com/jenkinsci/kubernetes-operator/issues/497)
+ - Unblock easier integration with 3rd party systems e.g. sidecars injection
- Improve contribution process and establish governance model [#496](https://github.com/jenkinsci/kubernetes-operator/issues/496)
- Improve CONTRIBUTING.md
- Introduce architecture decision proposals process
- Introduce governance model
-- Migrate Jenkins instance from Pod to Deployment [#497](https://github.com/jenkinsci/kubernetes-operator/issues/497)
- - Unblock easier integration with 3rd party systems e.g. sidecars injection
+- Engage with community more
+ - After releasing Operator version with new API, gather feedback from users on where the Operator should go next
- Reference Architecture - Jenkins on Kubernetes
- Bridge the gap between Jenkins and Kubernetes
- https://www.jenkins.io/blog/2020/12/04/gsod-project-report/
-- Pay technical debt
- - Review existing issues on GitHub and prioritise them
- - Introduce project board to track milestones
- - Fix existing bugs
+
## Have a Question?
-In case of further question feel free to create an issue or contact us directly.
+In case of questions, feel free to create a thread on [Jenkins Operator Category](https://community.jenkins.io/c/contributing/jenkins-operator/20) of Jenkins Community Discourse or contact us directly.
diff --git a/chart/index.yaml b/chart/index.yaml
index aa42e82d..f8bad344 100644
--- a/chart/index.yaml
+++ b/chart/index.yaml
@@ -1,7 +1,17 @@
apiVersion: v1
entries:
jenkins-operator:
- - apiVersion: v2
+ - apiVersion: v2
+ appVersion: 0.6.0
+ created: "2021-08-11T15:40:10.659538+02:00"
+ description: Kubernetes native operator which fully manages Jenkins on Kubernetes
+ digest: e79615d988cc0c0bb64996394268ff87d232797b72ab9ad9a7891e9999daee9f
+ icon: https://raw.githubusercontent.com/jenkinsci/kubernetes-operator/master/assets/jenkins-operator-icon.png
+ name: jenkins-operator
+ urls:
+ - https://raw.githubusercontent.com/jenkinsci/kubernetes-operator/master/chart/jenkins-operator/jenkins-operator-0.5.3.tgz
+ version: 0.5.3
+ - apiVersion: v2
appVersion: 0.6.0
created: "2021-06-11T13:50:32.677639006+02:00"
description: Kubernetes native operator which fully manages Jenkins on Kubernetes
@@ -288,4 +298,4 @@ entries:
urls:
- https://raw.githubusercontent.com/jenkinsci/kubernetes-operator/master/chart/jenkins-operator/jenkins-operator-0.0.1.tgz
version: 0.0.1
-generated: "2021-06-11T13:50:32.675502593+02:00"
+generated: "2021-08-11T15:40:10.654972+02:00"
diff --git a/chart/jenkins-operator/Chart.yaml b/chart/jenkins-operator/Chart.yaml
index fc8858bd..c894472f 100644
--- a/chart/jenkins-operator/Chart.yaml
+++ b/chart/jenkins-operator/Chart.yaml
@@ -2,7 +2,7 @@ apiVersion: v2
appVersion: "0.6.0"
description: Kubernetes native operator which fully manages Jenkins on Kubernetes
name: jenkins-operator
-version: 0.5.2
+version: 0.5.3
icon: https://raw.githubusercontent.com/jenkinsci/kubernetes-operator/master/assets/jenkins-operator-icon.png
dependencies:
- name: cert-manager
diff --git a/chart/jenkins-operator/jenkins-operator-0.5.3.tgz b/chart/jenkins-operator/jenkins-operator-0.5.3.tgz
new file mode 100644
index 00000000..1772d8f3
Binary files /dev/null and b/chart/jenkins-operator/jenkins-operator-0.5.3.tgz differ
diff --git a/chart/jenkins-operator/templates/_role.yaml b/chart/jenkins-operator/templates/_role.yaml
index 9ff46064..4da31d4e 100644
--- a/chart/jenkins-operator/templates/_role.yaml
+++ b/chart/jenkins-operator/templates/_role.yaml
@@ -1,11 +1,13 @@
{{ define "jenkins-operator.role" }}
{{ $namespace := . }}
---
-kind: Role
+kind: {{ if eq $namespace "" }}ClusterRole{{ else }}Role{{ end }}
apiVersion: rbac.authorization.k8s.io/v1
metadata:
name: jenkins-operator
+{{- if ne $namespace "" }}
namespace: {{ $namespace }}
+{{- end }}
rules:
- apiGroups:
- apps
@@ -171,4 +173,4 @@ rules:
- get
- list
- watch
-{{ end }}
\ No newline at end of file
+{{ end }}
diff --git a/chart/jenkins-operator/templates/role.yaml b/chart/jenkins-operator/templates/role.yaml
index f3c31553..07bdec63 100644
--- a/chart/jenkins-operator/templates/role.yaml
+++ b/chart/jenkins-operator/templates/role.yaml
@@ -1,4 +1,15 @@
-{{ template "jenkins-operator.role" .Release.Namespace }}
-{{ if ne .Release.Namespace .Values.jenkins.namespace }}
-{{ template "jenkins-operator.role" .Values.jenkins.namespace }}
+{{ if eq .Values.jenkins.namespace "" }}
+{{- /*
+# This is a special case when .Values.jenkins.namespace is equal to empty
+# string which leads to WATCH_NAMESPACE env of jenkins-operator to be set to
+# empty string and leads to operator actually watching all namespaces. In this
+# case we need to create clusterrole and clusterrolebinding instead of role and
+# rolebinding
+*/ -}}
+ {{- template "jenkins-operator.role" .Values.jenkins.namespace }}
+{{ else }}
+ {{- template "jenkins-operator.role" .Release.Namespace }}
+ {{- if ne .Release.Namespace .Values.jenkins.namespace -}}
+ {{- template "jenkins-operator.role" .Values.jenkins.namespace }}
+ {{- end }}
{{ end }}
\ No newline at end of file
diff --git a/chart/jenkins-operator/templates/role_binding.yaml b/chart/jenkins-operator/templates/role_binding.yaml
index 23817139..c36b6a2a 100644
--- a/chart/jenkins-operator/templates/role_binding.yaml
+++ b/chart/jenkins-operator/templates/role_binding.yaml
@@ -1,3 +1,25 @@
+{{ if eq .Values.jenkins.namespace "" }}
+{{- /*
+# This is a special case when .Values.jenkins.namespace is equal to empty
+# string which leads to WATCH_NAMESPACE env of jenkins-operator to be set to
+# empty string and leads to operator actually watching all namespaces. In this
+# case we need to create clusterrole and clusterrolebinding instead of role and
+# rolebinding
+*/ -}}
+---
+kind: ClusterRoleBinding
+apiVersion: rbac.authorization.k8s.io/v1
+metadata:
+ name: jenkins-operator
+subjects:
+ - kind: ServiceAccount
+ name: jenkins-operator
+ namespace: {{ .Release.Namespace }}
+roleRef:
+ kind: ClusterRole
+ name: jenkins-operator
+ apiGroup: rbac.authorization.k8s.io
+{{ else }}
---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
@@ -27,4 +49,5 @@ roleRef:
kind: Role
name: jenkins-operator
apiGroup: rbac.authorization.k8s.io
-{{ end }}
\ No newline at end of file
+{{ end }}
+{{ end }}
diff --git a/chart/jenkins-operator/values.yaml b/chart/jenkins-operator/values.yaml
index ce3fb1c8..29a6e7a1 100644
--- a/chart/jenkins-operator/values.yaml
+++ b/chart/jenkins-operator/values.yaml
@@ -18,6 +18,7 @@ jenkins:
# namespace is the namespace where the resources will be deployed
# It's not recommended to use default namespace
# Create new namespace for jenkins (called e.g. jenkins)
+ # Note: this affects roles and rolebindings for jenkins operator itself
namespace: default
# labels are injected into metadata labels field
@@ -143,7 +144,7 @@ jenkins:
# slave Jenkins service
# See https://jenkinsci.github.io/kubernetes-operator/docs/getting-started/latest/schema/#github.com/jenkinsci/kubernetes-operator/pkg/apis/jenkins/v1alpha2.Service for details
#slaveService:
-
+
# LivenessProbe for Jenkins Master pod
livenessProbe:
failureThreshold: 12
diff --git a/docs/about/index.html b/docs/about/index.html
index fc843de8..8a4e1d47 100644
--- a/docs/about/index.html
+++ b/docs/about/index.html
@@ -104,20 +104,18 @@ Jenkins Operator is a Kubernetes native operator which fully manages Jenkins on
Some of the problems we want to solve: