fix(operator): Attempt to fix all the major issues present atm against the newest jenkins lts version (#784)

* fix(seed): fix #742, workaround #698
Original fix proposal: https://github.com/jenkinsci/kubernetes-operator/issues/742#issuecomment-1304398590

* fix(install-plugin.sh): fix #758, #739
* the fix was original attempted here:
  https://github.com/jenkinsci/kubernetes-operator/pull/764 but was not
  working correctly due to 2-3 additional changes which needed to be
  done
* removed the openshift check because the env is not mention anywhere
  and also the new jenkins-plugin-cli does not a specific command for
  openshift. Finally this does not make any sense in general, the only
  problem in ocp will be the user id that will be mapped to a random uid
  but that's another story. The command to install the plugins should
  remain the same across different k8s flavours.

* fix(doc/test): fix /usr/bin/tini in any doc and validation

* fix(jenkins): remove AdminWhitelistRule to avoid jvm stack trace, see: https://www.jenkins.io/doc/book/security/controller-isolation/jep-235/#api-compatibility

* fix(seed): fix seed img built on a previous jvm, fix #761

* fix(plugin): update the base plugin to work with the newest version of
jenkins:lts

* fix(run): fix #778

* fix(backup): add a trap to remove the tmp dir if the tar fail, also fix: #770

* test(chart): update chart values for testing, will revert before merge

* fix(configmap): leftover

* fix(tests): fix seed job test

* fix(e2e)

* fix(e2e): helm

* fix(operator): update the temporary img to reflect latests changes

* Fix Helm e2e tests

* add trap in case of unwanted exit and make shellcheck happy

* chore(plugin): update git ver to 5.0.0

* fix(backup): always force delete the backup directory

* chore(operator): update the temporary img to reflect latest changes

* chore(jenkins): upgrade jenkins latest lts
This commit is contained in:
Luigi Operoso
2023-01-12 17:29:30 +01:00
committed by GitHub
parent 6e03948b09
commit 60b8ee56de
26 changed files with 99 additions and 117 deletions
+2 -2
View File
@@ -14,7 +14,7 @@ import (
var (
errorNotFound = errors.New("404")
regex = regexp.MustCompile("(<application-desc main-class=\"hudson.remoting.jnlp.Main\"><argument>)(?P<secret>[a-z0-9]*)")
regex = regexp.MustCompile("(<application-desc><argument>)(?P<secret>[a-z0-9]*)")
)
// Jenkins defines Jenkins API.
@@ -159,7 +159,7 @@ func newClient(url, userName, passwordOrToken string) (Jenkins, error) {
httpClient := &http.Client{
Jar: jar,
Timeout: 10 * time.Second,
Timeout: 20 * time.Second,
}
if len(userName) > 0 && len(passwordOrToken) > 0 {
@@ -14,11 +14,10 @@ const (
basicSettingsGroovyScriptName = "1-basic-settings.groovy"
enableCSRFGroovyScriptName = "2-enable-csrf.groovy"
disableUsageStatsGroovyScriptName = "3-disable-usage-stats.groovy"
enableMasterAccessControlGroovyScriptName = "4-enable-master-access-control.groovy"
disableInsecureFeaturesGroovyScriptName = "5-disable-insecure-features.groovy"
configureKubernetesPluginGroovyScriptName = "6-configure-kubernetes-plugin.groovy"
configureViewsGroovyScriptName = "7-configure-views.groovy"
disableJobDslScriptApprovalGroovyScriptName = "8-disable-job-dsl-script-approval.groovy"
disableInsecureFeaturesGroovyScriptName = "4-disable-insecure-features.groovy"
configureKubernetesPluginGroovyScriptName = "5-configure-kubernetes-plugin.groovy"
configureViewsGroovyScriptName = "6-configure-views.groovy"
disableJobDslScriptApprovalGroovyScriptName = "7-disable-job-dsl-script-approval.groovy"
)
const basicSettingsFmt = `
@@ -63,18 +62,6 @@ if (jenkins.isUsageStatisticsCollected()) {
}
`
const enableMasterAccessControl = `
import jenkins.security.s2m.AdminWhitelistRule
import jenkins.model.Jenkins
// see https://wiki.jenkins-ci.org/display/JENKINS/Slave+To+Master+Access+Control
def jenkins = Jenkins.instance
jenkins.getInjector()
.getInstance(AdminWhitelistRule.class)
.setMasterKillSwitch(false) // for real though, false equals enabled..........
jenkins.save()
`
const disableInsecureFeatures = `
import jenkins.*
import jenkins.model.*
@@ -197,11 +184,10 @@ func NewBaseConfigurationConfigMap(meta metav1.ObjectMeta, jenkins *v1alpha2.Jen
suffix = prefix
}
groovyScriptsMap := map[string]string{
basicSettingsGroovyScriptName: fmt.Sprintf(basicSettingsFmt, constants.DefaultAmountOfExecutors),
enableCSRFGroovyScriptName: enableCSRF,
disableUsageStatsGroovyScriptName: disableUsageStats,
enableMasterAccessControlGroovyScriptName: enableMasterAccessControl,
disableInsecureFeaturesGroovyScriptName: disableInsecureFeatures,
basicSettingsGroovyScriptName: fmt.Sprintf(basicSettingsFmt, constants.DefaultAmountOfExecutors),
enableCSRFGroovyScriptName: enableCSRF,
disableUsageStatsGroovyScriptName: disableUsageStats,
disableInsecureFeaturesGroovyScriptName: disableInsecureFeatures,
configureKubernetesPluginGroovyScriptName: fmt.Sprintf(configureKubernetesPluginFmt,
clusterDomain,
jenkins.ObjectMeta.Namespace,
+1 -1
View File
@@ -53,7 +53,7 @@ func GetJenkinsMasterContainerBaseCommand() []string {
return []string{
"bash",
"-c",
fmt.Sprintf("%s/%s && exec /sbin/tini -s -- /usr/local/bin/jenkins.sh",
fmt.Sprintf("%s/%s && exec /usr/bin/tini -s -- /usr/local/bin/jenkins.sh",
JenkinsScriptsVolumePath, InitScriptName),
}
}
@@ -12,7 +12,7 @@ import (
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
)
const installPluginsCommand = "install-plugins.sh"
const installPluginsCommand = "jenkins-plugin-cli"
// bash scripts installs single jenkins plugin with specific version
const installPluginsBashScript = `#!/bin/bash -eu
@@ -341,30 +341,23 @@ chmod +x {{ .JenkinsHomePath }}/scripts/*.sh
{{- $installPluginsCommand := .InstallPluginsCommand }}
echo "Installing plugins required by Operator - begin"
cat > {{ .JenkinsHomePath }}/base-plugins << EOF
cat > {{ .JenkinsHomePath }}/base-plugins.txt << EOF
{{ range $index, $plugin := .BasePlugins }}
{{ $plugin.Name }}:{{ $plugin.Version }}{{if $plugin.DownloadURL}}:{{ $plugin.DownloadURL }}{{end}}
{{ end }}
EOF
if [[ -z "${OPENSHIFT_JENKINS_IMAGE_VERSION}" ]]; then
{{ $installPluginsCommand }} < {{ .JenkinsHomePath }}/base-plugins
else
{{ $installPluginsCommand }} {{ .JenkinsHomePath }}/base-plugins
fi
{{ $installPluginsCommand }} --verbose -f {{ .JenkinsHomePath }}/base-plugins.txt
echo "Installing plugins required by Operator - end"
echo "Installing plugins required by user - begin"
cat > {{ .JenkinsHomePath }}/user-plugins << EOF
cat > {{ .JenkinsHomePath }}/user-plugins.txt << EOF
{{ range $index, $plugin := .UserPlugins }}
{{ $plugin.Name }}:{{ $plugin.Version }}{{if $plugin.DownloadURL}}:{{ $plugin.DownloadURL }}{{end}}
{{ end }}
EOF
if [[ -z "${OPENSHIFT_JENKINS_IMAGE_VERSION}" ]]; then
{{ $installPluginsCommand }} < {{ .JenkinsHomePath }}/user-plugins
else
{{ $installPluginsCommand }} {{ .JenkinsHomePath }}/user-plugins
fi
{{ $installPluginsCommand }} --verbose -f {{ .JenkinsHomePath }}/user-plugins.txt
echo "Installing plugins required by user - end"
`))
@@ -388,7 +381,7 @@ func buildInitBashScript(jenkins *v1alpha2.Jenkins) (*string, error) {
InitConfigurationPath: jenkinsInitConfigurationVolumePath,
BasePlugins: jenkins.Spec.Master.BasePlugins,
UserPlugins: jenkins.Spec.Master.Plugins,
InstallPluginsCommand: JenkinsScriptsVolumePath + "/" + installPluginsCommand,
InstallPluginsCommand: installPluginsCommand,
JenkinsScriptsVolumePath: JenkinsScriptsVolumePath,
}
+2 -2
View File
@@ -905,7 +905,7 @@ func TestValidateJenkinsMasterContainerCommand(t *testing.T) {
Command: []string{
"bash",
"-c",
fmt.Sprintf("%s/%s && my-extra-command.sh && exec /sbin/tini -s -- /usr/local/bin/jenkins.sh",
fmt.Sprintf("%s/%s && my-extra-command.sh && exec /usr/bin/tini -s -- /usr/local/bin/jenkins.sh",
resources.JenkinsScriptsVolumePath, resources.InitScriptName),
},
},
@@ -929,7 +929,7 @@ func TestValidateJenkinsMasterContainerCommand(t *testing.T) {
Command: []string{
"bash",
"-c",
fmt.Sprintf("%s/%s && my-extra-command.sh && /sbin/tini -s -- /usr/local/bin/jenkins.sh",
fmt.Sprintf("%s/%s && my-extra-command.sh && /usr/bin/tini -s -- /usr/local/bin/jenkins.sh",
resources.JenkinsScriptsVolumePath, resources.InitScriptName),
},
},
+1 -1
View File
@@ -46,7 +46,7 @@ const (
AgentName = "seed-job-agent"
// DefaultAgentImage is the default image used for the seed-job agent
defaultAgentImage = "jenkins/inbound-agent:4.9-1"
defaultAgentImage = "jenkins/inbound-agent:4.10-3"
creatingGroovyScriptName = "seed-job-groovy-script.groovy"
@@ -113,7 +113,7 @@ func TestEnsureSeedJobs(t *testing.T) {
var agentDeployment appsv1.Deployment
err = fakeClient.Get(ctx, types.NamespacedName{Namespace: jenkins.Namespace, Name: agentDeploymentName(*jenkins, AgentName)}, &agentDeployment)
assert.NoError(t, err)
assert.Equal(t, "jenkins/inbound-agent:4.9-1", agentDeployment.Spec.Template.Spec.Containers[0].Image)
assert.Equal(t, "jenkins/inbound-agent:4.10-3", agentDeployment.Spec.Template.Spec.Containers[0].Image)
})
t.Run("delete agent deployment when no seed jobs", func(t *testing.T) {
+7 -7
View File
@@ -1,13 +1,13 @@
package plugins
const (
configurationAsCodePlugin = "configuration-as-code:1346.ve8cfa_3473c94"
gitPlugin = "git:4.11.3"
jobDslPlugin = "job-dsl:1.78.1"
kubernetesPlugin = "kubernetes:1.31.3"
kubernetesCredentialsProviderPlugin = "kubernetes-credentials-provider:0.20"
workflowAggregatorPlugin = "workflow-aggregator:2.6"
workflowJobPlugin = "workflow-job:1145.v7f2433caa07f"
configurationAsCodePlugin = "configuration-as-code:1569.vb_72405b_80249"
gitPlugin = "git:5.0.0"
jobDslPlugin = "job-dsl:1.81"
kubernetesPlugin = "kubernetes:3802.vb_b_600831fcb_3"
kubernetesCredentialsProviderPlugin = "kubernetes-credentials-provider:1.208.v128ee9800c04"
workflowAggregatorPlugin = "workflow-aggregator:590.v6a_d052e5a_a_b_5"
workflowJobPlugin = "workflow-job:1254.v3f64639b_11dd"
)
// basePluginsList contains plugins to install by operator.