mirror of
https://github.com/jenkinsci/kubernetes-operator.git
synced 2026-09-29 20:51:10 +02:00
fix(operator): Attempt to fix all the major issues present atm against the newest jenkins lts version (#784)
* fix(seed): fix #742, workaround #698 Original fix proposal: https://github.com/jenkinsci/kubernetes-operator/issues/742#issuecomment-1304398590 * fix(install-plugin.sh): fix #758, #739 * the fix was original attempted here: https://github.com/jenkinsci/kubernetes-operator/pull/764 but was not working correctly due to 2-3 additional changes which needed to be done * removed the openshift check because the env is not mention anywhere and also the new jenkins-plugin-cli does not a specific command for openshift. Finally this does not make any sense in general, the only problem in ocp will be the user id that will be mapped to a random uid but that's another story. The command to install the plugins should remain the same across different k8s flavours. * fix(doc/test): fix /usr/bin/tini in any doc and validation * fix(jenkins): remove AdminWhitelistRule to avoid jvm stack trace, see: https://www.jenkins.io/doc/book/security/controller-isolation/jep-235/#api-compatibility * fix(seed): fix seed img built on a previous jvm, fix #761 * fix(plugin): update the base plugin to work with the newest version of jenkins:lts * fix(run): fix #778 * fix(backup): add a trap to remove the tmp dir if the tar fail, also fix: #770 * test(chart): update chart values for testing, will revert before merge * fix(configmap): leftover * fix(tests): fix seed job test * fix(e2e) * fix(e2e): helm * fix(operator): update the temporary img to reflect latests changes * Fix Helm e2e tests * add trap in case of unwanted exit and make shellcheck happy * chore(plugin): update git ver to 5.0.0 * fix(backup): always force delete the backup directory * chore(operator): update the temporary img to reflect latest changes * chore(jenkins): upgrade jenkins latest lts
This commit is contained in:
@@ -14,7 +14,7 @@ import (
|
||||
|
||||
var (
|
||||
errorNotFound = errors.New("404")
|
||||
regex = regexp.MustCompile("(<application-desc main-class=\"hudson.remoting.jnlp.Main\"><argument>)(?P<secret>[a-z0-9]*)")
|
||||
regex = regexp.MustCompile("(<application-desc><argument>)(?P<secret>[a-z0-9]*)")
|
||||
)
|
||||
|
||||
// Jenkins defines Jenkins API.
|
||||
@@ -159,7 +159,7 @@ func newClient(url, userName, passwordOrToken string) (Jenkins, error) {
|
||||
|
||||
httpClient := &http.Client{
|
||||
Jar: jar,
|
||||
Timeout: 10 * time.Second,
|
||||
Timeout: 20 * time.Second,
|
||||
}
|
||||
|
||||
if len(userName) > 0 && len(passwordOrToken) > 0 {
|
||||
|
||||
@@ -14,11 +14,10 @@ const (
|
||||
basicSettingsGroovyScriptName = "1-basic-settings.groovy"
|
||||
enableCSRFGroovyScriptName = "2-enable-csrf.groovy"
|
||||
disableUsageStatsGroovyScriptName = "3-disable-usage-stats.groovy"
|
||||
enableMasterAccessControlGroovyScriptName = "4-enable-master-access-control.groovy"
|
||||
disableInsecureFeaturesGroovyScriptName = "5-disable-insecure-features.groovy"
|
||||
configureKubernetesPluginGroovyScriptName = "6-configure-kubernetes-plugin.groovy"
|
||||
configureViewsGroovyScriptName = "7-configure-views.groovy"
|
||||
disableJobDslScriptApprovalGroovyScriptName = "8-disable-job-dsl-script-approval.groovy"
|
||||
disableInsecureFeaturesGroovyScriptName = "4-disable-insecure-features.groovy"
|
||||
configureKubernetesPluginGroovyScriptName = "5-configure-kubernetes-plugin.groovy"
|
||||
configureViewsGroovyScriptName = "6-configure-views.groovy"
|
||||
disableJobDslScriptApprovalGroovyScriptName = "7-disable-job-dsl-script-approval.groovy"
|
||||
)
|
||||
|
||||
const basicSettingsFmt = `
|
||||
@@ -63,18 +62,6 @@ if (jenkins.isUsageStatisticsCollected()) {
|
||||
}
|
||||
`
|
||||
|
||||
const enableMasterAccessControl = `
|
||||
import jenkins.security.s2m.AdminWhitelistRule
|
||||
import jenkins.model.Jenkins
|
||||
|
||||
// see https://wiki.jenkins-ci.org/display/JENKINS/Slave+To+Master+Access+Control
|
||||
def jenkins = Jenkins.instance
|
||||
jenkins.getInjector()
|
||||
.getInstance(AdminWhitelistRule.class)
|
||||
.setMasterKillSwitch(false) // for real though, false equals enabled..........
|
||||
jenkins.save()
|
||||
`
|
||||
|
||||
const disableInsecureFeatures = `
|
||||
import jenkins.*
|
||||
import jenkins.model.*
|
||||
@@ -197,11 +184,10 @@ func NewBaseConfigurationConfigMap(meta metav1.ObjectMeta, jenkins *v1alpha2.Jen
|
||||
suffix = prefix
|
||||
}
|
||||
groovyScriptsMap := map[string]string{
|
||||
basicSettingsGroovyScriptName: fmt.Sprintf(basicSettingsFmt, constants.DefaultAmountOfExecutors),
|
||||
enableCSRFGroovyScriptName: enableCSRF,
|
||||
disableUsageStatsGroovyScriptName: disableUsageStats,
|
||||
enableMasterAccessControlGroovyScriptName: enableMasterAccessControl,
|
||||
disableInsecureFeaturesGroovyScriptName: disableInsecureFeatures,
|
||||
basicSettingsGroovyScriptName: fmt.Sprintf(basicSettingsFmt, constants.DefaultAmountOfExecutors),
|
||||
enableCSRFGroovyScriptName: enableCSRF,
|
||||
disableUsageStatsGroovyScriptName: disableUsageStats,
|
||||
disableInsecureFeaturesGroovyScriptName: disableInsecureFeatures,
|
||||
configureKubernetesPluginGroovyScriptName: fmt.Sprintf(configureKubernetesPluginFmt,
|
||||
clusterDomain,
|
||||
jenkins.ObjectMeta.Namespace,
|
||||
|
||||
@@ -53,7 +53,7 @@ func GetJenkinsMasterContainerBaseCommand() []string {
|
||||
return []string{
|
||||
"bash",
|
||||
"-c",
|
||||
fmt.Sprintf("%s/%s && exec /sbin/tini -s -- /usr/local/bin/jenkins.sh",
|
||||
fmt.Sprintf("%s/%s && exec /usr/bin/tini -s -- /usr/local/bin/jenkins.sh",
|
||||
JenkinsScriptsVolumePath, InitScriptName),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -12,7 +12,7 @@ import (
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
)
|
||||
|
||||
const installPluginsCommand = "install-plugins.sh"
|
||||
const installPluginsCommand = "jenkins-plugin-cli"
|
||||
|
||||
// bash scripts installs single jenkins plugin with specific version
|
||||
const installPluginsBashScript = `#!/bin/bash -eu
|
||||
@@ -341,30 +341,23 @@ chmod +x {{ .JenkinsHomePath }}/scripts/*.sh
|
||||
{{- $installPluginsCommand := .InstallPluginsCommand }}
|
||||
|
||||
echo "Installing plugins required by Operator - begin"
|
||||
cat > {{ .JenkinsHomePath }}/base-plugins << EOF
|
||||
cat > {{ .JenkinsHomePath }}/base-plugins.txt << EOF
|
||||
{{ range $index, $plugin := .BasePlugins }}
|
||||
{{ $plugin.Name }}:{{ $plugin.Version }}{{if $plugin.DownloadURL}}:{{ $plugin.DownloadURL }}{{end}}
|
||||
{{ end }}
|
||||
EOF
|
||||
|
||||
if [[ -z "${OPENSHIFT_JENKINS_IMAGE_VERSION}" ]]; then
|
||||
{{ $installPluginsCommand }} < {{ .JenkinsHomePath }}/base-plugins
|
||||
else
|
||||
{{ $installPluginsCommand }} {{ .JenkinsHomePath }}/base-plugins
|
||||
fi
|
||||
{{ $installPluginsCommand }} --verbose -f {{ .JenkinsHomePath }}/base-plugins.txt
|
||||
echo "Installing plugins required by Operator - end"
|
||||
|
||||
echo "Installing plugins required by user - begin"
|
||||
cat > {{ .JenkinsHomePath }}/user-plugins << EOF
|
||||
cat > {{ .JenkinsHomePath }}/user-plugins.txt << EOF
|
||||
{{ range $index, $plugin := .UserPlugins }}
|
||||
{{ $plugin.Name }}:{{ $plugin.Version }}{{if $plugin.DownloadURL}}:{{ $plugin.DownloadURL }}{{end}}
|
||||
{{ end }}
|
||||
EOF
|
||||
if [[ -z "${OPENSHIFT_JENKINS_IMAGE_VERSION}" ]]; then
|
||||
{{ $installPluginsCommand }} < {{ .JenkinsHomePath }}/user-plugins
|
||||
else
|
||||
{{ $installPluginsCommand }} {{ .JenkinsHomePath }}/user-plugins
|
||||
fi
|
||||
|
||||
{{ $installPluginsCommand }} --verbose -f {{ .JenkinsHomePath }}/user-plugins.txt
|
||||
echo "Installing plugins required by user - end"
|
||||
`))
|
||||
|
||||
@@ -388,7 +381,7 @@ func buildInitBashScript(jenkins *v1alpha2.Jenkins) (*string, error) {
|
||||
InitConfigurationPath: jenkinsInitConfigurationVolumePath,
|
||||
BasePlugins: jenkins.Spec.Master.BasePlugins,
|
||||
UserPlugins: jenkins.Spec.Master.Plugins,
|
||||
InstallPluginsCommand: JenkinsScriptsVolumePath + "/" + installPluginsCommand,
|
||||
InstallPluginsCommand: installPluginsCommand,
|
||||
JenkinsScriptsVolumePath: JenkinsScriptsVolumePath,
|
||||
}
|
||||
|
||||
|
||||
@@ -905,7 +905,7 @@ func TestValidateJenkinsMasterContainerCommand(t *testing.T) {
|
||||
Command: []string{
|
||||
"bash",
|
||||
"-c",
|
||||
fmt.Sprintf("%s/%s && my-extra-command.sh && exec /sbin/tini -s -- /usr/local/bin/jenkins.sh",
|
||||
fmt.Sprintf("%s/%s && my-extra-command.sh && exec /usr/bin/tini -s -- /usr/local/bin/jenkins.sh",
|
||||
resources.JenkinsScriptsVolumePath, resources.InitScriptName),
|
||||
},
|
||||
},
|
||||
@@ -929,7 +929,7 @@ func TestValidateJenkinsMasterContainerCommand(t *testing.T) {
|
||||
Command: []string{
|
||||
"bash",
|
||||
"-c",
|
||||
fmt.Sprintf("%s/%s && my-extra-command.sh && /sbin/tini -s -- /usr/local/bin/jenkins.sh",
|
||||
fmt.Sprintf("%s/%s && my-extra-command.sh && /usr/bin/tini -s -- /usr/local/bin/jenkins.sh",
|
||||
resources.JenkinsScriptsVolumePath, resources.InitScriptName),
|
||||
},
|
||||
},
|
||||
|
||||
@@ -46,7 +46,7 @@ const (
|
||||
AgentName = "seed-job-agent"
|
||||
|
||||
// DefaultAgentImage is the default image used for the seed-job agent
|
||||
defaultAgentImage = "jenkins/inbound-agent:4.9-1"
|
||||
defaultAgentImage = "jenkins/inbound-agent:4.10-3"
|
||||
|
||||
creatingGroovyScriptName = "seed-job-groovy-script.groovy"
|
||||
|
||||
|
||||
@@ -113,7 +113,7 @@ func TestEnsureSeedJobs(t *testing.T) {
|
||||
var agentDeployment appsv1.Deployment
|
||||
err = fakeClient.Get(ctx, types.NamespacedName{Namespace: jenkins.Namespace, Name: agentDeploymentName(*jenkins, AgentName)}, &agentDeployment)
|
||||
assert.NoError(t, err)
|
||||
assert.Equal(t, "jenkins/inbound-agent:4.9-1", agentDeployment.Spec.Template.Spec.Containers[0].Image)
|
||||
assert.Equal(t, "jenkins/inbound-agent:4.10-3", agentDeployment.Spec.Template.Spec.Containers[0].Image)
|
||||
})
|
||||
|
||||
t.Run("delete agent deployment when no seed jobs", func(t *testing.T) {
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
package plugins
|
||||
|
||||
const (
|
||||
configurationAsCodePlugin = "configuration-as-code:1346.ve8cfa_3473c94"
|
||||
gitPlugin = "git:4.11.3"
|
||||
jobDslPlugin = "job-dsl:1.78.1"
|
||||
kubernetesPlugin = "kubernetes:1.31.3"
|
||||
kubernetesCredentialsProviderPlugin = "kubernetes-credentials-provider:0.20"
|
||||
workflowAggregatorPlugin = "workflow-aggregator:2.6"
|
||||
workflowJobPlugin = "workflow-job:1145.v7f2433caa07f"
|
||||
configurationAsCodePlugin = "configuration-as-code:1569.vb_72405b_80249"
|
||||
gitPlugin = "git:5.0.0"
|
||||
jobDslPlugin = "job-dsl:1.81"
|
||||
kubernetesPlugin = "kubernetes:3802.vb_b_600831fcb_3"
|
||||
kubernetesCredentialsProviderPlugin = "kubernetes-credentials-provider:1.208.v128ee9800c04"
|
||||
workflowAggregatorPlugin = "workflow-aggregator:590.v6a_d052e5a_a_b_5"
|
||||
workflowJobPlugin = "workflow-job:1254.v3f64639b_11dd"
|
||||
)
|
||||
|
||||
// basePluginsList contains plugins to install by operator.
|
||||
|
||||
Reference in New Issue
Block a user