Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 13 additions & 9 deletions ci/fix-buildhost.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,17 +2,19 @@
# it is expected that this file is sourced, not executed directly
set -ex

# Resolve our own directory up front: the ci/ scripts sourced and run below live
# next to this file. Previously this was only computed in the centos-7 branch,
# leaving $my_dir empty for the linux-install-* calls further down. This file is
# sourced rather than executed, so BASH_SOURCE names it where $0 names the caller.
my_dir="$(dirname "${BASH_SOURCE[0]}")"
if command -v realpath >/dev/null; then
my_dir="$(realpath "$my_dir")"
fi

if [ -f /etc/os-release ]; then
source /etc/os-release
if [ "$ID" = "centos" ] && [ "$VERSION_ID" = "7" ]; then
if command -v realpath >/dev/null; then
my_path="$(realpath "${BASH_SOURCE[0]}")"
my_dir="$(dirname "$my_path")"
source "$my_dir"/centos-7-setup-devtoolset-11.sh
else
echo "FAIL: could not find realpath command on rhel/centos-7 to source needed centos-7-setup-devtoolset-11.sh"
exit 1
fi
source "$my_dir"/centos-7-setup-devtoolset-11.sh
fi
fi

Expand All @@ -30,7 +32,9 @@ if [ -f /etc/profile ]; then
fi

mkdir -p ~/.ssh
echo "build-artifacts-cache.cloud.cfengine.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGahpsY8Phk2+isBmuJQjjQVlh6BNL/Qetc14g26gowV" >> ~/.ssh/known_hosts
# Only the cache host is needed here; github.com is not contacted from a build
# host. Which key type gets used depends on the client, so pin all of them.
grep '^build-artifacts-cache' "$my_dir"/known_hosts >> ~/.ssh/known_hosts

# /etc/profile can contain tricky things, on suse for example it includes a call to tty which will fail in CI
# so only source /etc/profile where we absolutely need it.
Expand Down
16 changes: 16 additions & 0 deletions ci/known_hosts
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
# Pinned SSH host keys for the hosts CI connects to. Consumers grep out the
# host they need: github.com for source checkouts on an agent, and
# build-artifacts-cache for the dependency cache (used inside the build
# container and by ci/fix-buildhost.sh on the build hosts).
#
# All key types each host offers are listed, since which one is used depends on
# the client's HostKeyAlgorithms preference.
#
# ci/cfengine-build-host-setup.cf holds its own inline copy. That policy is being
# replaced by these scripts (ENT-14330), so it is not worth coupling to.
github.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl
github.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBEmKSENjQEezOmxkZMy7opKgwFB9nkt5YRrYMjNuG5N87uRgg6CLrbo5wAdT/y6v0mKV0U2w0WZ2YB/++Tpockg=
github.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCj7ndNxQowgcQnjshcLrqPEiiphnt+VTTvDP6mHBL9j1aNUkY4Ue1gvwnGLVlOhGeYrnZaMgRK6+PKCUXaDbC7qtbW8gIkhL7aGCsOr/C56SJMy/BCZfxd1nWzAOxSDPgVsmerOBYfNqltV9/hWCqBywINIR+5dIg6JTJ72pcEpEjcYgXkE2YEFXV1JHnsKgbLWNlhScqb2UmyRkQyytRLtL+38TGxkxCflmO+5Z8CSSNY7GidjMIZ7Q4zMjA2n1nGrlTDkzwDCsw+wqFPGQA179cnfGWOWRVruj16z6XyvxvjJwbz0wQZ75XK5tKSb7FNyeIEs4TT4jk+S4dhPeAUC5y+bDYirYgM4GC7uEnztnZyaVWQ7B381AK4Qdrwt51ZqExKbQpTUNn+EjqoTwvqNj4kqx5QUCI0ThS/YkOxJCXmPUWZbhjpCg56i+2aB6CmK2JGhn57K5mj0MNdBXA4/WnwH6XoPWJzK5Nyu2zB3nAZp+S5hpQs+p1vN1/wsjk=
build-artifacts-cache.cloud.cfengine.com ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGahpsY8Phk2+isBmuJQjjQVlh6BNL/Qetc14g26gowV
build-artifacts-cache.cloud.cfengine.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCdv55BmDmwEjN3izaL8intrSRJQglkv++TaQppopKCh5VkYuSpNj/W+x0vjxwL3+NNp4CAhOLYuGTFuUL8zz/H0kwWE06c3WjghpHS3NS1usiamVZN6uaJMGwDaq8fPB3WiiI/L5lLM8/ubXxfmta0UlVufHCiBH8pBQarAY5rdPDtITXzu56qIa3k9Ou7Si2r/1n37espzwsPxoBqVJg7BvzMV28MzxdmQpGP6puuPfi9tvYbtnF788le3jvGOc+3GOiwtXsv44y/PCJNhi7sFeUfxocuNbWXZ3x/UEfbN8IiUVZsUAuLQFeqr3pv4w28D+SvJHBMCFudygenmLc3th+typiFRmqam7UQif9Pa3e2FxX4ghTp1KNXBoCQluIk2j7wX9zXppSyUG6d7tPDzfu81lImuW34+bsZvYq+s+25vbAhSDdQe1lqG0Fdvvi+zbqrMYQuMfnInDrK52xNSZcfATWjudhmY6wiwdSS0XsBADmZsy3qf3ErdEabqQk=
build-artifacts-cache.cloud.cfengine.com ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBIzU5+SoC4gbtV3Wfw4oB6oMs5RYKGFCiS0lVeN4XQlAM8UjvyUUSflytf/vQEANv1OJs5vicslRn/iPlrvF8Mk=
2 changes: 1 addition & 1 deletion ci/setup-cfengine-build-host.sh
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,7 @@ if [ -f /etc/cfengine-bootstrap-pr-host.flag ]; then
exit
fi

if [ -f /etc/cfengine-containers-host.flag ]; then
if [ -f /etc/cfengine-containers-host.flag ] || [ -f /etc/cfengine-docker-host.flag ]; then
"$thisdir"/setup-ci-host.sh
exit
fi
Expand Down
78 changes: 73 additions & 5 deletions ci/setup-ci-host.sh
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,48 @@ EOF
fi
fi

# Hosts for the build-in-container job (ENT-14361). They only run containers:
# the target platform comes from the image, so none of the native build
# toolchain below is wanted here.
if [ -f /etc/cfengine-docker-host.flag ]; then
case "$ID" in
debian | ubuntu) ;;
*)
echo "docker host setup supports debian and ubuntu, not $ID"
exit 1
;;
esac

# Docker CE from upstream rather than the distribution's docker.io, since
# build-in-container.py passes --build-context and so needs BuildKit.
# Follows https://docs.docker.com/engine/install/ubuntu/ ("Install using the
# apt repository"); the debian page has the same steps with the other URI.
apt-get -y install ca-certificates curl
install -m 0755 -d /etc/apt/keyrings
curl -fsSL "https://download.docker.com/linux/$ID/gpg" -o /etc/apt/keyrings/docker.asc
chmod a+r /etc/apt/keyrings/docker.asc
tee /etc/apt/sources.list.d/docker.sources << EOF
Types: deb
URIs: https://download.docker.com/linux/$ID
Suites: ${UBUNTU_CODENAME:-$VERSION_CODENAME}
Components: stable
Architectures: $(dpkg --print-architecture)
Signed-By: /etc/apt/keyrings/docker.asc
EOF
apt-get -qy update

# docker-compose-plugin, the fifth package the documented command installs,
# is deliberately left out: nothing we run calls docker compose.
add-pkg containerd.io
add-pkg docker-buildx-plugin
add-pkg docker-ce
add-pkg docker-ce-cli
add-pkg git # the pipeline checks the source repos out on the agent
add-pkg jq
add-pkg python3 # runs build-in-container.py
add-pkg rsync
fi

if [ "$redhat" != 0 ]; then
if [ "$redhat" -gt 7 ]; then
if ! grep best=False /etc/yum.conf; then
Expand Down Expand Up @@ -185,13 +227,39 @@ if command -v coredumpctl >/dev/null; then
fi
fi

# Host keys for the ssh source checkouts. These come from
# cfengine-build-host-setup.cf today, which will be obsolete in ENT-14330.
mkdir -p /home/jenkins/.ssh
cat "$thisdir"/known_hosts >> /home/jenkins/.ssh/known_hosts
chown -R jenkins:jenkins /home/jenkins/.ssh

"$thisdir"/linux-install-jdk.sh # the script should skip if sufficient java is already installed

# leech2 build toolchain host
if [ "$ubuntu" -ge 20 ] || [ "$debian" -ge 12 ] || [ "$redhat" -ge 7 ]; then
"$thisdir"/linux-install-protobuf.sh
# TODO if mingw then pass along x86_64-pc-windows-gnu as an arg to install rust
"$thisdir"/linux-install-rust.sh
if [ -f /etc/cfengine-docker-host.flag ]; then
systemctl enable --now docker

# Give jenkins access to the docker socket, per
# https://docs.docker.com/engine/install/linux-postinstall/.
groupadd -f docker
usermod -aG docker jenkins

# Dependency cache root for build-in-container.py's --cache-dir. Outside any
# workspace so that cleanWs() cannot wipe it between builds.
install -d -o jenkins -g jenkins /home/jenkins/cfengine-build-cache

docker --version
docker buildx version
sudo -u jenkins docker info
fi

# leech2 build toolchain host. Not on a docker host, where the toolchain belongs
# in the build images.
if [ ! -f /etc/cfengine-docker-host.flag ]; then
if [ "$ubuntu" -ge 20 ] || [ "$debian" -ge 12 ] || [ "$redhat" -ge 7 ]; then
"$thisdir"/linux-install-protobuf.sh
# TODO if mingw then pass along x86_64-pc-windows-gnu as an arg to install rust
"$thisdir"/linux-install-rust.sh
fi
fi

if [ "$redhat" -ge 7 ]; then
Expand Down
Loading