chore: pipelines init
This commit is contained in:
commit
3288087310
23
pipelines/build-pipeline.yaml
Normal file
23
pipelines/build-pipeline.yaml
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
apiVersion: triggers.tekton.dev/v1beta1
|
||||||
|
kind: EventListener
|
||||||
|
metadata:
|
||||||
|
name: cicd-listener
|
||||||
|
namespace: tekton-pipelines
|
||||||
|
spec:
|
||||||
|
serviceAccountName: tekton-triggers-sa # Needs RBAC to start PipelineRuns
|
||||||
|
triggers:
|
||||||
|
- name: github-push
|
||||||
|
interceptors:
|
||||||
|
- ref:
|
||||||
|
name: github
|
||||||
|
params:
|
||||||
|
- name: secretRef
|
||||||
|
value:
|
||||||
|
secretName: webhook-secret
|
||||||
|
secretKey: token
|
||||||
|
- name: eventTypes
|
||||||
|
value: ["push"]
|
||||||
|
bindings:
|
||||||
|
- ref: git-binding # Maps JSON payload to Params
|
||||||
|
template:
|
||||||
|
ref: build-template # Creates the PipelineRun
|
||||||
13
tasks/cleanup-preview.yaml
Normal file
13
tasks/cleanup-preview.yaml
Normal file
|
|
@ -0,0 +1,13 @@
|
||||||
|
apiVersion: tekton.dev/v1beta1
|
||||||
|
kind: Task
|
||||||
|
metadata:
|
||||||
|
name: cleanup-preview
|
||||||
|
spec:
|
||||||
|
params:
|
||||||
|
- name: app-name
|
||||||
|
- name: pr-number
|
||||||
|
steps:
|
||||||
|
- name: delete-ns
|
||||||
|
image: bitnami/kubectl:latest
|
||||||
|
script: |
|
||||||
|
kubectl delete namespace preview-$(params.app-name)-$(params.pr-number) --ignore-not-found
|
||||||
21
tasks/git-clone.yaml
Normal file
21
tasks/git-clone.yaml
Normal file
|
|
@ -0,0 +1,21 @@
|
||||||
|
apiVersion: tekton.dev/v1beta1
|
||||||
|
kind: Task
|
||||||
|
metadata:
|
||||||
|
name: git-clone
|
||||||
|
namespace: tekton-pipelines
|
||||||
|
spec:
|
||||||
|
workspaces:
|
||||||
|
- name: output
|
||||||
|
params:
|
||||||
|
- name: url
|
||||||
|
type: string
|
||||||
|
- name: revision
|
||||||
|
type: string
|
||||||
|
default: main
|
||||||
|
steps:
|
||||||
|
- name: clone
|
||||||
|
image: alpine/git
|
||||||
|
script: |
|
||||||
|
git clone $(params.url) $(workspaces.output.path)
|
||||||
|
cd $(workspaces.output.path)
|
||||||
|
git checkout $(params.revision)
|
||||||
68
tasks/manage-preview.yaml
Normal file
68
tasks/manage-preview.yaml
Normal file
|
|
@ -0,0 +1,68 @@
|
||||||
|
apiVersion: tekton.dev/v1beta1
|
||||||
|
kind: Task
|
||||||
|
metadata:
|
||||||
|
name: manage-preview
|
||||||
|
namespace: tekton-pipelines
|
||||||
|
spec:
|
||||||
|
params:
|
||||||
|
- name: app-name
|
||||||
|
- name: pr-number
|
||||||
|
- name: action # "apply" or "delete"
|
||||||
|
- name: image-tag
|
||||||
|
default: "latest"
|
||||||
|
workspaces:
|
||||||
|
- name: source # Workspace containing the app's code (to find preview/values.yaml)
|
||||||
|
steps:
|
||||||
|
- name: preview-logic
|
||||||
|
image: bitnami/kubectl:latest
|
||||||
|
workingDir: $(workspaces.source.path)
|
||||||
|
script: |
|
||||||
|
# Use a specific naming convention for the PR namespace
|
||||||
|
NS="$(params.app-name)-pr-$(params.pr-number)"
|
||||||
|
|
||||||
|
if [ "$(params.action)" = "delete" ]; then
|
||||||
|
echo "Cleaning up PR environment..."
|
||||||
|
kubectl delete namespace $NS --ignore-not-found
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Deploying PR environment to namespace: $NS"
|
||||||
|
kubectl create namespace $NS --dry-run=client -o yaml | kubectl apply -f -
|
||||||
|
|
||||||
|
# Check if the app repo has custom preview values
|
||||||
|
VALUES_REF_YAML=""
|
||||||
|
if [ -f "preview/values.yaml" ]; then
|
||||||
|
kubectl create configmap preview-values --from-file=values.yaml=preview/values.yaml \
|
||||||
|
-n $NS --dry-run=client -o yaml | kubectl apply -f -
|
||||||
|
VALUES_REF_YAML="- kind: ConfigMap\n name: preview-values"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Apply the HelmRelease for this specific PR
|
||||||
|
cat <<EOF | kubectl apply -n $NS -f -
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2beta1
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: $(params.app-name)-pr-$(params.pr-number)
|
||||||
|
spec:
|
||||||
|
interval: 5m
|
||||||
|
releaseName: $(params.app-name)
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: charts/$(params.app-name)
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: ghcr-charts
|
||||||
|
namespace: flux-system
|
||||||
|
valuesFrom:
|
||||||
|
$(echo -e $VALUES_REF_YAML)
|
||||||
|
values:
|
||||||
|
image:
|
||||||
|
tag: "$(params.image-tag)"
|
||||||
|
ingress:
|
||||||
|
enabled: true
|
||||||
|
hosts:
|
||||||
|
- host: $(params.app-name)-pr-$(params.pr-number).nid3.com
|
||||||
|
paths:
|
||||||
|
- path: /
|
||||||
|
pathType: ImplementationSpecific
|
||||||
|
EOF
|
||||||
44
tasks/update-manifest.yaml
Normal file
44
tasks/update-manifest.yaml
Normal file
|
|
@ -0,0 +1,44 @@
|
||||||
|
apiVersion: tekton.dev/v1beta1
|
||||||
|
kind: Task
|
||||||
|
metadata:
|
||||||
|
name: update-manifest
|
||||||
|
namespace: tekton-pipelines
|
||||||
|
spec:
|
||||||
|
params:
|
||||||
|
- name: app-name
|
||||||
|
- name: image-tag
|
||||||
|
- name: env # staging or production
|
||||||
|
- name: create-branch
|
||||||
|
default: "false"
|
||||||
|
steps:
|
||||||
|
- name: git-update
|
||||||
|
image: alpine/git:latest
|
||||||
|
script: |
|
||||||
|
git config --global user.email "cicd-bot@nid3.com"
|
||||||
|
git config --global user.name "Pingu-CI-Bot"
|
||||||
|
|
||||||
|
# Clone manifest repo using secrets
|
||||||
|
git clone https://$(GIT_USER):$(GIT_PASS)@github.com/Pingu-Studio/cicd-deployment-manifests.git m
|
||||||
|
cd m
|
||||||
|
|
||||||
|
if [ "$(params.create-branch)" = "true" ]; then
|
||||||
|
git checkout -b promote-$(params.app-name)-$(params.image-tag)
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Update the image tag in the specific environment folder
|
||||||
|
TARGET_FILE="apps/$(params.env)/$(params.app-name)/release.yaml"
|
||||||
|
if [ -f "$TARGET_FILE" ]; then
|
||||||
|
sed -i "s/tag: .*/tag: \"$(params.image-tag)\"/" $TARGET_FILE
|
||||||
|
else
|
||||||
|
echo "Error: $TARGET_FILE not found"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
git add .
|
||||||
|
git commit -m "chore($(params.env)): update $(params.app-name) to $(params.image-tag)"
|
||||||
|
git push origin $(git rev-parse --abbrev-ref HEAD)
|
||||||
|
env:
|
||||||
|
- name: GIT_USER
|
||||||
|
valueFrom: { secretKeyRef: { name: github-auth, key: username } }
|
||||||
|
- name: GIT_PASS
|
||||||
|
valueFrom: { secretKeyRef: { name: github-auth, key: password } }
|
||||||
11
triggers/binding.yaml
Normal file
11
triggers/binding.yaml
Normal file
|
|
@ -0,0 +1,11 @@
|
||||||
|
apiVersion: triggers.tekton.dev/v1beta1
|
||||||
|
kind: TriggerBinding
|
||||||
|
metadata:
|
||||||
|
name: git-binding
|
||||||
|
namespace: tekton-pipelines
|
||||||
|
spec:
|
||||||
|
params:
|
||||||
|
- name: git-revision
|
||||||
|
value: $(body.head_commit.id)
|
||||||
|
- name: git-url
|
||||||
|
value: $(body.repository.clone_url)
|
||||||
23
triggers/event-listener.yaml
Normal file
23
triggers/event-listener.yaml
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
apiVersion: triggers.tekton.dev/v1beta1
|
||||||
|
kind: EventListener
|
||||||
|
metadata:
|
||||||
|
name: cicd-listener
|
||||||
|
namespace: tekton-pipelines
|
||||||
|
spec:
|
||||||
|
serviceAccountName: tekton-triggers-sa
|
||||||
|
triggers:
|
||||||
|
- name: generic-webhook-trigger
|
||||||
|
interceptors:
|
||||||
|
- ref:
|
||||||
|
name: "github" # Or "cel" for Forgejo
|
||||||
|
params:
|
||||||
|
- name: "secretRef"
|
||||||
|
value:
|
||||||
|
secretName: "webhook-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
- name: "eventTypes"
|
||||||
|
value: ["push", "pull_request"]
|
||||||
|
bindings:
|
||||||
|
- ref: generic-git-binding
|
||||||
|
template:
|
||||||
|
ref: app-bootstrap-template
|
||||||
Loading…
Reference in a new issue