Repository navigation
Expand file tree
/
Copy path.gitlab-ci.yml
More file actions
346 lines (311 loc) · 8.98 KB
/
Copy path.gitlab-ci.yml
File metadata and controls
346 lines (311 loc) · 8.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
include:
- template: Code-Quality.gitlab-ci.yml
- template: Security/SAST.gitlab-ci.yml
- template: Security/Dependency-Scanning.gitlab-ci.yml
- template: Security/Secret-Detection.gitlab-ci.yml
- component: ${CI_SERVER_FQDN}/gitlab-org/components/danger-review/danger-review@2.1.0
- component: ${CI_SERVER_FQDN}/components/code-intelligence/golang-code-intel@v0.1.2
inputs:
golang_version: ${GO_VERSION}
stage: post-test
stages:
- prepare
- lint
- test
- post-test
variables:
FF_USE_FASTZIP: "true"
TRANSFER_METER_FREQUENCY: "1s"
GOPATH: $CI_PROJECT_DIR/.GOPATH
DEBIAN_VERSION: "trixie"
POLICY: pull
CI_DEBUG_SERVICES: "true"
DOCKER_VERSION: "20.10.15"
GO_VERSION: "1.25"
NILAWAY_VERSION: "v0.0.0-20260915140140-59aa42bdc591"
UBI_VERSION: "9.6"
GITLAB_ADVANCED_SAST_ENABLED: "true"
IMAGE_TAG: "latest"
DEFAULT_IMAGE: "registry.gitlab.com/gitlab-org/gitlab-build-images/debian-${DEBIAN_VERSION}-golang-${GO_VERSION}:${IMAGE_TAG}"
FIPS_IMAGE_TAG: "latest"
FIPS_IMAGE: "registry.gitlab.com/gitlab-org/gitlab-build-images/ubi-${UBI_VERSION}-golang-${GO_VERSION}:${FIPS_IMAGE_TAG}"
GOTOOLCHAIN: local
workflow:
rules: &workflow_rules # For merge requests, create a pipeline.
- if: "$CI_MERGE_REQUEST_IID"
# For `main` branch, create a pipeline (this includes on schedules, pushes, merges, etc.).
- if: '$CI_COMMIT_BRANCH == "main"'
# For tags, create a pipeline.
- if: "$CI_COMMIT_TAG"
.rules:go-changes:
rules:
- changes: &go_change_paths
- .gitlab-ci.yml
- "go.mod"
- "go.sum"
- "**/*.go"
.rules:ssh-audit:
rules:
- changes: *go_change_paths
- changes:
- Makefile
- "support/ssh-audit/**/*"
default:
image: ${DEFAULT_IMAGE}
tags:
- gitlab-org
.use-docker-in-docker:
image: docker:${DOCKER_VERSION}
services:
- docker:${DOCKER_VERSION}-dind
tags:
# See https://gitlab.com/gitlab-com/www-gitlab-com/-/issues/7019 for tag descriptions
- gitlab-org-docker
.cached-go: &cached_go
- key:
prefix: "golang-${GO_VERSION}-cache"
files:
- go.mod
- go.sum
policy: $POLICY
paths:
- .GOPATH/pkg/mod/
.cached-go-job:
variables:
CACHE_COMPRESSION_LEVEL: "fastest"
cache:
- *cached_go
# The pinned ssh-audit download, cached so the ssh-audit jobs do not depend on
# github.com being reachable on every run. Keyed on the Makefile so bumping
# SSH_AUDIT_VERSION invalidates it.
.cached-ssh-audit: &cached_ssh_audit
key:
prefix: "ssh-audit"
files:
- Makefile
paths:
- support/bin/ssh-audit-*
.cached-job:
cache:
- *cached_go
.go-matrix-job:
parallel:
matrix:
- GO_VERSION: ["1.25", "1.26", "1.27"]
################################################################################
# Prepare jobs
################################################################################
modules:download:
stage: prepare
extends:
- .cached-go-job
- .go-matrix-job
variables:
POLICY: pull-push
script:
- go mod download
################################################################################
# Test jobs
################################################################################
.test-job:
needs: ["modules:download"]
rules: !reference [".rules:go-changes", rules]
variables:
GITALY_CONNECTION_INFO: '{"address":"tcp://gitaly:8075", "storage":"default"}'
before_script:
# Set up the environment to run integration tests
- make build
- cp config.yml.example config.yml
- go version
services:
- name: registry.gitlab.com/gitlab-org/build/cng/gitaly:master
# Disable the hooks so we don't have to stub the GitLab API
command:
[
"bash",
"-c",
"mkdir -p /home/git/repositories && rm -rf /srv/gitlab-shell/hooks/* && touch /srv/gitlab-shell/.gitlab_shell_secret && exec /usr/bin/env GITALY_TESTING_NO_GIT_HOOKS=1 /scripts/process-wrapper",
]
alias: gitaly
tests:
extends:
- .cached-job
- .go-matrix-job
- .test-job
script:
- make verify test_fancy
after_script:
- make coverage
coverage: '/\d+.\d+%/'
artifacts:
when: always
paths:
- cover.xml
reports:
junit: cover.xml
tests_without_cgo:
extends:
- .cached-job
- .go-matrix-job
- .test-job
variables:
CGO_ENABLED: 0
script:
- make verify test_fancy
tests:fips:
image: ${FIPS_IMAGE}
extends:
- .cached-job
- .test-job
variables:
FIPS_MODE: 1
GOLANG_FIPS: 1
script:
- make test_fancy
race:
extends:
- .cached-go-job
- .go-matrix-job
- .test-job
script:
- make test_race
acceptance:
stage: test
extends:
- .cached-go-job
- .go-matrix-job
needs: ["modules:download"]
rules: !reference [".rules:go-changes", rules]
script:
- make acceptance-test
# Verify gitlab-sshd's negotiated SSH algorithms against a committed ssh-audit
# policy so a dependency bump that silently adds or drops a cipher, key exchange
# or MAC fails the pipeline. See support/ssh-audit/README.md.
.ssh-audit-base:
stage: test
extends:
- .cached-go-job
needs: ["modules:download"]
rules: !reference [".rules:ssh-audit", rules]
# Overriding cache replaces the list inherited from .cached-go-job, so
# *cached_go must be listed again alongside the ssh-audit cache.
cache:
- *cached_go
- *cached_ssh_audit
script:
- make ssh-audit-test
ssh-audit:
extends: .ssh-audit-base
ssh-audit:fips:
extends: .ssh-audit-base
image: ${FIPS_IMAGE}
variables:
FIPS_MODE: 1
GOLANG_FIPS: 1
SSH_AUDIT_POLICY: support/ssh-audit/gitlab-sshd-fips.policy
SSH_AUDIT_HOST_KEY_TYPES: "rsa ecdsa"
before_script:
# The FIPS UBI image ships neither ssh-keygen (from openssh) nor python3,
# both of which the ssh-audit harness needs.
- dnf install -y openssh python3
code_quality:
stage: lint
extends: .use-docker-in-docker
rules: *workflow_rules
check_gitaly_version:
stage: lint
rules: *workflow_rules
## In case the job fails, mark the job as warning
## That way we don't block the pipeline but we warn the user
allow_failure: true
script:
- chmod +x ./support/lint_gitaly_version.sh
- ./support/lint_gitaly_version.sh
# SAST
semgrep-sast:
stage: lint
rules: *workflow_rules
gitlab-advanced-sast:
stage: lint
rules: *workflow_rules
# Dependency Scanning
gemnasium-dependency_scanning:
stage: lint
rules: *workflow_rules
# Secret Detection
secret_detection:
stage: lint
rules: *workflow_rules
build-package-and-qa:
stage: post-test
trigger:
project: "gitlab-org/build/omnibus-gitlab-mirror"
branch: "master"
strategy: depend
inherit:
variables: false
variables:
GITLAB_SHELL_VERSION: $CI_MERGE_REQUEST_SOURCE_BRANCH_SHA
TOP_UPSTREAM_SOURCE_PROJECT: $CI_PROJECT_PATH
TOP_UPSTREAM_SOURCE_REF: $CI_COMMIT_REF_NAME
TOP_UPSTREAM_SOURCE_JOB: $CI_JOB_URL
ee: "true"
rules:
# For MRs that change dependencies, we want to automatically ensure builds
# aren't broken. In such cases, we don't want the QA tests to be run
# automatically, but still available for developers to manually run.
- if: "$CI_MERGE_REQUEST_IID"
changes:
- go.sum
variables:
BUILD_ON_ALL_OS: "true"
MANUAL_QA_TEST: "true"
allow_failure: false
# For other MRs, we still provide this job as a manual job for developers
# to obtain a package for testing and run QA tests.
- if: "$CI_MERGE_REQUEST_IID"
when: manual
allow_failure: true
needs: []
modules:tidy:
stage: lint
needs: ["modules:download"]
script:
- go mod tidy
- git diff --exit-code go.mod go.sum
lint:
stage: lint
script:
# Write the code coverage report to gl-code-quality-report.json
# and print linting issues to stdout in the format: path/to/file:line description
# remove `--issues-exit-code 0` or set to non-zero to fail the job if linting issues are detected
- apt update && apt install -y jq
- make lint GOLANGCI_LINT_ARGS="--output.code-climate.path=gl-code-quality-report-temp.json --output.text.path=stdout"
- cat gl-code-quality-report-temp.json | jq '[ .[] | select(.severity == "warning").severity |= "minor" ]' > gl-code-quality-report.json
- rm -f gl-code-quality-report-temp.json
artifacts:
reports:
codequality: gl-code-quality-report.json
paths:
- gl-code-quality-report.json
nilaway:
stage: lint
rules: !reference [".rules:go-changes", rules]
before_script:
- go install go.uber.org/nilaway/cmd/nilaway@${NILAWAY_VERSION}
script:
- NILAWAY_EXIT_CODE=$(${GOPATH}/bin/nilaway -include-pkgs="gitlab.com/gitlab-org/gitlab-shell/v14" ./... > /tmp/out.txt 2>&1 ; echo $?) || true
- cat /tmp/out.txt
- exit ${NILAWAY_EXIT_CODE}
logging-field-validator:
stage: test
needs: ["modules:download"]
rules:
- changes:
- .gitlab-ci.yml
- "go.mod"
- "go.sum"
- "**/*.go"
- .labkit_logging_todo.yml
script:
- make validate-log-fields