Jenkinsfile_keygen 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. pipeline {
  2. agent {
  3. label "swarm"
  4. }
  5. environment {
  6. DOCKER_REGISTRY='dev-registry.infoclinica.ru:5000'
  7. DOCKER_IMAGE='ovpn-rsa'
  8. SERVICE_NAME="keygen"
  9. PKI_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/openvpn-pki.git'
  10. PKI_GIT_NAME='openvpn-pki'
  11. OVPN_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/openvpn.git'
  12. OVPN_GIT_DIR='openvpn'
  13. JENKINS_MAIL='jenkins.dev@sdsys.ru'
  14. SMTP_SERVER='mail.sdsys.ru'
  15. DOCKER_CERT_PATH='/run/secrets/swarm'
  16. COMMAND=''
  17. }
  18. parameters {
  19. string(
  20. name: "branch",
  21. defaultValue: "master",
  22. description: "Which branch to use"
  23. )
  24. choice (
  25. choices: 'keygen\nrevoke',
  26. description: 'Whats is action?',
  27. name: 'TASK_ACTION')
  28. choice (
  29. choices: 'client\nadmin',
  30. description: 'Whats is mode?',
  31. name: 'MODE')
  32. string(
  33. name: "client_mail",
  34. defaultValue: "tomishinets.v@sdsys.ru",
  35. description: "Email which has to be recieved certs and key"
  36. )
  37. string(
  38. name: "key_name",
  39. defaultValue: "test",
  40. description: "The names for generation keys and certs."
  41. )
  42. string(
  43. name: "mailto",
  44. defaultValue: "tomishinets.v@sdsys.ru",
  45. description: "Email which has to be notified."
  46. )
  47. }
  48. stages {
  49. stage("Pull repo") {
  50. steps {
  51. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  52. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  53. git clone ${PKI_GIT_URL}
  54. cd ${WORKSPACE}/${PKI_GIT_NAME} && git checkout ${branch}
  55. '''
  56. }
  57. }
  58. }
  59. stage("Generate Keys and Certs or Revoke") {
  60. steps {
  61. script {
  62. switch (TASK_ACTION) {
  63. case 'keygen':
  64. def cert = "${WORKSPACE}/${PKI_GIT_NAME}/open/easy-rsa/client_keys/sds-${key_name}.zip"
  65. if (fileExists(cert)) {
  66. currentBuild.result = 'ABORTED'
  67. error ("Cert already exist!!!")
  68. return
  69. }
  70. COMMAND ="keygen.sh"
  71. break
  72. case 'revoke':
  73. def cert = "${WORKSPACE}/${PKI_GIT_NAME}/open/easy-rsa/client_keys/sds-${key_name}.zip"
  74. if (!fileExists(cert)) {
  75. currentBuild.result = 'ABORTED'
  76. error ("Cert doesn't exist!!!")
  77. return
  78. }
  79. COMMAND ="revoke.sh"
  80. break
  81. }
  82. echo "Running ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:latest."
  83. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  84. sh """set +x
  85. docker pull $DOCKER_REGISTRY/iru/$DOCKER_IMAGE:latest
  86. docker run -i --rm -e TZ=Europe/Moscow -e mode=keygen -e "SSHKEY=`cat ${GIT_SSH_KEY}`" \
  87. -e git_url=$PKI_GIT_URL -e git_dir=$PKI_GIT_NAME \
  88. $DOCKER_REGISTRY/iru/$DOCKER_IMAGE:latest /tmp/$COMMAND $key_name $branch
  89. """
  90. }
  91. }
  92. }
  93. }
  94. stage("Pull new version of REPOs") {
  95. steps {
  96. script {
  97. echo "Delete old repo version"
  98. sh 'rm -rf ${WORKSPACE}/${PKI_GIT_NAME} && rm -rf ${WORKSPACE}/${OVPN_GIT_DIR}'
  99. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  100. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  101. git clone ${OVPN_GIT_URL}
  102. cd ${WORKSPACE}/${OVPN_GIT_DIR} && git checkout ${branch} && cd ${WORKSPACE}
  103. GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  104. git clone ${PKI_GIT_URL}
  105. cd ${WORKSPACE}/${PKI_GIT_NAME} && git checkout ${branch}
  106. '''
  107. }
  108. }
  109. }
  110. }
  111. stage("Generate configs") {
  112. when {
  113. expression { params.TASK_ACTION == 'keygen' }
  114. }
  115. steps {
  116. script {
  117. switch (MODE) {
  118. case 'client':
  119. file = "${WORKSPACE}/${OVPN_GIT_DIR}/ip_client.txt"
  120. break
  121. case 'admin':
  122. file = "${WORKSPACE}/${OVPN_GIT_DIR}/ip_admin.txt"
  123. break
  124. }
  125. string ip = readFile(file)
  126. split = ip.tokenize(".")
  127. if (split[3].toInteger() >= 254) {
  128. currentBuild.result == 'FAILURE'
  129. error ("The last oktet => 254!!!")
  130. return
  131. } else {
  132. split[3] = (split[3].toInteger() + 1) + ""
  133. def newIp = split.join(".")
  134. string txt = split[3].toString()
  135. writeFile file: file, text: newIp
  136. def conf = "${WORKSPACE}/${OVPN_GIT_DIR}/${OVPN_GIT_DIR}/ccd/${key_name}"
  137. writeFile file: conf, text: "ifconfig-push " + newIp + " 255.255.0.0"
  138. }
  139. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  140. sh '''cd ${OVPN_GIT_DIR}
  141. echo "Add new config for ${key_name}" > ../commit.txt
  142. git add -A
  143. git config --global user.email "${JENKINS_MAIL}"
  144. git config --global user.name "Jenkins"
  145. git commit -F ../commit.txt
  146. GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  147. git push origin ${branch}
  148. '''
  149. }
  150. }
  151. }
  152. }
  153. post {
  154. always {
  155. echo "CleaningUp work directory"
  156. deleteDir()
  157. }
  158. failure {
  159. mail charset: 'UTF-8',
  160. subject: "Jenkins build ERROR",
  161. mimeType: 'text/html',
  162. to: "${mailto}",
  163. body: "<b>ATTENTION!!!</b> <b><br> Jenkins job failed.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  164. }
  165. aborted {
  166. mail charset: 'UTF-8',
  167. subject: "Jenkins build ERROR",
  168. mimeType: 'text/html',
  169. to: "${client_mail}",
  170. body: "<b>ATTENTION!!!</b> <b><br> Jenkins job aborted.\n\n <b><br> The CNAME ${key_name} is already exists!\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  171. }
  172. }
  173. }