Jenkinsfile 7.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175
  1. def SERIAL
  2. pipeline {
  3. agent {
  4. label "swarm"
  5. }
  6. environment {
  7. DOCKER_REGISTRY='dev-registry.infoclinica.ru:5000'
  8. DOCKER_IMAGE='ovpn'
  9. SERVICE_NAME='ovpn_server'
  10. SERVICE_IMAGE='container_run'
  11. SWARM_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/stack-deploy.git'
  12. SWARM_GIT_NAME='stack-deploy'
  13. PKI_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/openvpn-pki.git'
  14. PKI_GIT_NAME='openvpn-pki'
  15. OVPN_GIT_DIR='openvpn'
  16. JENKINS_MAIL='jenkins@sdsys.ru'
  17. CLUSTER_NAME='dev-iru-swarm.infoclinica.lan'
  18. }
  19. parameters {
  20. string(
  21. name: "branch",
  22. defaultValue: "97009",
  23. description: "Which branch to use"
  24. )
  25. string(
  26. name: "mailto",
  27. defaultValue: "tomishinets.v@sdsys.ru",
  28. description: "Email which has to be notified."
  29. )
  30. }
  31. stages {
  32. stage ("Discover SERIAL") {
  33. steps {
  34. script {
  35. SERIAL = sh script: "echo -n `date +%y%m%d``printf %03d $BUILD_NUMBER`", returnStdout: true
  36. }
  37. }
  38. }
  39. stage("Pull PKI repo") {
  40. steps {
  41. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  42. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  43. git clone ${PKI_GIT_URL} && cd ${WORKSPACE}/${PKI_GIT_NAME} && git checkout ${branch} && cd ${WORKSPACE}
  44. '''
  45. }
  46. sh '''cp ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/ca.crt \
  47. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/server.crt \
  48. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/server.key \
  49. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/sds-test.crt \
  50. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/sds-test.key \
  51. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/ta.key \
  52. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/stonevpn.crl \
  53. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/dh2048.pem \
  54. ${WORKSPACE}/openvpn/keys
  55. ls -al ${WORKSPACE}/openvpn/keys/
  56. '''
  57. }
  58. }
  59. /* stage("Build") {
  60. steps {
  61. echo "Building ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}."
  62. sh "docker build --no-cache -t ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} ."
  63. }
  64. }
  65. stage("Staging") {
  66. steps {
  67. echo "Run ${DOCKER_IMAGE} in server mode."
  68. sh '''container_id_server=`docker run -d --rm -e "mode=server" \
  69. --privileged ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}`
  70. container_ip_server=`docker inspect ${container_id_server} --format='{{.NetworkSettings.IPAddress}}'`
  71. container_id_client=`docker run -d --rm -e "mode=client" -e "server=${container_ip_server}" --privileged ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}`
  72. sleep 15
  73. docker exec ${container_id_client} ping -c 3 -q 10.10.20.1
  74. if [ $? != 0 ]
  75. then
  76. echo "Can not connect to VPN server !!!"
  77. docker stop ${container_id_server} ${container_id_client}
  78. exit 1
  79. else
  80. echo "VPN server is started"
  81. docker stop ${container_id_server} ${container_id_client}
  82. fi
  83. '''
  84. }
  85. }
  86. stage("Publish") {
  87. steps {
  88. echo "Publishing ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}."
  89. sh "docker push ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}"
  90. }
  91. }
  92. stage("Prod-like") {
  93. steps {
  94. echo "Check Prod-like cluster status"
  95. sh '''ping -c 2 ${CLUSTER_NAME}
  96. if [ $? -eq 0 ]; then
  97. export DOCKER_CERT_PATH=/run/secrets/swarm
  98. export DOCKER_HOST=tcp://${CLUSTER_NAME}:2376 DOCKER_TLS_VERIFY=1
  99. docker node ls --format "{{.Hostname}} {{.TLSStatus}}" | while read host status
  100. do
  101. if [ $status != Ready ]; then echo "Cluster ${CLUSTER_NAME} state is inconsistent"; exit 1
  102. else echo "HOST: $host STATUS: $status"
  103. fi
  104. done
  105. else echo "Host not Found"; exit 1
  106. fi
  107. '''
  108. echo "Run containers in Prod-like"
  109. sh '''export DOCKER_CERT_PATH=/run/secrets/swarm
  110. export DOCKER_HOST=tcp://${CLUSTER_NAME}:2376 DOCKER_TLS_VERIFY=1
  111. export DOCKER_HOST=tcp://$(docker info -f '{{.Name}}'):2376 DOCKER_TLS_VERIFY=1
  112. if [ -z $(docker service ps -q ${DOCKER_IMAGE}) ];then
  113. docker service create --replicas 1 \
  114. --mount type=bind,source=/var/run/docker.sock,destination=/var/run/docker.sock \
  115. --name ${SERVICE_NAME} ${DOCKER_REGISTRY}/${SERVICE_IMAGE}:2 -p 1194:1194 \
  116. --privileged --security-opt seccomp=unconfined \
  117. --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro \
  118. -e "mode=server" ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}
  119. else
  120. docker service update \
  121. --args "-p 1194:1194 --privileged --security-opt seccomp=unconfined \
  122. --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro \
  123. -e "mode=server" ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}" \
  124. ${SERVICE_NAME}
  125. if [ $? != 0 ]; then docker service rollback ${SERVICE_NAME}; fi
  126. fi
  127. '''
  128. }
  129. }
  130. stage("Tagging") {
  131. steps {
  132. echo "Tagging ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} to ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:latest"
  133. sh '''docker tag ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} \
  134. ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:latest
  135. docker push ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:latest
  136. '''
  137. echo "Updating tag info in ${SWARM_GIT_NAME} repository"
  138. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  139. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  140. git clone ${SWARM_GIT_URL}
  141. cd ${SWARM_GIT_NAME}
  142. echo -n ${BUILD_NUMBER} > tags/${DOCKER_IMAGE}.version
  143. git add -A
  144. git config --global user.email "${JENKINS_MAIL}"
  145. git config --global user.name "Jenkins"
  146. git commit -m 'Version update'
  147. GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  148. git push origin master
  149. '''
  150. }
  151. }
  152. }
  153. */ }
  154. post {
  155. always {
  156. echo "CleaningUp work directory"
  157. deleteDir()
  158. }
  159. failure {
  160. mail charset: 'UTF-8',
  161. subject: "Jenkins build ERROR",
  162. mimeType: 'text/html',
  163. to: "${mailto}",
  164. body: "<b>ATTENTION!!!</b> <b><br> Jenkins job failed.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  165. }
  166. success {
  167. mail charset: 'UTF-8',
  168. subject: "Jenkins build SUSCCESS",
  169. mimeType: 'text/html',
  170. to: "${mailto}",
  171. body: "<b>Congradulations!!!</b> <b><br> Jenkins job succefully finished.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  172. }
  173. }
  174. }