Jenkinsfile 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192
  1. def ENAMES = [ 'prod', 'dev' ]
  2. def CLUSTERS = ['prod': 'iru-swarm1-open.infoclinica.lan', 'dev': 'dev-iru-swarm.infoclinica.lan']
  3. def REGISTRIES = ['prod': 'registry.infoclinica.ru:5000', 'dev': 'dev-registry.infoclinica.ru:5000']
  4. pipeline {
  5. agent {
  6. label "swarm"
  7. }
  8. environment {
  9. DOCKER_REGISTRY='dev-registry.infoclinica.ru:5000'
  10. DOCKER_IMAGE='ovpn'
  11. SERVICE_NAME='ovpn_server'
  12. SERVICE_IMAGE='container_run'
  13. SWARM_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/stack-deploy.git'
  14. SWARM_GIT_NAME='stack-deploy'
  15. PKI_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/openvpn-pki.git'
  16. PKI_GIT_NAME='openvpn-pki'
  17. OVPN_GIT_DIR='openvpn'
  18. JENKINS_MAIL='jenkins@sdsys.ru'
  19. CLUSTER_NAME='dev-iru-swarm.infoclinica.lan'
  20. }
  21. parameters {
  22. string(
  23. name: "branch",
  24. defaultValue: "97009",
  25. description: "Which branch to use"
  26. )
  27. string(
  28. name: "mailto",
  29. defaultValue: "tomishinets.v@sdsys.ru",
  30. description: "Email which has to be notified."
  31. )
  32. }
  33. stages {
  34. stage ("Discover SERIAL") {
  35. steps {
  36. script {
  37. SERIAL = sh script: "echo -n `date +%y%m%d``printf %03d $BUILD_NUMBER`", returnStdout: true
  38. }
  39. }
  40. }
  41. stage("Pull PKI repo") {
  42. steps {
  43. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  44. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  45. git clone ${PKI_GIT_URL} && cd ${WORKSPACE}/${PKI_GIT_NAME} && git checkout ${branch} && cd ${WORKSPACE}
  46. GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  47. git clone ${SWARM_GIT_URL}
  48. '''
  49. }
  50. sh '''cp ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/ca.crt \
  51. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/server.crt \
  52. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/server.key \
  53. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/sds-test.crt \
  54. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/sds-test.key \
  55. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/ta.key \
  56. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/stonevpn.crl \
  57. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/dh2048.pem \
  58. ${WORKSPACE}/openvpn/keys
  59. ls -al ${WORKSPACE}/openvpn/keys/
  60. '''
  61. }
  62. }
  63. stage("Build") {
  64. steps {
  65. echo "Building ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:${SERIAL}."
  66. sh """docker build --no-cache -t ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:${SERIAL} .
  67. if [ \$? != 0 ]; then echo 'The container was not built'; exit 1; fi
  68. """
  69. }
  70. }
  71. stage("Staging") {
  72. steps {
  73. echo "Run ${DOCKER_IMAGE} in server mode."
  74. sh """container_id_server=\$(docker run -d --rm -e "mode=server" --privileged ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:${SERIAL})
  75. container_ip_server=\$(docker inspect \${container_id_server} --format='{{.NetworkSettings.IPAddress}}')
  76. container_id_client=`docker run -d --rm -e "mode=client" -e "server=\${container_ip_server}" --privileged \${DOCKER_REGISTRY}/iru/\${DOCKER_IMAGE}:\${SERIAL}`
  77. sleep 15
  78. docker exec \${container_id_client} ping -c 3 -q 10.10.20.1
  79. if [ $? != 0 ]
  80. then
  81. echo "Can not connect to VPN server !!!"
  82. docker stop ${container_id_server} ${container_id_client}
  83. exit 1
  84. else
  85. echo "VPN server is started"
  86. docker stop ${container_id_server} ${container_id_client}
  87. fi
  88. """
  89. }
  90. }
  91. stage ("Push to registry") {
  92. steps {
  93. script {
  94. ENAMES.each { item ->
  95. echo "Pushing to: ${item}, CLUSTER ${CLUSTERS.get((item))}"
  96. sh """docker tag ${DOCKER_IMAGE}:${SERIAL} ${REGISTRIES.get((item))}/${DOCKER_IMAGE}:${SERIAL}
  97. docker push ${REGISTRIES.get((item))}/${DOCKER_IMAGE}:${SERIAL}
  98. """
  99. }
  100. }
  101. }
  102. }
  103. /* stage("Publish") {
  104. steps {
  105. echo "Publishing ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}."
  106. sh "docker push ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}"
  107. }
  108. }
  109. stage("Prod-like") {
  110. steps {
  111. echo "Check Prod-like cluster status"
  112. sh '''ping -c 2 ${CLUSTER_NAME}
  113. if [ $? -eq 0 ]; then
  114. export DOCKER_CERT_PATH=/run/secrets/swarm
  115. export DOCKER_HOST=tcp://${CLUSTER_NAME}:2376 DOCKER_TLS_VERIFY=1
  116. docker node ls --format "{{.Hostname}} {{.TLSStatus}}" | while read host status
  117. do
  118. if [ $status != Ready ]; then echo "Cluster ${CLUSTER_NAME} state is inconsistent"; exit 1
  119. else echo "HOST: $host STATUS: $status"
  120. fi
  121. done
  122. else echo "Host not Found"; exit 1
  123. fi
  124. '''
  125. echo "Run containers in Prod-like"
  126. sh '''export DOCKER_CERT_PATH=/run/secrets/swarm
  127. export DOCKER_HOST=tcp://${CLUSTER_NAME}:2376 DOCKER_TLS_VERIFY=1
  128. export DOCKER_HOST=tcp://$(docker info -f '{{.Name}}'):2376 DOCKER_TLS_VERIFY=1
  129. if [ -z $(docker service ps -q ${DOCKER_IMAGE}) ];then
  130. docker service create --replicas 1 \
  131. --mount type=bind,source=/var/run/docker.sock,destination=/var/run/docker.sock \
  132. --name ${SERVICE_NAME} ${DOCKER_REGISTRY}/${SERVICE_IMAGE}:2 -p 1194:1194 \
  133. --privileged --security-opt seccomp=unconfined \
  134. --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro \
  135. -e "mode=server" ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}
  136. else
  137. docker service update \
  138. --args "-p 1194:1194 --privileged --security-opt seccomp=unconfined \
  139. --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro \
  140. -e "mode=server" ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}" \
  141. ${SERVICE_NAME}
  142. if [ $? != 0 ]; then docker service rollback ${SERVICE_NAME}; fi
  143. fi
  144. '''
  145. }
  146. }
  147. stage("Tagging") {
  148. steps {
  149. echo "Tagging ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} to ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:latest"
  150. sh '''docker tag ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} \
  151. ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:latest
  152. docker push ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:latest
  153. '''
  154. echo "Updating tag info in ${SWARM_GIT_NAME} repository"
  155. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  156. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  157. git clone ${SWARM_GIT_URL}
  158. cd ${SWARM_GIT_NAME}
  159. echo -n ${BUILD_NUMBER} > tags/${DOCKER_IMAGE}.version
  160. git add -A
  161. git config --global user.email "${JENKINS_MAIL}"
  162. git config --global user.name "Jenkins"
  163. git commit -m 'Version update'
  164. GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  165. git push origin master
  166. '''
  167. }
  168. }
  169. }
  170. */ }
  171. post {
  172. always {
  173. echo "CleaningUp work directory"
  174. deleteDir()
  175. }
  176. failure {
  177. mail charset: 'UTF-8',
  178. subject: "Jenkins build ERROR",
  179. mimeType: 'text/html',
  180. to: "${mailto}",
  181. body: "<b>ATTENTION!!!</b> <b><br> Jenkins job failed.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  182. }
  183. success {
  184. mail charset: 'UTF-8',
  185. subject: "Jenkins build SUSCCESS",
  186. mimeType: 'text/html',
  187. to: "${mailto}",
  188. body: "<b>Congradulations!!!</b> <b><br> Jenkins job succefully finished.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  189. }
  190. }
  191. }