Jenkinsfile 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160
  1. pipeline {
  2. agent {
  3. label "swarm"
  4. }
  5. environment {
  6. DOCKER_REGISTRY='dev-registry.infoclinica.ru:5000'
  7. DOCKER_IMAGE='ovpn'
  8. SERVICE_IMAGE='container_run'
  9. SERVICE_NAME='ovpn'
  10. SWARM_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/stack-deploy.git'
  11. SWARM_GIT_NAME='stack-deploy'
  12. PKI_GIT_URL='ssh://git@git.sdsys.ru:8022/iru/openvpn-pki.git'
  13. PKI_GIT_NAME='openvpn-pki'
  14. GOST_GIT_DIR='openvpn'
  15. JENKINS_MAIL='jenkins@sdsys.ru'
  16. CLUSTER_NAME='dev-iru-swarm.infoclinica.lan'
  17. }
  18. parameters {
  19. string(
  20. name: "mailto",
  21. defaultValue: "tomishinets.v@sdsys.ru",
  22. description: "Email which has to be notified."
  23. )
  24. }
  25. stages {
  26. stage("Pull PKI repo") {
  27. steps {
  28. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  29. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  30. git clone ${PKI_GIT_URL}
  31. '''
  32. }
  33. sh '''cp ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/ca.crt \
  34. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/server.crt \
  35. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/server.key \
  36. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/sds-test.crt \
  37. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/sds-test.key \
  38. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/ta.key \
  39. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/stonevpn.crl \
  40. ${WORKSPACE}/openvpn-pki/open/easy-rsa/keys/dh2048.pem \
  41. ${WORKSPACE}/openvpn/keys
  42. ls -al ${WORKSPACE}/openvpn/keys/
  43. '''
  44. }
  45. }
  46. stage("Build") {
  47. steps {
  48. echo "Building ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}."
  49. sh "docker build --no-cache -t ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} ."
  50. }
  51. }
  52. stage("Staging") {
  53. steps {
  54. echo "Run ${DOCKER_IMAGE} in server mode."
  55. sh '''container_id_server=`docker run -d --rm -e "mode=server" \
  56. --privileged ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}`
  57. container_ip_server=`docker inspect ${container_id_server} --format='{{.NetworkSettings.IPAddress}}'`
  58. container_id_client=`docker run -d --rm -e "mode=client" -e "server=${container_ip_server}" --privileged ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}`
  59. sleep 15
  60. docker exec ${container_id_client} ping -c 3 -q 10.10.20.1
  61. if [ $? != 0 ]
  62. then
  63. echo "Can not connect to VPN server !!!"
  64. docker stop ${container_id_server} ${container_id_client}
  65. exit 1
  66. else
  67. echo "VPN server is started"
  68. docker stop ${container_id_server} ${container_id_client}
  69. fi
  70. '''
  71. }
  72. }
  73. stage("Publish") {
  74. steps {
  75. echo "Publishing ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}."
  76. sh "docker push ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}"
  77. }
  78. }
  79. stage("Prod-like") {
  80. steps {
  81. echo "Check Prod-like cluster status"
  82. sh '''ping -c 2 ${CLUSTER_NAME}
  83. if [ $? -eq 0 ]; then
  84. export DOCKER_CERT_PATH=/run/secrets/swarm
  85. export DOCKER_HOST=tcp://${CLUSTER_NAME}:2376 DOCKER_TLS_VERIFY=1
  86. docker node ls --format "{{.Hostname}} {{.TLSStatus}}" | while read host status
  87. do
  88. if [ $status != Ready ]; then echo "Cluster ${CLUSTER_NAME} state is inconsistent"; exit 1
  89. else echo "HOST: $host STATUS: $status"
  90. fi
  91. done
  92. else echo "Host not Found"; exit 1
  93. fi
  94. '''
  95. echo "Run containers in Prod-like"
  96. sh '''export DOCKER_CERT_PATH=/run/secrets/swarm
  97. export DOCKER_HOST=tcp://dev-iru-swarm1.infoclinica.lan:2376 DOCKER_TLS_VERIFY=1
  98. if [ !$(docker service ps -q ${DOCKER_IMAGE}) ];then
  99. docker service create --replicas 2 \
  100. --mount type=bind,source=/var/run/docker.sock,destination=/var/run/docker.sock \
  101. --name ${SERVICE_NAME} ${DOCKER_REGISTRY}/${SERVICE_IMAGE}:1 -p 1194:1194 \
  102. --privileged --security-opt seccomp=unconfined \
  103. --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro \
  104. -e "mode=server" ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}
  105. else
  106. docker service update \
  107. --args "-p 1194:1194 --privileged --security-opt seccomp=unconfined \
  108. --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro \
  109. -e "mode=server" ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER}" \
  110. ${SERVICE_NAME}
  111. if [ $? != 0 ]; then docker service rollback ${SERVICE_NAME}; fi
  112. fi
  113. '''
  114. }
  115. }
  116. stage("Tagging") {
  117. steps {
  118. echo "Tagging ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} to ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:latest"
  119. sh '''docker tag ${DOCKER_REGISTRY}/${DOCKER_IMAGE}:${BUILD_NUMBER} \
  120. ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:latest
  121. docker push ${DOCKER_REGISTRY}/iru/${DOCKER_IMAGE}:latest
  122. '''
  123. echo "Updating tag info in ${SWARM_GIT_NAME} repository"
  124. withCredentials([sshUserPrivateKey(credentialsId: 'provision', keyFileVariable: 'GIT_SSH_KEY', passphraseVariable: '', usernameVariable: 'GIT_SSH_USERNAME')]) {
  125. sh '''GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  126. git clone ${SWARM_GIT_URL}
  127. cd ${SWARM_GIT_NAME}
  128. echo -n ${BUILD_NUMBER} > tags/${DOCKER_IMAGE}.version
  129. git add -A
  130. git config --global user.email "${JENKINS_MAIL}"
  131. git config --global user.name "Jenkins"
  132. git commit -m 'Version update'
  133. GIT_SSH_COMMAND='ssh -i ${GIT_SSH_KEY} -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' \
  134. git push origin master
  135. '''
  136. }
  137. }
  138. }
  139. }
  140. post {
  141. always {
  142. echo "CleaningUp work directory"
  143. deleteDir()
  144. }
  145. failure {
  146. mail charset: 'UTF-8',
  147. subject: "Jenkins build ERROR",
  148. mimeType: 'text/html',
  149. to: "${mailto}",
  150. body: "<b>ATTENTION!!!</b> <b><br> Jenkins job failed.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  151. }
  152. success {
  153. mail charset: 'UTF-8',
  154. subject: "Jenkins build SUSCCESS",
  155. mimeType: 'text/html',
  156. to: "${mailto}",
  157. body: "<b>Congradulations!!!</b> <b><br> Jenkins job succefully finished.\n\n <b><br>Project Name:</b> ${env.JOB_NAME} <b><br>\nBuild Number:</b> ${env.BUILD_NUMBER} <b><br>\nURL Build:</b> ${RUN_DISPLAY_URL}"
  158. }
  159. }
  160. }