-
Notifications
You must be signed in to change notification settings - Fork 7
Expand file tree
/
Copy pathwerf.yaml
More file actions
250 lines (237 loc) · 7.21 KB
/
Copy pathwerf.yaml
File metadata and controls
250 lines (237 loc) · 7.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
project: virtualization
configVersion: 1
build:
imageSpec:
author: "Deckhouse <contact@deckhouse.io>"
clearHistory: true
config:
keepEssentialWerfLabels: true
removeLabels:
- /.*/
---
# Base Images: merged into $.Images, no output of its own.
{{- $_ := include "parse_base_images_map" . }}
# Base image for VEX attestations (cosign attest --type openvex).
# Consumed by the "vex mitigation" template in .werf/defines/vex.tmpl.
image: base/vex
from: {{ index $.Images "tools/coreutils" }}
final: false
import:
- from: {{ index $.Images "builder/alpine" }}
add: /etc/ssl/certs/ca-certificates.crt
to: /etc/ssl/certs/ca-certificates.crt
before: install
- from: {{ index $.Images "tools/cosign" }}
add: /usr/bin/cosign
to: /usr/bin/cosign
before: install
- from: {{ index $.Images "tools/jq" }}
add: /usr/bin/jq
to: /usr/bin/jq
before: install
- from: {{ index $.Images "tools/curl" }}
add: /usr/bin/curl-static
to: /usr/bin/curl
before: install
- from: {{ index $.Images "tools/bash" }}
add: /usr/bin/bash
to: /bin/bash
before: install
---
# Source repo settings
{{- $_ := set . "SOURCE_REPO" (env "SOURCE_REPO" "https://github.com") }}
# Token for cloning/fetching private forks on fox.flant.com (e.g. kubevirt mirror).
{{- $_ := set . "CI_JOB_TOKEN" (env "CI_JOB_TOKEN" "") }}
{{- $_ := set . "DECKHOUSE_PRIVATE_REPO" (env "DECKHOUSE_PRIVATE_REPO" "example.com") }}
# Go module proxy for the images defined in this file; images/*/werf.inc.yaml get
# their own copy from .werf/images.yaml.
{{- $_ := set . "GOPROXY" (env "GOPROXY" "https://proxy.golang.org,direct") }}
# Define packages proxy settings
{{- $_ := set . "DistroPackagesProxy" (env "DISTRO_PACKAGES_PROXY" "") }}
# Delve debag
{{- $_ := set . "DEBUG_COMPONENT" (env "DEBUG_COMPONENT" "") }}
# svace analyze toggler
{{- $_ := set . "SVACE_ENABLED" (env "SVACE_ENABLED" "false") }}
{{- $_ := set . "SVACE_ANALYZE_HOST" (env "SVACE_ANALYZE_HOST" "example.host") }}
{{- $_ := set . "SVACE_ANALYZE_SSH_USER" (env "SVACE_ANALYZE_SSH_USER" "user") }}
{{- $_ := set . "ImagesIDList" list }}
{{- range $path, $content := .Files.Glob ".werf/*.yaml" }}
{{- tpl $content $ }}
{{- end }}
---
image: images-digests
from: {{ index $.Images "builder/alpine" }}
dependencies:
{{- range $ImageID := $.ImagesIDList }}
{{- $ImageName := $ImageID | splitList "/" | last }}
{{- $ImageNameCamel := $ImageID | splitList "/" | last | camelcase | untitle }}
{{- if eq $ImageName (trimSuffix "-vex-artifact" $ImageName) }}
- image: {{ $ImageID }}
before: setup
imports:
- type: ImageDigest
targetEnv: MODULE_IMAGE_DIGEST_{{ $ImageNameCamel }}
{{- end }}
{{- end }}
import:
- from: {{ index $.Images "tools/jq" }}
add: /usr/bin/jq
to: /usr/bin/jq
before: setup
shell:
setup:
- |
env | grep MODULE_IMAGE_DIGEST | jq -Rn '
reduce inputs as $i (
{};
. * (
$i | ltrimstr("MODULE_IMAGE_DIGEST_") | sub("=";"_") |
split("_") as [$imageName, $digest] |
{($imageName): $digest}
)
)
' > /images_digests.json
cat images_digests.json
{{- if .DEBUG_COMPONENT }}
- |
cat <<EOF>> /delve.yaml
debug:
component: "{{ .DEBUG_COMPONENT }}"
EOF
{{- end }}
---
# Renders the release notes: CHANGELOG/release-notes.yaml holds the notes of every
# version in both languages, and this image turns them into the files that are
# published — the two documentation pages and the changelog the Console reads. They
# are generated here, during the build, so no generated file is kept in the
# repository and nothing has to be regenerated by hand.
#
# builder/golang-debian-1.25 is what most Go images of the module build with;
# builder/golang-alpine would not do — it carries Go 1.25.10 with GOTOOLCHAIN=local
# and cannot build a module that asks for 1.25.12. GOWORK=off keeps the build off
# the workspace: the tool needs yaml.v3 and nothing else, so there is no reason to
# load every module and authenticate for the private kubevirt fork.
image: release-notes-artifact
from: {{ index $.Images "builder/golang-debian-1.25" }}
final: false
git:
- add: /tools/releasenotes
to: /src/tools/releasenotes
stageDependencies:
install:
- '**/*'
# The per-release changelogs ride along so the render's vulnerability
# cross-check has something to compare the notes with.
- add: /CHANGELOG
to: /src/CHANGELOG
includePaths:
- release-notes.yaml
- CHANGELOG-*.yml
stageDependencies:
setup:
- release-notes.yaml
- CHANGELOG-*.yml
mount:
{{- include "mount points for golang builds" . }}
secrets:
- id: GOPROXY
value: {{ .GOPROXY }}
shell:
install:
- export GOPROXY=$(cat /run/secrets/GOPROXY)
- export GOWORK=off CGO_ENABLED=0
- cd /src/tools/releasenotes
- go build -ldflags="-s -w" -o /usr/bin/release-notes .
setup:
- cd /src
{{- $tag := env "MODULES_MODULE_TAG" "" }}
{{- if regexMatch `^v[0-9]+\.[0-9]+\.[0-9]+$` $tag }}
# A release image publishes the changelog of its own version, so the notes of
# the tagged release have to be the newest in the source before the tag is cut.
- release-notes --type render --out /out --version {{ $tag }}
{{- else }}
- release-notes --type render --out /out
{{- end }}
---
image: bundle
from: {{ index $.Images "builder/scratch" }}
import:
- image: prepare-bundle
add: /prep-bundle
to: /
after: setup
---
image: prepare-bundle
from: {{ index $.Images "builder/alpine" }}
import:
- image: images-digests
add: /
to: /prep-bundle
after: setup
includePaths:
- images_digests.json
{{- if .DEBUG_COMPONENT }}
- delve.yaml
{{- end }}
- image: go-hooks-artifact
add: /go-hooks
to: /prep-bundle/hooks/go
after: setup
# Rendered release notes: the documentation pages and the changelog for the
# Console. Generated during the build, see release-notes-artifact.
- image: release-notes-artifact
add: /out
to: /prep-bundle
after: setup
includePaths:
- docs/RELEASE_NOTES.md
- docs/RELEASE_NOTES.ru.md
- changelog.yaml
git:
- add: /
to: /prep-bundle
stageDependencies:
install:
- '**/*'
includePaths:
- charts
- crds
- build/components
- docs
- openapi
- monitoring
- templates
- Chart.yaml
- module.yaml
- .helmignore
excludePaths:
- build/components/README.md
- docs/images/*.drawio
- docs/images/*.sh
- docs/internal
- openapi/openapi-case-tests.yaml
{{- if eq .MODULE_EDITION "CE" }}
- templates/virtualization-audit
- templates/virtualization-dra
{{- end }}
shell:
install:
- ls -la /prep-bundle
---
image: release-channel-version
from: {{ index $.Images "builder/scratch" }}
import:
- image: prepare-bundle
add: /prep-bundle
to: /
after: install
includePaths:
- module.yaml
- changelog.yaml
shell:
install:
- echo '{"version":"{{ env "MODULES_MODULE_TAG" "dev" }}"}' > version.json
# VEX attestation for the module (bundle) image. Covers GO-2026-5932
# (golang.org/x/crypto/openpgp) carried by the hooks/go/virtualization-module-hooks
# binary. Predicate lives in the repo-root known_vulnerabilities.vex.
{{- include "vex mitigation" (list . "bundle") }}