This downstream-only directory implements the NetApp ONTAP presubmit for
CloudStack. Do not include it in pull requests to apache/cloudstack.
For setup, operation, testing, security boundaries, troubleshooting, and the
current implementation contract, see
docs/PRIVATE-CICD-GUIDE.md.
The production Jenkins job loads Jenkinsfile and helper scripts
from the protected NetApp main branch. Every five minutes a short discovery
build polls GitHub and self-queues a worker for each unseen PR head SHA. Each
worker checks out the exact commit into a separate cloudstack-src directory,
then:
- validates the request, builder, credentials, and VM inventory;
- runs the full Maven build and unit tests;
- builds and verifies CloudStack Debian packages;
- locks and reverts a compatible lab VM;
- installs and configures CloudStack, MySQL, KVM, NFS, and iSCSI;
- creates the test zone and runs the ONTAP iSCSI and NFS3 suites;
- redacts and archives results, publishes a GitHub Check, and sends mail.
Eligible pull-request revisions receive the required Check
cloudstack-ontap-presubmit. GitHub API and SMTP failures are reported without
replacing the underlying build or test result.
- Pull request:
SOURCE_MODE=discovernotices an open non-draft PR update tomainand self-queues at most fiveSOURCE_MODE=pull_requestworkers in the same job. Extra SHAs wait for a later poll. Workers then wait on thecloudstack-presubmit-vmlock for a lab VM. - Manual branch: a separate triggerless job uses
SOURCE_MODE=branchwith a remote branch and exact 40-character commit SHA. - Local validation:
scripts/validate-local.shchecks the CI files without building CloudStack. - Direct lab validation: the scripts can be run gate by gate on a disposable Ubuntu 22.04 nested-KVM VM.
Different sources may run concurrently. A newer run aborts an older run only for the same pull-request ID or manual source branch, and only before the older run acquires its integration-test VM.
config/vm-inventory.yaml.example is the
only tracked inventory file. Create populated inventory outside Git and upload
it to Jenkins as a Secret file. Keep passwords, tokens, and private keys in
dedicated Jenkins credentials; generated runtime configuration is not archived.
The Kubernetes pod uses a jnlp agent container and a separate
cloudstack-driver build container. The immutable driver image reference,
resource requests, build commands, credential mapping, and snapshot contract
are documented in the comprehensive guide.
./private-cicd/scripts/validate-local.sh
# Also build the driver image
./private-cicd/scripts/validate-local.sh --with-dockerLocal validation checks shell syntax, compiles Python, and parses YAML when a supported parser is available. The Docker option builds the driver image. These commands do not run Maven, create Debian packages, deploy CloudStack, or run ONTAP tests.
- ONTAP plugin:
../plugins/storage/volume/ontap/ - ONTAP integration tests:
../test/integration/plugins/ontap/