Visitar URL original
cloudstack/private-cicd at main · NetApp/cloudstack · GitHub
Skip to content

Latest commit

 

History

History
 
 

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 

README.md

Private CloudStack CI/CD

This downstream-only directory implements the NetApp ONTAP presubmit for CloudStack. Do not include it in pull requests to apache/cloudstack.

For setup, operation, testing, security boundaries, troubleshooting, and the current implementation contract, see docs/PRIVATE-CICD-GUIDE.md.

How it works

The production Jenkins job loads Jenkinsfile and helper scripts from the protected NetApp main branch. Every five minutes a short discovery build polls GitHub and self-queues a worker for each unseen PR head SHA. Each worker checks out the exact commit into a separate cloudstack-src directory, then:

  1. validates the request, builder, credentials, and VM inventory;
  2. runs the full Maven build and unit tests;
  3. builds and verifies CloudStack Debian packages;
  4. locks and reverts a compatible lab VM;
  5. installs and configures CloudStack, MySQL, KVM, NFS, and iSCSI;
  6. creates the test zone and runs the ONTAP iSCSI and NFS3 suites;
  7. redacts and archives results, publishes a GitHub Check, and sends mail.

Eligible pull-request revisions receive the required Check cloudstack-ontap-presubmit. GitHub API and SMTP failures are reported without replacing the underlying build or test result.

Entry points

  • Pull request: SOURCE_MODE=discover notices an open non-draft PR update to main and self-queues at most five SOURCE_MODE=pull_request workers in the same job. Extra SHAs wait for a later poll. Workers then wait on the cloudstack-presubmit-vm lock for a lab VM.
  • Manual branch: a separate triggerless job uses SOURCE_MODE=branch with a remote branch and exact 40-character commit SHA.
  • Local validation: scripts/validate-local.sh checks the CI files without building CloudStack.
  • Direct lab validation: the scripts can be run gate by gate on a disposable Ubuntu 22.04 nested-KVM VM.

Different sources may run concurrently. A newer run aborts an older run only for the same pull-request ID or manual source branch, and only before the older run acquires its integration-test VM.

Configuration and secrets

config/vm-inventory.yaml.example is the only tracked inventory file. Create populated inventory outside Git and upload it to Jenkins as a Secret file. Keep passwords, tokens, and private keys in dedicated Jenkins credentials; generated runtime configuration is not archived.

The Kubernetes pod uses a jnlp agent container and a separate cloudstack-driver build container. The immutable driver image reference, resource requests, build commands, credential mapping, and snapshot contract are documented in the comprehensive guide.

Local validation

./private-cicd/scripts/validate-local.sh

# Also build the driver image
./private-cicd/scripts/validate-local.sh --with-docker

Local validation checks shell syntax, compiles Python, and parses YAML when a supported parser is available. The Docker option builds the driver image. These commands do not run Maven, create Debian packages, deploy CloudStack, or run ONTAP tests.

Related code