apiVersion: tekton.dev/v1 kind: PipelineRun metadata: name: build-homepage-staging spec: timeouts: pipeline: "2h0m0s" tasks: "1h0m0s" finally: "0h30m0s" taskRunTemplate: serviceAccountName: build-bot pipelineSpec: params: - name: image-name description: The name for the built image type: string - name: target-name description: The dockerfile target to build type: string - name: path-to-image-context description: The path to the build context type: string - name: path-to-dockerfile description: The path to the Dockerfile type: string tasks: - name: get-time taskSpec: metadata: {} stepTemplate: image: alpine:3.20 computeResources: requests: cpu: 10m memory: 600Mi workingDir: "/" results: - name: unix-time description: The current date in unix timestamp format. steps: - image: alpine:3.20 name: get-time-step script: | #!/usr/bin/env sh set -euo pipefail echo -n "$(date +%s)" | tee $(results.unix-time.path) - name: get-git-commit-time taskSpec: metadata: {} stepTemplate: image: alpine:3.20 computeResources: requests: cpu: 10m memory: 600Mi workingDir: "$(workspaces.repo.path)" results: - name: unix-time description: The time of the git commit in unix timestamp format. steps: - image: alpine/git:v2.34.2 name: detect-tag-step script: | #!/usr/bin/env sh set -euo pipefail echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path) workspaces: - name: repo workspace: git-source runAfter: - fetch-repository - name: report-pending taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/gitea-set-status/0.1/gitea-set-status.yaml runAfter: - fetch-repository - fetch-repository-private - fetch-repository-explorer - fetch-repository-organic params: - name: CONTEXT value: "$(params.JOB_NAME)" - name: REPO_FULL_NAME value: "$(params.REPO_OWNER)/$(params.REPO_NAME)" - name: GITEA_HOST_URL value: code.fizz.buzz - name: SHA value: "$(tasks.fetch-repository.results.commit)" - name: DESCRIPTION value: "Build $(params.JOB_NAME) has started" - name: STATE value: pending - name: TARGET_URL value: "https://tekton.fizz.buzz/#/namespaces/$(context.pipelineRun.namespace)/pipelineruns/$(context.pipelineRun.name)" - name: fetch-repository taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/git-clone/0.9/git-clone.yaml workspaces: - name: output workspace: git-source params: - name: url value: $(params.REPO_URL) - name: revision value: $(params.PULL_BASE_SHA) - name: deleteExisting value: "true" - name: fetch-repository-private taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/git-clone/0.9/git-clone.yaml workspaces: - name: output workspace: git-source-private params: - name: url value: git@code.fizz.buzz:talexander/homepage_private.git - name: revision value: main - name: deleteExisting value: "true" - name: fetch-repository-explorer taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/git-clone/0.9/git-clone.yaml workspaces: - name: output workspace: git-source-explorer params: - name: url value: git@code.fizz.buzz:talexander/organic_ast_explorer.git - name: revision value: main - name: deleteExisting value: "true" - name: fetch-repository-organic taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/git-clone/0.9/git-clone.yaml workspaces: - name: output workspace: git-source-organic params: - name: url value: git@code.fizz.buzz:talexander/organic.git - name: revision value: main - name: deleteExisting value: "true" - name: copy-private-files taskSpec: metadata: {} stepTemplate: image: alpine:3.20 computeResources: requests: cpu: 10m memory: 600Mi workingDir: "$(workspaces.source.path)" steps: - image: alpine:3.20 name: copy-private-files script: | #!/usr/bin/env sh set -euo pipefail cp -r "$(workspaces.source-private.path)/static/"* "$(workspaces.source.path)/static/" workspaces: - name: source workspace: git-source - name: source-private workspace: git-source-private runAfter: - fetch-repository - fetch-repository-private - name: build-explorer-image taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision value: 8e4e323389e66d8365a3243f8e956136e916132e - name: pathInRepo value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: - name: OUTPUT value: >- type=image,"name=harbor.fizz.buzz/private/homepage-build-organic:latest,harbor.fizz.buzz/private/homepage-build-organic:$(tasks.get-time.results.unix-time)",push=true,compression=zstd,compression-level=22,oci-mediatypes=true - name: CONTEXT value: . - name: DOCKERFILE value: docker/organic/ - name: EXTRA_ARGS value: - --import-cache - "type=registry,ref=harbor.fizz.buzz/private/homepage-build-organic:buildcache" - --export-cache - "type=registry,ref=harbor.fizz.buzz/private/homepage-build-organic:buildcache,mode=max,compression=zstd,compression-level=3,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" - --opt - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) - name: BUILDKITD_TOML value: | debug = true [registry."docker.io"] mirrors = ["dockerhub.dockerhub.svc.cluster.local"] [registry."dockerhub.dockerhub.svc.cluster.local"] http = true insecure = true workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials runAfter: - fetch-repository - name: build-explorer-wasm taskSpec: metadata: {} stepTemplate: image: alpine:3.20 computeResources: requests: cpu: 10m memory: 600Mi workingDir: "$(workspaces.organic.path)" steps: - image: "$(params.IMAGE)" name: build-explorer-wasm params: - name: IMAGE value: "$(tasks.build-explorer-image.results.IMAGE_URL[1])" workspaces: - name: organic workspace: git-source-organic runAfter: - build-explorer-image - name: copy-explorer-files taskSpec: metadata: {} stepTemplate: image: alpine:3.20 computeResources: requests: cpu: 10m memory: 600Mi workingDir: "$(workspaces.source-explorer.path)" steps: - image: node:lts-alpine3.20 name: copy-explorer-files script: | #!/usr/bin/env sh set -euo pipefail npm install npm run release mkdir -p "$(workspaces.source.path)/static/organic/ast_explorer/" cp -r "$(workspaces.source-explorer.path)/dist/"* "$(workspaces.source.path)/static/organic/ast_explorer/" workspaces: - name: source workspace: git-source - name: source-explorer workspace: git-source-explorer - name: organic workspace: git-source-organic runAfter: - build-explorer-wasm - name: build-image taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/kaniko/0.6/kaniko.yaml params: - name: IMAGE value: "$(params.image-name):$(tasks.get-time.results.unix-time)" - name: CONTEXT value: $(params.path-to-image-context) - name: DOCKERFILE value: $(params.path-to-dockerfile) - name: BUILDER_IMAGE value: "gcr.io/kaniko-project/executor:v1.23.2" - name: EXTRA_ARGS value: - "--destination=$(params.image-name)" # Also write the :latest image - "--target=$(params.target-name)" - --cache=true - --cache-copy-layers - --cache-repo=harbor.fizz.buzz/kanikocache/cache - --use-new-run # Should result in a speed-up - --reproducible # To remove timestamps so layer caching works. - --snapshot-mode=redo - --skip-unused-stages=true - --registry-mirror=dockerhub.dockerhub.svc.cluster.local workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials runAfter: - copy-private-files - copy-explorer-files finally: - name: report-success when: - input: "$(tasks.status)" operator: in values: ["Succeeded", "Completed"] taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/gitea-set-status/0.1/gitea-set-status.yaml params: - name: CONTEXT value: "$(params.JOB_NAME)" - name: REPO_FULL_NAME value: "$(params.REPO_OWNER)/$(params.REPO_NAME)" - name: GITEA_HOST_URL value: code.fizz.buzz - name: SHA value: "$(tasks.fetch-repository.results.commit)" - name: DESCRIPTION value: "Build $(params.JOB_NAME) has succeeded" - name: STATE value: success - name: TARGET_URL value: "https://tekton.fizz.buzz/#/namespaces/$(context.pipelineRun.namespace)/pipelineruns/$(context.pipelineRun.name)" - name: report-failure when: - input: "$(tasks.status)" operator: in values: ["Failed"] taskRef: resolver: git params: - name: url value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git - name: revision value: df36b3853a5657fd883015cdbf07ad6466918acf - name: pathInRepo value: task/gitea-set-status/0.1/gitea-set-status.yaml params: - name: CONTEXT value: "$(params.JOB_NAME)" - name: REPO_FULL_NAME value: "$(params.REPO_OWNER)/$(params.REPO_NAME)" - name: GITEA_HOST_URL value: code.fizz.buzz - name: SHA value: "$(tasks.fetch-repository.results.commit)" - name: DESCRIPTION value: "Build $(params.JOB_NAME) has failed" - name: STATE value: failure - name: TARGET_URL value: "https://tekton.fizz.buzz/#/namespaces/$(context.pipelineRun.namespace)/pipelineruns/$(context.pipelineRun.name)" workspaces: - name: git-source - name: docker-credentials workspaces: - name: git-source volumeClaimTemplate: spec: storageClassName: "nfs-client" accessModes: - ReadWriteOnce resources: requests: storage: 10Gi subPath: rust-source - name: git-source-private volumeClaimTemplate: spec: storageClassName: "nfs-client" accessModes: - ReadWriteOnce resources: requests: storage: 10Gi subPath: git-source - name: git-source-explorer volumeClaimTemplate: spec: storageClassName: "nfs-client" accessModes: - ReadWriteOnce resources: requests: storage: 10Gi subPath: git-source - name: git-source-organic volumeClaimTemplate: spec: storageClassName: "nfs-client" accessModes: - ReadWriteOnce resources: requests: storage: 10Gi subPath: git-source - name: docker-credentials secret: secretName: harbor-plain params: - name: image-name value: "harbor.fizz.buzz/private/homepage-staging" - name: target-name value: "" - name: path-to-image-context value: . - name: path-to-dockerfile value: docker/server/Dockerfile