From d80b473faea1c65024ae96454bca313f57fa706e Mon Sep 17 00:00:00 2001 From: Tom Alexander Date: Sun, 20 Oct 2024 22:55:22 -0400 Subject: [PATCH] Switch to using BuiltKit instead of Kaniko to build docker images. --- .webhook_bridge/pipeline-build-hash.yaml | 86 +++++++++++++------ .../pipeline-foreign-document-test.yaml | 69 +++++++++++---- .webhook_bridge/pipeline-format.yaml | 69 +++++++++++---- .webhook_bridge/pipeline-rust-clippy.yaml | 69 +++++++++++---- .webhook_bridge/pipeline-rust-test.yaml | 69 +++++++++++---- 5 files changed, 258 insertions(+), 104 deletions(-) diff --git a/.webhook_bridge/pipeline-build-hash.yaml b/.webhook_bridge/pipeline-build-hash.yaml index 9ad4cd9..cb5fac7 100644 --- a/.webhook_bridge/pipeline-build-hash.yaml +++ b/.webhook_bridge/pipeline-build-hash.yaml @@ -69,42 +69,72 @@ spec: value: $(params.PULL_BASE_SHA) - name: deleteExisting value: "true" + - name: get-git-commit-time + taskSpec: + metadata: {} + stepTemplate: + image: alpine:3.20 + computeResources: + requests: + cpu: 10m + memory: 600Mi + workingDir: "$(workspaces.repo.path)" + results: + - name: unix-time + description: The time of the git commit in unix timestamp format. + steps: + - image: alpine/git:v2.34.2 + name: detect-tag-step + script: | + #!/usr/bin/env sh + set -euo pipefail + echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path) + workspaces: + - name: repo + workspace: git-source + runAfter: + - fetch-repository - name: build-image taskRef: resolver: git params: - name: url - value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git + value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision - value: df36b3853a5657fd883015cdbf07ad6466918acf + value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 - name: pathInRepo - value: task/kaniko/0.6/kaniko.yaml + value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: - - name: IMAGE - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + - name: OUTPUT + value: >- + type=image,"name=$(params.image-name):latest,$(params.image-name):$(tasks.fetch-repository.results.commit)",push=true,compression=zstd,compression-level=22,oci-mediatypes=true - name: CONTEXT value: $(params.path-to-image-context) - name: DOCKERFILE value: $(params.path-to-dockerfile) - - name: BUILDER_IMAGE - value: "gcr.io/kaniko-project/executor:v1.12.1" - name: EXTRA_ARGS value: - - "--destination=$(params.image-name)" # Also write the :latest image - - "--target=$(params.target-name)" - - --cache=true - - --cache-copy-layers - - --cache-repo=harbor.fizz.buzz/kanikocache/cache - - --use-new-run # Should result in a speed-up - - --reproducible # To remove timestamps so layer caching works. - - --snapshot-mode=redo - - --skip-unused-stages=true - - --registry-mirror=dockerhub.dockerhub.svc.cluster.local + - --import-cache + - "type=registry,ref=$(params.image-name):buildcache" + - --export-cache + - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" + - --opt + - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) + - name: BUILDKITD_TOML + value: | + debug = true + [registry."docker.io"] + mirrors = ["dockerhub.dockerhub.svc.cluster.local"] + [registry."dockerhub.dockerhub.svc.cluster.local"] + http = true + insecure = true workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials + runAfter: + - fetch-repository ############# - name: run-image-none taskSpec: @@ -147,7 +177,7 @@ spec: - build-image params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-tracing taskSpec: @@ -190,7 +220,7 @@ spec: - run-image-none params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-compare taskSpec: @@ -233,7 +263,7 @@ spec: - run-image-tracing params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-default taskSpec: @@ -276,7 +306,7 @@ spec: - run-image-compare params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-tracing-compare taskSpec: @@ -319,7 +349,7 @@ spec: - run-image-default params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-compare-foreign taskSpec: @@ -367,7 +397,7 @@ spec: - run-image-tracing-compare params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-all taskSpec: @@ -415,7 +445,7 @@ spec: - run-image-compare-foreign params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-wasm taskSpec: @@ -469,7 +499,7 @@ spec: - run-image-all params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# - name: run-image-wasm-test taskSpec: @@ -519,7 +549,7 @@ spec: - run-image-wasm params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" ############# finally: - name: report-success @@ -621,7 +651,7 @@ spec: subPath: $(params.cache-subdir) params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" - name: cache-subdir value: none # matrix: @@ -666,4 +696,4 @@ spec: - name: path-to-image-context value: . - name: path-to-dockerfile - value: docker/organic_development/Dockerfile + value: docker/organic_development/ diff --git a/.webhook_bridge/pipeline-foreign-document-test.yaml b/.webhook_bridge/pipeline-foreign-document-test.yaml index d1af109..e491809 100644 --- a/.webhook_bridge/pipeline-foreign-document-test.yaml +++ b/.webhook_bridge/pipeline-foreign-document-test.yaml @@ -69,41 +69,72 @@ spec: value: $(params.PULL_BASE_SHA) - name: deleteExisting value: "true" + - name: get-git-commit-time + taskSpec: + metadata: {} + stepTemplate: + image: alpine:3.20 + computeResources: + requests: + cpu: 10m + memory: 600Mi + workingDir: "$(workspaces.repo.path)" + results: + - name: unix-time + description: The time of the git commit in unix timestamp format. + steps: + - image: alpine/git:v2.34.2 + name: detect-tag-step + script: | + #!/usr/bin/env sh + set -euo pipefail + echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path) + workspaces: + - name: repo + workspace: git-source + runAfter: + - fetch-repository - name: build-image taskRef: resolver: git params: - name: url - value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git + value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision - value: df36b3853a5657fd883015cdbf07ad6466918acf + value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 - name: pathInRepo - value: task/kaniko/0.6/kaniko.yaml + value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: - - name: IMAGE - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + - name: OUTPUT + value: >- + type=image,"name=$(params.image-name):latest,$(params.image-name):$(tasks.fetch-repository.results.commit)",push=true,compression=zstd,compression-level=22,oci-mediatypes=true - name: CONTEXT value: $(params.path-to-image-context) - name: DOCKERFILE value: $(params.path-to-dockerfile) - - name: BUILDER_IMAGE - value: "gcr.io/kaniko-project/executor:v1.12.1" - name: EXTRA_ARGS value: - - "--target=$(params.target-name)" - - --cache=true - - --cache-copy-layers - - --cache-repo=harbor.fizz.buzz/kanikocache/cache - - --use-new-run # Should result in a speed-up - - --reproducible # To remove timestamps so layer caching works. - - --snapshot-mode=redo - - --skip-unused-stages=true - - --registry-mirror=dockerhub.dockerhub.svc.cluster.local + - --import-cache + - "type=registry,ref=$(params.image-name):buildcache" + - --export-cache + - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" + - --opt + - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) + - name: BUILDKITD_TOML + value: | + debug = true + [registry."docker.io"] + mirrors = ["dockerhub.dockerhub.svc.cluster.local"] + [registry."dockerhub.dockerhub.svc.cluster.local"] + http = true + insecure = true workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials + runAfter: + - fetch-repository - name: run-test taskSpec: metadata: {} @@ -141,7 +172,7 @@ spec: - build-image params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" finally: - name: report-success when: @@ -235,7 +266,7 @@ spec: workspace: cargo-cache params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" workspaces: - name: git-source - name: docker-credentials @@ -265,4 +296,4 @@ spec: - name: path-to-image-context value: docker/organic_test/ - name: path-to-dockerfile - value: docker/organic_test/Dockerfile + value: docker/organic_test/ diff --git a/.webhook_bridge/pipeline-format.yaml b/.webhook_bridge/pipeline-format.yaml index 05df7d0..75f8e7b 100644 --- a/.webhook_bridge/pipeline-format.yaml +++ b/.webhook_bridge/pipeline-format.yaml @@ -69,41 +69,72 @@ spec: value: $(params.PULL_BASE_SHA) - name: deleteExisting value: "true" + - name: get-git-commit-time + taskSpec: + metadata: {} + stepTemplate: + image: alpine:3.20 + computeResources: + requests: + cpu: 10m + memory: 600Mi + workingDir: "$(workspaces.repo.path)" + results: + - name: unix-time + description: The time of the git commit in unix timestamp format. + steps: + - image: alpine/git:v2.34.2 + name: detect-tag-step + script: | + #!/usr/bin/env sh + set -euo pipefail + echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path) + workspaces: + - name: repo + workspace: git-source + runAfter: + - fetch-repository - name: build-image taskRef: resolver: git params: - name: url - value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git + value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision - value: df36b3853a5657fd883015cdbf07ad6466918acf + value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 - name: pathInRepo - value: task/kaniko/0.6/kaniko.yaml + value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: - - name: IMAGE - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + - name: OUTPUT + value: >- + type=image,"name=$(params.image-name):latest,$(params.image-name):$(tasks.fetch-repository.results.commit)",push=true,compression=zstd,compression-level=22,oci-mediatypes=true - name: CONTEXT value: $(params.path-to-image-context) - name: DOCKERFILE value: $(params.path-to-dockerfile) - - name: BUILDER_IMAGE - value: "gcr.io/kaniko-project/executor:v1.12.1" - name: EXTRA_ARGS value: - - "--target=$(params.target-name)" - - --cache=true - - --cache-copy-layers - - --cache-repo=harbor.fizz.buzz/kanikocache/cache - - --use-new-run # Should result in a speed-up - - --reproducible # To remove timestamps so layer caching works. - - --snapshot-mode=redo - - --skip-unused-stages=true - - --registry-mirror=dockerhub.dockerhub.svc.cluster.local + - --import-cache + - "type=registry,ref=$(params.image-name):buildcache" + - --export-cache + - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" + - --opt + - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) + - name: BUILDKITD_TOML + value: | + debug = true + [registry."docker.io"] + mirrors = ["dockerhub.dockerhub.svc.cluster.local"] + [registry."dockerhub.dockerhub.svc.cluster.local"] + http = true + insecure = true workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials + runAfter: + - fetch-repository - name: run-cargo-fmt taskSpec: metadata: {} @@ -143,7 +174,7 @@ spec: - build-image params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" - name: commit-changes taskRef: resolver: git @@ -268,7 +299,7 @@ spec: workspace: cargo-cache params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" workspaces: - name: git-source - name: docker-credentials @@ -298,4 +329,4 @@ spec: - name: path-to-image-context value: docker/organic_development/ - name: path-to-dockerfile - value: docker/organic_development/Dockerfile + value: docker/organic_development/ diff --git a/.webhook_bridge/pipeline-rust-clippy.yaml b/.webhook_bridge/pipeline-rust-clippy.yaml index 209093c..031b192 100644 --- a/.webhook_bridge/pipeline-rust-clippy.yaml +++ b/.webhook_bridge/pipeline-rust-clippy.yaml @@ -69,41 +69,72 @@ spec: value: $(params.PULL_BASE_SHA) - name: deleteExisting value: "true" + - name: get-git-commit-time + taskSpec: + metadata: {} + stepTemplate: + image: alpine:3.20 + computeResources: + requests: + cpu: 10m + memory: 600Mi + workingDir: "$(workspaces.repo.path)" + results: + - name: unix-time + description: The time of the git commit in unix timestamp format. + steps: + - image: alpine/git:v2.34.2 + name: detect-tag-step + script: | + #!/usr/bin/env sh + set -euo pipefail + echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path) + workspaces: + - name: repo + workspace: git-source + runAfter: + - fetch-repository - name: build-image taskRef: resolver: git params: - name: url - value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git + value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision - value: df36b3853a5657fd883015cdbf07ad6466918acf + value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 - name: pathInRepo - value: task/kaniko/0.6/kaniko.yaml + value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: - - name: IMAGE - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + - name: OUTPUT + value: >- + type=image,"name=$(params.image-name):latest,$(params.image-name):$(tasks.fetch-repository.results.commit)",push=true,compression=zstd,compression-level=22,oci-mediatypes=true - name: CONTEXT value: $(params.path-to-image-context) - name: DOCKERFILE value: $(params.path-to-dockerfile) - - name: BUILDER_IMAGE - value: "gcr.io/kaniko-project/executor:v1.12.1" - name: EXTRA_ARGS value: - - "--target=$(params.target-name)" - - --cache=true - - --cache-copy-layers - - --cache-repo=harbor.fizz.buzz/kanikocache/cache - - --use-new-run # Should result in a speed-up - - --reproducible # To remove timestamps so layer caching works. - - --snapshot-mode=redo - - --skip-unused-stages=true - - --registry-mirror=dockerhub.dockerhub.svc.cluster.local + - --import-cache + - "type=registry,ref=$(params.image-name):buildcache" + - --export-cache + - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" + - --opt + - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) + - name: BUILDKITD_TOML + value: | + debug = true + [registry."docker.io"] + mirrors = ["dockerhub.dockerhub.svc.cluster.local"] + [registry."dockerhub.dockerhub.svc.cluster.local"] + http = true + insecure = true workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials + runAfter: + - fetch-repository - name: run-cargo-clippy taskSpec: metadata: {} @@ -153,7 +184,7 @@ spec: - build-image params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" finally: - name: report-success when: @@ -247,7 +278,7 @@ spec: workspace: cargo-cache params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" workspaces: - name: git-source - name: docker-credentials @@ -277,4 +308,4 @@ spec: - name: path-to-image-context value: docker/organic_development/ - name: path-to-dockerfile - value: docker/organic_development/Dockerfile + value: docker/organic_development/ diff --git a/.webhook_bridge/pipeline-rust-test.yaml b/.webhook_bridge/pipeline-rust-test.yaml index 6face02..345e1aa 100644 --- a/.webhook_bridge/pipeline-rust-test.yaml +++ b/.webhook_bridge/pipeline-rust-test.yaml @@ -69,41 +69,72 @@ spec: value: $(params.PULL_BASE_SHA) - name: deleteExisting value: "true" + - name: get-git-commit-time + taskSpec: + metadata: {} + stepTemplate: + image: alpine:3.20 + computeResources: + requests: + cpu: 10m + memory: 600Mi + workingDir: "$(workspaces.repo.path)" + results: + - name: unix-time + description: The time of the git commit in unix timestamp format. + steps: + - image: alpine/git:v2.34.2 + name: detect-tag-step + script: | + #!/usr/bin/env sh + set -euo pipefail + echo -n "$(git log -1 --pretty=%ct)" | tee $(results.unix-time.path) + workspaces: + - name: repo + workspace: git-source + runAfter: + - fetch-repository - name: build-image taskRef: resolver: git params: - name: url - value: https://code.fizz.buzz/mirror/catalog.git # mirror of https://github.com/tektoncd/catalog.git + value: https://code.fizz.buzz/talexander/personal_tekton_catalog.git - name: revision - value: df36b3853a5657fd883015cdbf07ad6466918acf + value: 7ee31a185243ee6da13dcd26a592c585b64c80e5 - name: pathInRepo - value: task/kaniko/0.6/kaniko.yaml + value: task/buildkit-rootless-daemonless/0.1/buildkit-rootless-daemonless.yaml params: - - name: IMAGE - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + - name: OUTPUT + value: >- + type=image,"name=$(params.image-name):latest,$(params.image-name):$(tasks.fetch-repository.results.commit)",push=true,compression=zstd,compression-level=22,oci-mediatypes=true - name: CONTEXT value: $(params.path-to-image-context) - name: DOCKERFILE value: $(params.path-to-dockerfile) - - name: BUILDER_IMAGE - value: "gcr.io/kaniko-project/executor:v1.12.1" - name: EXTRA_ARGS value: - - "--target=$(params.target-name)" - - --cache=true - - --cache-copy-layers - - --cache-repo=harbor.fizz.buzz/kanikocache/cache - - --use-new-run # Should result in a speed-up - - --reproducible # To remove timestamps so layer caching works. - - --snapshot-mode=redo - - --skip-unused-stages=true - - --registry-mirror=dockerhub.dockerhub.svc.cluster.local + - --import-cache + - "type=registry,ref=$(params.image-name):buildcache" + - --export-cache + - "type=registry,ref=$(params.image-name):buildcache,mode=max,compression=zstd,compression-level=22,rewrite-timestamp=true,image-manifest=true,oci-mediatypes=true" + - --opt + - build-arg:SOURCE_DATE_EPOCH=$(tasks.get-git-commit-time.results.unix-time) + - name: BUILDKITD_TOML + value: | + debug = true + [registry."docker.io"] + mirrors = ["dockerhub.dockerhub.svc.cluster.local"] + [registry."dockerhub.dockerhub.svc.cluster.local"] + http = true + insecure = true workspaces: - name: source workspace: git-source - name: dockerconfig workspace: docker-credentials + runAfter: + - fetch-repository - name: run-cargo-test taskSpec: metadata: {} @@ -152,7 +183,7 @@ spec: - build-image params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" finally: - name: report-success when: @@ -246,7 +277,7 @@ spec: workspace: cargo-cache params: - name: docker-image - value: "$(params.image-name):$(tasks.fetch-repository.results.commit)" + value: "$(tasks.build-image.results.IMAGE_URL[1])" workspaces: - name: git-source - name: docker-credentials @@ -276,4 +307,4 @@ spec: - name: path-to-image-context value: docker/organic_test/ - name: path-to-dockerfile - value: docker/organic_test/Dockerfile + value: docker/organic_test/