[v11.0.x] CI: Add github app token generation in pipelines that use GITHUB_TOKEN (#96871)
CI: Add github app token generation in pipelines that use GITHUB_TOKEN (#96646)
* Add github app token generation in pipelines that use GITHUB_TOKEN
* ci?
* clone gh repo using x-access-token user
* address linting issues
* use mounted volume for exporting token
* remove unused github_token env var swagger gen step
* replace pat on release_pr pipepline
* cleanup GH PAT references
* linting
* Update scripts/drone/steps/lib.star
* make drone
---------
Co-authored-by: Matheus Macabu <macabu.matheus@gmail.com>
(cherry picked from commit 2400483d6c)
This commit is contained in:
@@ -7,6 +7,11 @@ load(
|
||||
"integration_test_services",
|
||||
"integration_test_services_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"compile_build_cmd",
|
||||
@@ -32,10 +37,13 @@ def integration_benchmarks(prefix):
|
||||
environment = {"EDITION": "oss"}
|
||||
|
||||
services = integration_test_services()
|
||||
volumes = integration_test_services_volumes()
|
||||
volumes = integration_test_services_volumes() + github_app_pipeline_volumes()
|
||||
|
||||
# In pull requests, attempt to clone grafana enterprise.
|
||||
init_steps = [enterprise_setup_step(isPromote = True)]
|
||||
init_steps = [
|
||||
github_app_generate_token_step(),
|
||||
enterprise_setup_step(isPromote = True),
|
||||
]
|
||||
|
||||
verify_step = verify_gen_cue_step()
|
||||
verify_jsonnet_step = verify_gen_jsonnet_step()
|
||||
|
||||
@@ -1,5 +1,10 @@
|
||||
"""This module contains the comprehensive build pipeline."""
|
||||
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"build_frontend_package_step",
|
||||
@@ -57,6 +62,7 @@ def build_e2e(trigger, ver_mode):
|
||||
|
||||
environment = {"EDITION": "oss"}
|
||||
init_steps = [
|
||||
github_app_generate_token_step(),
|
||||
identify_runner_step(),
|
||||
download_grabpl_step(),
|
||||
compile_build_cmd(),
|
||||
@@ -172,4 +178,5 @@ def build_e2e(trigger, ver_mode):
|
||||
services = [],
|
||||
steps = init_steps + build_steps,
|
||||
trigger = trigger,
|
||||
volumes = github_app_pipeline_volumes(),
|
||||
)
|
||||
|
||||
@@ -7,6 +7,11 @@ load(
|
||||
"integration_test_services",
|
||||
"integration_test_services_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"compile_build_cmd",
|
||||
@@ -50,8 +55,11 @@ def integration_tests(trigger, prefix, ver_mode = "pr"):
|
||||
|
||||
if ver_mode == "pr":
|
||||
# In pull requests, attempt to clone grafana enterprise.
|
||||
init_steps.append(github_app_generate_token_step())
|
||||
init_steps.append(enterprise_setup_step())
|
||||
|
||||
volumes += github_app_pipeline_volumes()
|
||||
|
||||
init_steps += [
|
||||
download_grabpl_step(),
|
||||
compile_build_cmd(),
|
||||
|
||||
@@ -2,6 +2,11 @@
|
||||
This module returns the pipeline used for linting backend code.
|
||||
"""
|
||||
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"compile_build_cmd",
|
||||
@@ -38,10 +43,15 @@ def lint_backend_pipeline(trigger, ver_mode):
|
||||
compile_build_cmd(),
|
||||
]
|
||||
|
||||
volumes = []
|
||||
|
||||
if ver_mode == "pr":
|
||||
# In pull requests, attempt to clone grafana enterprise.
|
||||
init_steps.append(github_app_generate_token_step())
|
||||
init_steps.append(enterprise_setup_step())
|
||||
|
||||
volumes += github_app_pipeline_volumes()
|
||||
|
||||
init_steps.append(wire_step)
|
||||
|
||||
test_steps = [
|
||||
@@ -59,4 +69,5 @@ def lint_backend_pipeline(trigger, ver_mode):
|
||||
services = [],
|
||||
steps = init_steps + test_steps,
|
||||
environment = environment,
|
||||
volumes = volumes,
|
||||
)
|
||||
|
||||
@@ -2,6 +2,11 @@
|
||||
This module returns the pipeline used for linting frontend code.
|
||||
"""
|
||||
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"enterprise_setup_step",
|
||||
@@ -31,9 +36,16 @@ def lint_frontend_pipeline(trigger, ver_mode):
|
||||
lint_step = lint_frontend_step()
|
||||
i18n_step = verify_i18n_step()
|
||||
|
||||
volumes = []
|
||||
|
||||
if ver_mode == "pr":
|
||||
# In pull requests, attempt to clone grafana enterprise.
|
||||
init_steps = [enterprise_setup_step()]
|
||||
init_steps = [
|
||||
github_app_generate_token_step(),
|
||||
enterprise_setup_step(),
|
||||
]
|
||||
|
||||
volumes += github_app_pipeline_volumes()
|
||||
|
||||
init_steps += [
|
||||
identify_runner_step(),
|
||||
@@ -50,4 +62,5 @@ def lint_frontend_pipeline(trigger, ver_mode):
|
||||
services = [],
|
||||
steps = init_steps + test_steps,
|
||||
environment = environment,
|
||||
volumes = volumes,
|
||||
)
|
||||
|
||||
@@ -2,6 +2,11 @@
|
||||
This module returns all pipelines used in OpenAPI specification generation of Grafana HTTP APIs
|
||||
"""
|
||||
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"enterprise_setup_step",
|
||||
@@ -14,10 +19,6 @@ load(
|
||||
"scripts/drone/utils/utils.star",
|
||||
"pipeline",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/vault.star",
|
||||
"from_secret",
|
||||
)
|
||||
|
||||
def swagger_gen_step(ver_mode):
|
||||
if ver_mode != "pr":
|
||||
@@ -26,9 +27,6 @@ def swagger_gen_step(ver_mode):
|
||||
return {
|
||||
"name": "swagger-gen",
|
||||
"image": images["go"],
|
||||
"environment": {
|
||||
"GITHUB_TOKEN": from_secret("github_token"),
|
||||
},
|
||||
"commands": [
|
||||
"apk add --update git make",
|
||||
"make swagger-clean && make openapi3-gen",
|
||||
@@ -42,6 +40,7 @@ def swagger_gen_step(ver_mode):
|
||||
|
||||
def swagger_gen(ver_mode, source = "${DRONE_SOURCE_BRANCH}"):
|
||||
test_steps = [
|
||||
github_app_generate_token_step(),
|
||||
enterprise_setup_step(source = source, canFail = True),
|
||||
swagger_gen_step(ver_mode = ver_mode),
|
||||
]
|
||||
@@ -53,6 +52,7 @@ def swagger_gen(ver_mode, source = "${DRONE_SOURCE_BRANCH}"):
|
||||
},
|
||||
services = [],
|
||||
steps = test_steps,
|
||||
volumes = github_app_pipeline_volumes(),
|
||||
)
|
||||
|
||||
return p
|
||||
|
||||
@@ -2,6 +2,11 @@
|
||||
This module returns the pipeline used for testing backend code.
|
||||
"""
|
||||
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"enterprise_setup_step",
|
||||
@@ -34,10 +39,15 @@ def test_backend(trigger, ver_mode):
|
||||
verify_step = verify_gen_cue_step()
|
||||
verify_jsonnet_step = verify_gen_jsonnet_step()
|
||||
|
||||
volumes = []
|
||||
|
||||
if ver_mode == "pr":
|
||||
# In pull requests, attempt to clone grafana enterprise.
|
||||
steps.append(github_app_generate_token_step())
|
||||
steps.append(enterprise_setup_step())
|
||||
|
||||
volumes += github_app_pipeline_volumes()
|
||||
|
||||
steps += [
|
||||
identify_runner_step(),
|
||||
verify_step,
|
||||
@@ -52,4 +62,5 @@ def test_backend(trigger, ver_mode):
|
||||
trigger = trigger,
|
||||
steps = steps,
|
||||
environment = environment,
|
||||
volumes = volumes,
|
||||
)
|
||||
|
||||
@@ -2,6 +2,11 @@
|
||||
This module returns the pipeline used for testing backend code.
|
||||
"""
|
||||
|
||||
load(
|
||||
"scripts/drone/steps/github.star",
|
||||
"github_app_generate_token_step",
|
||||
"github_app_pipeline_volumes",
|
||||
)
|
||||
load(
|
||||
"scripts/drone/steps/lib.star",
|
||||
"betterer_frontend_step",
|
||||
@@ -35,10 +40,15 @@ def test_frontend(trigger, ver_mode):
|
||||
|
||||
test_step = test_frontend_step()
|
||||
|
||||
volumes = []
|
||||
|
||||
if ver_mode == "pr":
|
||||
# In pull requests, attempt to clone grafana enterprise.
|
||||
steps.append(github_app_generate_token_step())
|
||||
steps.append(enterprise_setup_step())
|
||||
|
||||
volumes += github_app_pipeline_volumes()
|
||||
|
||||
steps.append(test_step)
|
||||
|
||||
return pipeline(
|
||||
@@ -46,4 +56,5 @@ def test_frontend(trigger, ver_mode):
|
||||
trigger = trigger,
|
||||
steps = steps,
|
||||
environment = environment,
|
||||
volumes = volumes,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user