ci: build release images without a missing Docker daemon

This commit is contained in:
codex 2026-10-03 16:00:22 -05:00
parent 3c0c868708
commit 596b2df8e6

66
Jenkinsfile vendored
View File

@ -18,6 +18,7 @@ spec:
operator: NotIn
values:
- titan-06
- titan-08
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
preference:
@ -38,22 +39,22 @@ spec:
jenkins/jenkins-jenkins-agent: "true"
containers:
- name: builder
image: registry.bstein.dev/bstein/docker:27
image: gcr.io/kaniko-project/executor@sha256:c3109d5926a997b100c4343944e06c6b30a6804b2f9abe0994d3de6ef92b028e
command:
- cat
- /busybox/cat
tty: true
env:
- name: DOCKER_HOST
value: tcp://localhost:2375
- name: DOCKER_TLS_CERTDIR
value: ""
resources:
requests:
cpu: 100m
memory: 1Gi
limits:
cpu: 1500m
memory: 2Gi
volumeMounts:
- name: workspace-volume
mountPath: /home/jenkins/agent
- name: docker-config-writable
mountPath: /root/.docker
- name: harbor-config
mountPath: /docker-config
mountPath: /kaniko/.docker
- name: tester
image: registry.bstein.dev/bstein/golang:1.25-bookworm
command:
@ -73,12 +74,6 @@ spec:
volumes:
- name: docker-config-writable
emptyDir: {}
- name: harbor-config
secret:
secretName: harbor-robot-pipeline
items:
- key: .dockerconfigjson
path: config.json
- name: workspace-volume
emptyDir: {}
"""
@ -523,7 +518,7 @@ PY
expression { return params.PUBLISH_IMAGES }
}
steps {
container('builder') {
container('tester') {
script {
sh 'git config --global --add safe.directory /home/jenkins/agent/workspace/Soteria'
def semver = sh(returnStdout: true, script: 'git describe --tags --exact-match || true').trim()
@ -536,24 +531,6 @@ PY
}
}
}
stage('Buildx setup') {
when {
expression { return params.PUBLISH_IMAGES }
}
steps {
container('builder') {
sh '''
set -eu
seq 1 10 | while read _; do
docker info && break || sleep 2
done
BUILDER_NAME="soteria-${BUILD_NUMBER}"
docker buildx rm "${BUILDER_NAME}" >/dev/null 2>&1 || true
docker buildx create --name "${BUILDER_NAME}" --driver docker-container --driver-opt image=registry.bstein.dev/bstein/buildkit:buildx-stable-1 --bootstrap --use
'''
}
}
}
stage('Build & push image') {
when {
expression { return params.PUBLISH_IMAGES }
@ -563,13 +540,20 @@ PY
withCredentials([usernamePassword(credentialsId: 'harbor-robot', usernameVariable: 'HARBOR_USERNAME', passwordVariable: 'HARBOR_PASSWORD')]) {
sh '''
set -eu
set +x
VERSION_TAG=$(cut -d= -f2 build.env)
printf '%s' "${HARBOR_PASSWORD}" | docker login registry.bstein.dev -u "${HARBOR_USERNAME}" --password-stdin
docker buildx build --platform linux/arm64 \
--provenance=false \
--tag registry.bstein.dev/bstein/soteria:${VERSION_TAG} \
--tag registry.bstein.dev/bstein/soteria:latest \
--push .
umask 077
auth=$(printf '%s:%s' "${HARBOR_USERNAME}" "${HARBOR_PASSWORD}" | base64 | tr -d '\\n')
printf '{"auths":{"registry.bstein.dev":{"auth":"%s"}}}\\n' "${auth}" > /kaniko/.docker/config.json
trap 'rm -f /kaniko/.docker/config.json' EXIT
/kaniko/executor \
--context "${WORKSPACE}" \
--dockerfile "${WORKSPACE}/Dockerfile" \
--build-arg BUILDPLATFORM=linux/arm64 \
--build-arg TARGETOS=linux \
--build-arg TARGETARCH=arm64 \
--destination "registry.bstein.dev/bstein/soteria:${VERSION_TAG}" \
--destination registry.bstein.dev/bstein/soteria:latest
'''
}
}