From 596b2df8e61917449c6d9bcdd43136a021670d1c Mon Sep 17 00:00:00 2001 From: codex Date: Sat, 3 Oct 2026 16:00:22 -0500 Subject: [PATCH] ci: build release images without a missing Docker daemon --- Jenkinsfile | 66 ++++++++++++++++++++--------------------------------- 1 file changed, 25 insertions(+), 41 deletions(-) diff --git a/Jenkinsfile b/Jenkinsfile index 6bc2a2c..ae3819a 100644 --- a/Jenkinsfile +++ b/Jenkinsfile @@ -18,6 +18,7 @@ spec: operator: NotIn values: - titan-06 + - titan-08 preferredDuringSchedulingIgnoredDuringExecution: - weight: 100 preference: @@ -38,22 +39,22 @@ spec: jenkins/jenkins-jenkins-agent: "true" containers: - name: builder - image: registry.bstein.dev/bstein/docker:27 + image: gcr.io/kaniko-project/executor@sha256:c3109d5926a997b100c4343944e06c6b30a6804b2f9abe0994d3de6ef92b028e command: - - cat + - /busybox/cat tty: true - env: - - name: DOCKER_HOST - value: tcp://localhost:2375 - - name: DOCKER_TLS_CERTDIR - value: "" + resources: + requests: + cpu: 100m + memory: 1Gi + limits: + cpu: 1500m + memory: 2Gi volumeMounts: - name: workspace-volume mountPath: /home/jenkins/agent - name: docker-config-writable - mountPath: /root/.docker - - name: harbor-config - mountPath: /docker-config + mountPath: /kaniko/.docker - name: tester image: registry.bstein.dev/bstein/golang:1.25-bookworm command: @@ -73,12 +74,6 @@ spec: volumes: - name: docker-config-writable emptyDir: {} - - name: harbor-config - secret: - secretName: harbor-robot-pipeline - items: - - key: .dockerconfigjson - path: config.json - name: workspace-volume emptyDir: {} """ @@ -523,7 +518,7 @@ PY expression { return params.PUBLISH_IMAGES } } steps { - container('builder') { + container('tester') { script { sh 'git config --global --add safe.directory /home/jenkins/agent/workspace/Soteria' def semver = sh(returnStdout: true, script: 'git describe --tags --exact-match || true').trim() @@ -536,24 +531,6 @@ PY } } } - stage('Buildx setup') { - when { - expression { return params.PUBLISH_IMAGES } - } - steps { - container('builder') { - sh ''' - set -eu - seq 1 10 | while read _; do - docker info && break || sleep 2 - done - BUILDER_NAME="soteria-${BUILD_NUMBER}" - docker buildx rm "${BUILDER_NAME}" >/dev/null 2>&1 || true - docker buildx create --name "${BUILDER_NAME}" --driver docker-container --driver-opt image=registry.bstein.dev/bstein/buildkit:buildx-stable-1 --bootstrap --use - ''' - } - } - } stage('Build & push image') { when { expression { return params.PUBLISH_IMAGES } @@ -563,13 +540,20 @@ PY withCredentials([usernamePassword(credentialsId: 'harbor-robot', usernameVariable: 'HARBOR_USERNAME', passwordVariable: 'HARBOR_PASSWORD')]) { sh ''' set -eu + set +x VERSION_TAG=$(cut -d= -f2 build.env) - printf '%s' "${HARBOR_PASSWORD}" | docker login registry.bstein.dev -u "${HARBOR_USERNAME}" --password-stdin - docker buildx build --platform linux/arm64 \ - --provenance=false \ - --tag registry.bstein.dev/bstein/soteria:${VERSION_TAG} \ - --tag registry.bstein.dev/bstein/soteria:latest \ - --push . + umask 077 + auth=$(printf '%s:%s' "${HARBOR_USERNAME}" "${HARBOR_PASSWORD}" | base64 | tr -d '\\n') + printf '{"auths":{"registry.bstein.dev":{"auth":"%s"}}}\\n' "${auth}" > /kaniko/.docker/config.json + trap 'rm -f /kaniko/.docker/config.json' EXIT + /kaniko/executor \ + --context "${WORKSPACE}" \ + --dockerfile "${WORKSPACE}/Dockerfile" \ + --build-arg BUILDPLATFORM=linux/arm64 \ + --build-arg TARGETOS=linux \ + --build-arg TARGETARCH=arm64 \ + --destination "registry.bstein.dev/bstein/soteria:${VERSION_TAG}" \ + --destination registry.bstein.dev/bstein/soteria:latest ''' } }