diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..5041a2d --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,87 @@ +name: CI Pipeline + +on: + pull_request: + branches: + - main + push: + branches: + - main + +env: + SA_IMAGE: registry-egc.enflame-tech.com/enflame/ci_sast:v1.0-os + CI_IMAGE: registry-egc.enflame-tech.com/artifacts/qic_ubuntu_1804_gcc7:1.8.2 + SAST_REPO: EnflameTechnology/sast + SAST_BRANCH: main + +jobs: + all-ci-check: + runs-on: S60 + + steps: + - name: Setup SSH Agent + uses: webfactory/ssh-agent@v0.9.0 + with: + ssh-private-key: ${{ secrets.SSH_PRIVATE_KEY }} + + - name: Checkout SAST tools + uses: actions/checkout@v4 + with: + repository: ${{env.SAST_REPO}} + ref: ${{env.SAST_BRANCH}} + path: ./sast + ssh-key: ${{ secrets.SSH_PUB_KEY }} + + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-depth: 0 # Required for full git history to compare changes + path: ./gcushare + ssh-key: ${{ secrets.SSH_PUB_KEY }} + + - name: Run static code analysis + run: | + sudo docker run --rm \ + -v "$(pwd)/gcushare:/app" \ + -v "$(pwd)/sast:/sast" \ + -u "$(id -u):$(id -g)" \ + -w /app \ + "${{ env.SA_IMAGE }}" \ + bash -c 'cd /app && python3 /sast/run.py --all_ci_check' + + - name: Run CI Build + run: | + sudo docker run --rm \ + -v "$(pwd):/app" \ + --volume=/log:/log \ + --volume=/root:/root \ + --volume=/lib/modules/:/lib/modules/ \ + --volume=/usr/src/:/usr/src/ \ + --volume=/dev:/dev \ + --privileged \ + -v /home/pypi_packages:/home/pypi_packages \ + -w /app \ + "${{ env.CI_IMAGE }}" \ + bash -c 'sudo git config --global --add safe.directory /app/gcushare;cd /app/gcushare && bash ./build.sh all' + + - name: Upload wheel artifact + uses: actions/upload-artifact@v4 + with: + name: gcushare-wheel + path: ${{ github.workspace }}/gcushare/dist/** + if-no-files-found: error + + - name: Clean up + if: always() + run: | + set -euo pipefail + WORKSPACE="${{ github.workspace }}" + for repo in gcushare sast; do + TARGET_PATH="${WORKSPACE}/${repo}" + if [ -d "${TARGET_PATH}" ]; then + sudo rm -rf "${TARGET_PATH}" + echo "Removed ${TARGET_PATH}" + else + echo "Skip ${TARGET_PATH}, directory not found" + fi + done \ No newline at end of file diff --git a/gcushare-device-plugin/deployments/build-image.sh b/gcushare-device-plugin/deployments/build-image.sh deleted file mode 120000 index 0ac13b6..0000000 --- a/gcushare-device-plugin/deployments/build-image.sh +++ /dev/null @@ -1 +0,0 @@ -../../../common/build-image.sh \ No newline at end of file diff --git a/gcushare-device-plugin/deployments/build-image.sh b/gcushare-device-plugin/deployments/build-image.sh new file mode 100755 index 0000000..845b302 --- /dev/null +++ b/gcushare-device-plugin/deployments/build-image.sh @@ -0,0 +1,184 @@ +#!/bin/bash +# +# Copyright (c) 2024 Enflame. All Rights Reserved. +# + +if [ -f "./build-image.conf" ]; then + source ./build-image.conf +else + echo "build-image.conf is not found, exit."; exit 0 +fi + +VERSION="v1" +SET_VERSION=false + +function usage() { + cat < /dev/null 2>&1; then + echo "docker is not found, exit."; exit 1 + fi + elif [ "$CLI_NAME" == "podman" ]; then + if ! command -v podman > /dev/null 2>&1; then + echo "podman is not found, exit."; exit 1 + fi + elif [ "$CLI_NAME" == "nerdctl" ]; then + if ! command -v nerdctl > /dev/null 2>&1; then + echo "nerdctl is not found, exit."; exit 1 + fi + elif [ "$CLI_NAME" == "ctr" ]; then + if ! command -v ctr > /dev/null 2>&1; then + echo "ctr is not found, exit."; exit 1 + fi + if ! command -v docker > /dev/null 2>&1; then + echo "docker is not found, exit."; exit 1 + fi + else + echo "Invalid cli provided: $CLI_NAME"; exit 1 + fi + + case "$VERSION" in + "v1" | "v1beta1") + echo -e "\033[33mBuild gcushare device plugin version: '$VERSION'\033[0m" + ;; + *) + echo -e "\033[31mError: Invalid version '$VERSION'. Supported versions: v1, v1beta1\033[0m" + usage + exit 1 + ;; + esac +} + +function clearImage() { + echo -e "\033[33mClear old image if exist.\033[0m" + if [ "$CLI_NAME" == "nerdctl" ]; then + $CLI_NAME --namespace $NAMESPACE rmi -f $REPO_FULL_NAME > /dev/null 2>&1 || true + elif [ "$CLI_NAME" == "ctr" ]; then + $CLI_NAME --namespace $NAMESPACE images rm $REPO_FULL_NAME > /dev/null 2>&1 || true + else + $CLI_NAME rmi -f $REPO_FULL_NAME > /dev/null 2>&1 || true + fi +} + +function buildImage() { + echo -e "\033[33mBuilding image: $REPO_FULL_NAME start...\033[0m" + if [ "$CLI_NAME" == "nerdctl" ]; then + $CLI_NAME --namespace $NAMESPACE build --build-arg VERSION=$VERSION -t $REPO_FULL_NAME --file dockerfiles/Dockerfile.$OS . + elif [ "$CLI_NAME" == "ctr" ]; then + docker build --build-arg VERSION=$VERSION -t $REPO_FULL_NAME --file dockerfiles/Dockerfile.$OS . + else + $CLI_NAME build --build-arg VERSION=$VERSION -t $REPO_FULL_NAME --file dockerfiles/Dockerfile.$OS . + fi + echo "The image built successfully." +} + +function saveImage() { + echo -e "\033[33mSave image package to ./images\033[0m" + if [ -d "./images" ]; then + rm -rf ./images + fi + mkdir -p ./images + + IMAGE_SAVED_NAME="${IMAGE_NAME}.tar" + if [ "$CLI_NAME" == "nerdctl" ]; then + $CLI_NAME --namespace $NAMESPACE save -o ./images/$IMAGE_SAVED_NAME $REPO_FULL_NAME + elif [ "$CLI_NAME" == "ctr" ]; then + docker save -o ./images/$IMAGE_SAVED_NAME $REPO_FULL_NAME + $CLI_NAME --namespace $NAMESPACE image import ./images/$IMAGE_SAVED_NAME + else + $CLI_NAME save -o ./images/$IMAGE_SAVED_NAME $REPO_FULL_NAME + fi +} + +function listImage() { + echo -e "\033[33mList images...\033[0m" + if [ "$CLI_NAME" == "nerdctl" ]; then + $CLI_NAME --namespace $NAMESPACE images | grep $IMAGE_NAME + elif [ "$CLI_NAME" == "ctr" ]; then + $CLI_NAME --namespace $NAMESPACE images list | grep $IMAGE_NAME + else + $CLI_NAME images | grep $IMAGE_NAME + fi +} + +while true : + do + [[ "$#" -lt 1 ]] && { break;} + case $1 in + "") + break;; + --os) + OS=$2 + shift;; + --cli) + CLI_NAME=$2 + shift;; + --repo) + REPO_NAME=$2 + shift;; + --name) + IMAGE_NAME=$2 + shift;; + --tag) + TAG=$2 + shift;; + --namespace) + NAMESPACE=$2 + shift;; + --version) + VERSION=$2 + SET_VERSION=true + shift;; + --help | -h) + usage + exit 0;; + *) + echo -e "\033[31mError! Unknown parameter: $1. Please enter the specified parameters according to the usage\033[0m" + usage + exit 1;; + esac + shift +done + +if [ "$SET_VERSION" == "false" ]; then + echo -e "\033[32mWarning: The parameter: '--version' default '$VERSION' only apply to k8s1.24+,"\ + "set to v1beta1 for lower k8s versions\033[0m" +fi + +REPO_FULL_NAME="${REPO_NAME}/${IMAGE_NAME}:${TAG}" + +printEnv +checkCommand + +clearImage +buildImage +saveImage +listImage