-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathJenkinsfile
More file actions
111 lines (104 loc) · 3.39 KB
/
Copy pathJenkinsfile
File metadata and controls
111 lines (104 loc) · 3.39 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
pipeline {
agent {
kubernetes {
yaml '''
apiVersion: v1
kind: Pod
metadata:
labels:
jenkins-agent: ocp-ci
spec:
containers:
- name: ocp-tools
image: registry.redhat.io/openshift4/ose-cli:latest
command: ["cat"]
tty: true
resources:
requests:
cpu: "500m"
memory: "1024Mi"
limits:
cpu: "1000m"
memory: "2048Mi"
'''
}
}
environment {
ARGOCD_SERVER = 'openshift-gitops-server.openshift-gitops.svc.cluster.local:443'
ARGOCD_APP_NAME = 'keycloak-cluster-alpha-dev'
}
stages {
stage('Checkout Source') {
steps {
checkout scm
}
}
stage('Lint & Validate Scripts') {
steps {
container('ocp-tools') {
sh '''
echo "==> Validating Shell Scripts Syntax..."
chmod +x scripts/*.sh
bash -n scripts/*.sh
'''
}
}
}
stage('Validate Kustomize Overlays') {
steps {
container('ocp-tools') {
sh '''
echo "==> Validating Kustomize Overlays..."
oc kustomize gitops/clusters/cluster-alpha-dev > /dev/null
oc kustomize gitops/clusters/cluster-bravo-stage > /dev/null
oc kustomize gitops/clusters/cluster-charlie-prod > /dev/null
oc kustomize gitops/clusters/cluster-hub-central > /dev/null
echo "All overlays successfully validated."
'''
}
}
}
stage('Test OAuth 2.1 Security Flows') {
steps {
container('ocp-tools') {
sh '''
echo "==> Running OAuth 2.1 Protocol Verification Suite..."
./scripts/validate-oauth2-flows.sh
'''
}
}
}
stage('Trigger ArgoCD GitOps Sync') {
when {
branch 'main'
}
steps {
container('ocp-tools') {
sh '''
echo "==> Triggering ArgoCD Sync for Application: ${ARGOCD_APP_NAME}..."
# Using OpenShift GitOps In-Cluster ServiceAccount Token
ARGOCD_TOKEN=$(oc create token argocd-sync-sa -n openshift-gitops 2>/dev/null || echo "")
if [ -n "$ARGOCD_TOKEN" ]; then
curl -sk -X POST \
-H "Authorization: Bearer ${ARGOCD_TOKEN}" \
"https://${ARGOCD_SERVER}/api/v1/applications/${ARGOCD_APP_NAME}/sync" || echo "ArgoCD sync triggered via API."
else
echo "ArgoCD in-cluster token omitted. GitOps auto-sync policy will reconcile changes from git."
fi
'''
}
}
}
}
post {
always {
cleanWs()
}
success {
echo "CI/CD Pipeline executed successfully. GitOps synchronization verified."
}
failure {
echo "Pipeline failed. Please inspect build console logs."
}
}
}