Oscam is an Open Source Conditional Access Module software used for descrambling DVB transmissions using smart cards. It's both a server and a client.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

730 lines
34 KiB

  1. pipeline {
  2. agent {
  3. label 'X86-64-MULTI'
  4. }
  5. options {
  6. buildDiscarder(logRotator(numToKeepStr: '10', daysToKeepStr: '60'))
  7. parallelsAlwaysFailFast()
  8. }
  9. // Input to determine if this is a package check
  10. parameters {
  11. string(defaultValue: 'false', description: 'package check run', name: 'PACKAGE_CHECK')
  12. }
  13. // Configuration for the variables used for this specific repo
  14. environment {
  15. BUILDS_DISCORD=credentials('build_webhook_url')
  16. GITHUB_TOKEN=credentials('498b4638-2d02-4ce5-832d-8a57d01d97ab')
  17. GITLAB_TOKEN=credentials('b6f0f1dd-6952-4cf6-95d1-9c06380283f0')
  18. GITLAB_NAMESPACE=credentials('gitlab-namespace-id')
  19. BUILD_VERSION_ARG = 'OSCAM_VERSION'
  20. LS_USER = 'linuxserver'
  21. LS_REPO = 'docker-oscam'
  22. CONTAINER_NAME = 'oscam'
  23. DOCKERHUB_IMAGE = 'linuxserver/oscam'
  24. DEV_DOCKERHUB_IMAGE = 'lsiodev/oscam'
  25. PR_DOCKERHUB_IMAGE = 'lspipepr/oscam'
  26. DIST_IMAGE = 'alpine'
  27. MULTIARCH='true'
  28. CI='true'
  29. CI_WEB='true'
  30. CI_PORT='8888'
  31. CI_SSL='false'
  32. CI_DELAY='120'
  33. CI_DOCKERENV='TZ=US/Pacific'
  34. CI_AUTH='user:password'
  35. CI_WEBPATH=''
  36. }
  37. stages {
  38. // Setup all the basic environment variables needed for the build
  39. stage("Set ENV Variables base"){
  40. steps{
  41. script{
  42. env.EXIT_STATUS = ''
  43. env.LS_RELEASE = sh(
  44. script: '''docker run --rm ghcr.io/linuxserver/alexeiled-skopeo sh -c 'skopeo inspect docker://docker.io/'${DOCKERHUB_IMAGE}':latest 2>/dev/null' | jq -r '.Labels.build_version' | awk '{print $3}' | grep '\\-ls' || : ''',
  45. returnStdout: true).trim()
  46. env.LS_RELEASE_NOTES = sh(
  47. script: '''cat readme-vars.yml | awk -F \\" '/date: "[0-9][0-9].[0-9][0-9].[0-9][0-9]:/ {print $4;exit;}' | sed -E ':a;N;$!ba;s/\\r{0,1}\\n/\\\\n/g' ''',
  48. returnStdout: true).trim()
  49. env.GITHUB_DATE = sh(
  50. script: '''date '+%Y-%m-%dT%H:%M:%S%:z' ''',
  51. returnStdout: true).trim()
  52. env.COMMIT_SHA = sh(
  53. script: '''git rev-parse HEAD''',
  54. returnStdout: true).trim()
  55. env.CODE_URL = 'https://github.com/' + env.LS_USER + '/' + env.LS_REPO + '/commit/' + env.GIT_COMMIT
  56. env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.DOCKERHUB_IMAGE + '/tags/'
  57. env.PULL_REQUEST = env.CHANGE_ID
  58. env.TEMPLATED_FILES = 'Jenkinsfile README.md LICENSE ./.github/CONTRIBUTING.md ./.github/FUNDING.yml ./.github/ISSUE_TEMPLATE.md ./.github/PULL_REQUEST_TEMPLATE.md ./.github/workflows/greetings.yml ./.github/workflows/stale.yml'
  59. }
  60. script{
  61. env.LS_RELEASE_NUMBER = sh(
  62. script: '''echo ${LS_RELEASE} |sed 's/^.*-ls//g' ''',
  63. returnStdout: true).trim()
  64. }
  65. script{
  66. env.LS_TAG_NUMBER = sh(
  67. script: '''#! /bin/bash
  68. tagsha=$(git rev-list -n 1 ${LS_RELEASE} 2>/dev/null)
  69. if [ "${tagsha}" == "${COMMIT_SHA}" ]; then
  70. echo ${LS_RELEASE_NUMBER}
  71. elif [ -z "${GIT_COMMIT}" ]; then
  72. echo ${LS_RELEASE_NUMBER}
  73. else
  74. echo $((${LS_RELEASE_NUMBER} + 1))
  75. fi''',
  76. returnStdout: true).trim()
  77. }
  78. }
  79. }
  80. /* #######################
  81. Package Version Tagging
  82. ####################### */
  83. // Grab the current package versions in Git to determine package tag
  84. stage("Set Package tag"){
  85. steps{
  86. script{
  87. env.PACKAGE_TAG = sh(
  88. script: '''#!/bin/bash
  89. if [ -e package_versions.txt ] ; then
  90. cat package_versions.txt | md5sum | cut -c1-8
  91. else
  92. echo none
  93. fi''',
  94. returnStdout: true).trim()
  95. }
  96. }
  97. }
  98. /* ########################
  99. External Release Tagging
  100. ######################## */
  101. // If this is a custom command to determine version use that command
  102. stage("Set tag custom bash"){
  103. steps{
  104. script{
  105. env.EXT_RELEASE = sh(
  106. script: ''' docker run --rm alpine:3.9 sh -c 'apk add subversion > /dev/null 2>&1 && svn info --show-item revision https://svn.streamboard.tv/oscam/trunk' ''',
  107. returnStdout: true).trim()
  108. env.RELEASE_LINK = 'custom_command'
  109. }
  110. }
  111. }
  112. // Sanitize the release tag and strip illegal docker or github characters
  113. stage("Sanitize tag"){
  114. steps{
  115. script{
  116. env.EXT_RELEASE_CLEAN = sh(
  117. script: '''echo ${EXT_RELEASE} | sed 's/[~,%@+;:/]//g' ''',
  118. returnStdout: true).trim()
  119. }
  120. }
  121. }
  122. // If this is a master build use live docker endpoints
  123. stage("Set ENV live build"){
  124. when {
  125. branch "master"
  126. environment name: 'CHANGE_ID', value: ''
  127. }
  128. steps {
  129. script{
  130. env.IMAGE = env.DOCKERHUB_IMAGE
  131. env.GITHUBIMAGE = 'ghcr.io/' + env.LS_USER + '/' + env.CONTAINER_NAME
  132. env.GITLABIMAGE = 'registry.gitlab.com/linuxserver.io/' + env.LS_REPO + '/' + env.CONTAINER_NAME
  133. if (env.MULTIARCH == 'true') {
  134. env.CI_TAGS = 'amd64-' + env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER + '|arm32v7-' + env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER + '|arm64v8-' + env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER
  135. } else {
  136. env.CI_TAGS = env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER
  137. }
  138. env.META_TAG = env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER
  139. env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN
  140. }
  141. }
  142. }
  143. // If this is a dev build use dev docker endpoints
  144. stage("Set ENV dev build"){
  145. when {
  146. not {branch "master"}
  147. environment name: 'CHANGE_ID', value: ''
  148. }
  149. steps {
  150. script{
  151. env.IMAGE = env.DEV_DOCKERHUB_IMAGE
  152. env.GITHUBIMAGE = 'ghcr.io/' + env.LS_USER + '/lsiodev-' + env.CONTAINER_NAME
  153. env.GITLABIMAGE = 'registry.gitlab.com/linuxserver.io/' + env.LS_REPO + '/lsiodev-' + env.CONTAINER_NAME
  154. if (env.MULTIARCH == 'true') {
  155. env.CI_TAGS = 'amd64-' + env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-dev-' + env.COMMIT_SHA + '|arm32v7-' + env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-dev-' + env.COMMIT_SHA + '|arm64v8-' + env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-dev-' + env.COMMIT_SHA
  156. } else {
  157. env.CI_TAGS = env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-dev-' + env.COMMIT_SHA
  158. }
  159. env.META_TAG = env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-dev-' + env.COMMIT_SHA
  160. env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN
  161. env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.DEV_DOCKERHUB_IMAGE + '/tags/'
  162. }
  163. }
  164. }
  165. // If this is a pull request build use dev docker endpoints
  166. stage("Set ENV PR build"){
  167. when {
  168. not {environment name: 'CHANGE_ID', value: ''}
  169. }
  170. steps {
  171. script{
  172. env.IMAGE = env.PR_DOCKERHUB_IMAGE
  173. env.GITHUBIMAGE = 'ghcr.io/' + env.LS_USER + '/lspipepr-' + env.CONTAINER_NAME
  174. env.GITLABIMAGE = 'registry.gitlab.com/linuxserver.io/' + env.LS_REPO + '/lspipepr-' + env.CONTAINER_NAME
  175. if (env.MULTIARCH == 'true') {
  176. env.CI_TAGS = 'amd64-' + env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-pr-' + env.PULL_REQUEST + '|arm32v7-' + env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-pr-' + env.PULL_REQUEST + '|arm64v8-' + env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-pr-' + env.PULL_REQUEST
  177. } else {
  178. env.CI_TAGS = env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-pr-' + env.PULL_REQUEST
  179. }
  180. env.META_TAG = env.EXT_RELEASE_CLEAN + '-pkg-' + env.PACKAGE_TAG + '-pr-' + env.PULL_REQUEST
  181. env.EXT_RELEASE_TAG = 'version-' + env.EXT_RELEASE_CLEAN
  182. env.CODE_URL = 'https://github.com/' + env.LS_USER + '/' + env.LS_REPO + '/pull/' + env.PULL_REQUEST
  183. env.DOCKERHUB_LINK = 'https://hub.docker.com/r/' + env.PR_DOCKERHUB_IMAGE + '/tags/'
  184. }
  185. }
  186. }
  187. // Run ShellCheck
  188. stage('ShellCheck') {
  189. when {
  190. environment name: 'CI', value: 'true'
  191. }
  192. steps {
  193. withCredentials([
  194. string(credentialsId: 'ci-tests-s3-key-id', variable: 'S3_KEY'),
  195. string(credentialsId: 'ci-tests-s3-secret-access-key', variable: 'S3_SECRET')
  196. ]) {
  197. script{
  198. env.SHELLCHECK_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/shellcheck-result.xml'
  199. }
  200. sh '''curl -sL https://raw.githubusercontent.com/linuxserver/docker-shellcheck/master/checkrun.sh | /bin/bash'''
  201. sh '''#! /bin/bash
  202. set -e
  203. docker pull ghcr.io/linuxserver/lsiodev-spaces-file-upload:latest
  204. docker run --rm \
  205. -e DESTINATION=\"${IMAGE}/${META_TAG}/shellcheck-result.xml\" \
  206. -e FILE_NAME="shellcheck-result.xml" \
  207. -e MIMETYPE="text/xml" \
  208. -v ${WORKSPACE}:/mnt \
  209. -e SECRET_KEY=\"${S3_SECRET}\" \
  210. -e ACCESS_KEY=\"${S3_KEY}\" \
  211. -t ghcr.io/linuxserver/lsiodev-spaces-file-upload:latest \
  212. python /upload.py'''
  213. }
  214. }
  215. }
  216. // Use helper containers to render templated files
  217. stage('Update-Templates') {
  218. when {
  219. branch "master"
  220. environment name: 'CHANGE_ID', value: ''
  221. expression {
  222. env.CONTAINER_NAME != null
  223. }
  224. }
  225. steps {
  226. sh '''#! /bin/bash
  227. set -e
  228. TEMPDIR=$(mktemp -d)
  229. docker pull ghcr.io/linuxserver/jenkins-builder:latest
  230. docker run --rm -e CONTAINER_NAME=${CONTAINER_NAME} -e GITHUB_BRANCH=master -v ${TEMPDIR}:/ansible/jenkins ghcr.io/linuxserver/jenkins-builder:latest
  231. CURRENTHASH=$(grep -hs ^ ${TEMPLATED_FILES} | md5sum | cut -c1-8)
  232. cd ${TEMPDIR}/docker-${CONTAINER_NAME}
  233. NEWHASH=$(grep -hs ^ ${TEMPLATED_FILES} | md5sum | cut -c1-8)
  234. if [[ "${CURRENTHASH}" != "${NEWHASH}" ]]; then
  235. mkdir -p ${TEMPDIR}/repo
  236. git clone https://github.com/${LS_USER}/${LS_REPO}.git ${TEMPDIR}/repo/${LS_REPO}
  237. cd ${TEMPDIR}/repo/${LS_REPO}
  238. git checkout -f master
  239. cd ${TEMPDIR}/docker-${CONTAINER_NAME}
  240. mkdir -p ${TEMPDIR}/repo/${LS_REPO}/.github/workflows
  241. cp --parents ${TEMPLATED_FILES} ${TEMPDIR}/repo/${LS_REPO}/
  242. cd ${TEMPDIR}/repo/${LS_REPO}/
  243. git add ${TEMPLATED_FILES}
  244. git commit -m 'Bot Updating Templated Files'
  245. git push https://LinuxServer-CI:${GITHUB_TOKEN}@github.com/${LS_USER}/${LS_REPO}.git --all
  246. echo "true" > /tmp/${COMMIT_SHA}-${BUILD_NUMBER}
  247. else
  248. echo "false" > /tmp/${COMMIT_SHA}-${BUILD_NUMBER}
  249. fi
  250. mkdir -p ${TEMPDIR}/gitbook
  251. git clone https://github.com/linuxserver/docker-documentation.git ${TEMPDIR}/gitbook/docker-documentation
  252. if [[ "${BRANCH_NAME}" == "master" ]] && [[ (! -f ${TEMPDIR}/gitbook/docker-documentation/images/docker-${CONTAINER_NAME}.md) || ("$(md5sum ${TEMPDIR}/gitbook/docker-documentation/images/docker-${CONTAINER_NAME}.md | awk '{ print $1 }')" != "$(md5sum ${TEMPDIR}/docker-${CONTAINER_NAME}/docker-${CONTAINER_NAME}.md | awk '{ print $1 }')") ]]; then
  253. cp ${TEMPDIR}/docker-${CONTAINER_NAME}/docker-${CONTAINER_NAME}.md ${TEMPDIR}/gitbook/docker-documentation/images/
  254. cd ${TEMPDIR}/gitbook/docker-documentation/
  255. git add images/docker-${CONTAINER_NAME}.md
  256. git commit -m 'Bot Updating Documentation'
  257. git push https://LinuxServer-CI:${GITHUB_TOKEN}@github.com/linuxserver/docker-documentation.git --all
  258. fi
  259. rm -Rf ${TEMPDIR}'''
  260. script{
  261. env.FILES_UPDATED = sh(
  262. script: '''cat /tmp/${COMMIT_SHA}-${BUILD_NUMBER}''',
  263. returnStdout: true).trim()
  264. }
  265. }
  266. }
  267. // Exit the build if the Templated files were just updated
  268. stage('Template-exit') {
  269. when {
  270. branch "master"
  271. environment name: 'CHANGE_ID', value: ''
  272. environment name: 'FILES_UPDATED', value: 'true'
  273. expression {
  274. env.CONTAINER_NAME != null
  275. }
  276. }
  277. steps {
  278. script{
  279. env.EXIT_STATUS = 'ABORTED'
  280. }
  281. }
  282. }
  283. /* #######################
  284. GitLab Mirroring
  285. ####################### */
  286. // Ping into Gitlab to mirror this repo and have a registry endpoint
  287. stage("GitLab Mirror"){
  288. when {
  289. environment name: 'EXIT_STATUS', value: ''
  290. }
  291. steps{
  292. sh '''curl -H "Content-Type: application/json" -H "Private-Token: ${GITLAB_TOKEN}" -X POST https://gitlab.com/api/v4/projects \
  293. -d '{"namespace_id":'${GITLAB_NAMESPACE}',\
  294. "name":"'${LS_REPO}'",
  295. "mirror":true,\
  296. "import_url":"https://github.com/linuxserver/'${LS_REPO}'.git",\
  297. "issues_access_level":"disabled",\
  298. "merge_requests_access_level":"disabled",\
  299. "repository_access_level":"enabled",\
  300. "visibility":"public"}' '''
  301. }
  302. }
  303. /* ###############
  304. Build Container
  305. ############### */
  306. // Build Docker container for push to LS Repo
  307. stage('Build-Single') {
  308. when {
  309. environment name: 'MULTIARCH', value: 'false'
  310. environment name: 'EXIT_STATUS', value: ''
  311. }
  312. steps {
  313. sh "docker build --no-cache --pull -t ${IMAGE}:${META_TAG} \
  314. --build-arg ${BUILD_VERSION_ARG}=${EXT_RELEASE} --build-arg VERSION=\"${META_TAG}\" --build-arg BUILD_DATE=${GITHUB_DATE} ."
  315. }
  316. }
  317. // Build MultiArch Docker containers for push to LS Repo
  318. stage('Build-Multi') {
  319. when {
  320. environment name: 'MULTIARCH', value: 'true'
  321. environment name: 'EXIT_STATUS', value: ''
  322. }
  323. parallel {
  324. stage('Build X86') {
  325. steps {
  326. sh "docker build --no-cache --pull -t ${IMAGE}:amd64-${META_TAG} \
  327. --build-arg ${BUILD_VERSION_ARG}=${EXT_RELEASE} --build-arg VERSION=\"${META_TAG}\" --build-arg BUILD_DATE=${GITHUB_DATE} ."
  328. }
  329. }
  330. stage('Build ARMHF') {
  331. agent {
  332. label 'ARMHF'
  333. }
  334. steps {
  335. echo 'Logging into Github'
  336. sh '''#! /bin/bash
  337. echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin
  338. '''
  339. sh "docker build --no-cache --pull -f Dockerfile.armhf -t ${IMAGE}:arm32v7-${META_TAG} \
  340. --build-arg ${BUILD_VERSION_ARG}=${EXT_RELEASE} --build-arg VERSION=\"${META_TAG}\" --build-arg BUILD_DATE=${GITHUB_DATE} ."
  341. sh "docker tag ${IMAGE}:arm32v7-${META_TAG} ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER}"
  342. retry(5) {
  343. sh "docker push ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER}"
  344. }
  345. sh '''docker rmi \
  346. ${IMAGE}:arm32v7-${META_TAG} \
  347. ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER} || :'''
  348. }
  349. }
  350. stage('Build ARM64') {
  351. agent {
  352. label 'ARM64'
  353. }
  354. steps {
  355. echo 'Logging into Github'
  356. sh '''#! /bin/bash
  357. echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin
  358. '''
  359. sh "docker build --no-cache --pull -f Dockerfile.aarch64 -t ${IMAGE}:arm64v8-${META_TAG} \
  360. --build-arg ${BUILD_VERSION_ARG}=${EXT_RELEASE} --build-arg VERSION=\"${META_TAG}\" --build-arg BUILD_DATE=${GITHUB_DATE} ."
  361. sh "docker tag ${IMAGE}:arm64v8-${META_TAG} ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER}"
  362. retry(5) {
  363. sh "docker push ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER}"
  364. }
  365. sh '''docker rmi \
  366. ${IMAGE}:arm64v8-${META_TAG} \
  367. ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} || :'''
  368. }
  369. }
  370. }
  371. }
  372. // Take the image we just built and dump package versions for comparison
  373. stage('Update-packages') {
  374. when {
  375. branch "master"
  376. environment name: 'CHANGE_ID', value: ''
  377. environment name: 'EXIT_STATUS', value: ''
  378. }
  379. steps {
  380. sh '''#! /bin/bash
  381. set -e
  382. TEMPDIR=$(mktemp -d)
  383. if [ "${MULTIARCH}" == "true" ]; then
  384. LOCAL_CONTAINER=${IMAGE}:amd64-${META_TAG}
  385. else
  386. LOCAL_CONTAINER=${IMAGE}:${META_TAG}
  387. fi
  388. if [ "${DIST_IMAGE}" == "alpine" ]; then
  389. docker run --rm --entrypoint '/bin/sh' -v ${TEMPDIR}:/tmp ${LOCAL_CONTAINER} -c '\
  390. apk info -v > /tmp/package_versions.txt && \
  391. sort -o /tmp/package_versions.txt /tmp/package_versions.txt && \
  392. chmod 777 /tmp/package_versions.txt'
  393. elif [ "${DIST_IMAGE}" == "ubuntu" ]; then
  394. docker run --rm --entrypoint '/bin/sh' -v ${TEMPDIR}:/tmp ${LOCAL_CONTAINER} -c '\
  395. apt list -qq --installed | sed "s#/.*now ##g" | cut -d" " -f1 > /tmp/package_versions.txt && \
  396. sort -o /tmp/package_versions.txt /tmp/package_versions.txt && \
  397. chmod 777 /tmp/package_versions.txt'
  398. fi
  399. NEW_PACKAGE_TAG=$(md5sum ${TEMPDIR}/package_versions.txt | cut -c1-8 )
  400. echo "Package tag sha from current packages in buit container is ${NEW_PACKAGE_TAG} comparing to old ${PACKAGE_TAG} from github"
  401. if [ "${NEW_PACKAGE_TAG}" != "${PACKAGE_TAG}" ]; then
  402. git clone https://github.com/${LS_USER}/${LS_REPO}.git ${TEMPDIR}/${LS_REPO}
  403. git --git-dir ${TEMPDIR}/${LS_REPO}/.git checkout -f master
  404. cp ${TEMPDIR}/package_versions.txt ${TEMPDIR}/${LS_REPO}/
  405. cd ${TEMPDIR}/${LS_REPO}/
  406. wait
  407. git add package_versions.txt
  408. git commit -m 'Bot Updating Package Versions'
  409. git push https://LinuxServer-CI:${GITHUB_TOKEN}@github.com/${LS_USER}/${LS_REPO}.git --all
  410. echo "true" > /tmp/packages-${COMMIT_SHA}-${BUILD_NUMBER}
  411. echo "Package tag updated, stopping build process"
  412. else
  413. echo "false" > /tmp/packages-${COMMIT_SHA}-${BUILD_NUMBER}
  414. echo "Package tag is same as previous continue with build process"
  415. fi
  416. rm -Rf ${TEMPDIR}'''
  417. script{
  418. env.PACKAGE_UPDATED = sh(
  419. script: '''cat /tmp/packages-${COMMIT_SHA}-${BUILD_NUMBER}''',
  420. returnStdout: true).trim()
  421. }
  422. }
  423. }
  424. // Exit the build if the package file was just updated
  425. stage('PACKAGE-exit') {
  426. when {
  427. branch "master"
  428. environment name: 'CHANGE_ID', value: ''
  429. environment name: 'PACKAGE_UPDATED', value: 'true'
  430. environment name: 'EXIT_STATUS', value: ''
  431. }
  432. steps {
  433. script{
  434. env.EXIT_STATUS = 'ABORTED'
  435. }
  436. }
  437. }
  438. // Exit the build if this is just a package check and there are no changes to push
  439. stage('PACKAGECHECK-exit') {
  440. when {
  441. branch "master"
  442. environment name: 'CHANGE_ID', value: ''
  443. environment name: 'PACKAGE_UPDATED', value: 'false'
  444. environment name: 'EXIT_STATUS', value: ''
  445. expression {
  446. params.PACKAGE_CHECK == 'true'
  447. }
  448. }
  449. steps {
  450. script{
  451. env.EXIT_STATUS = 'ABORTED'
  452. }
  453. }
  454. }
  455. /* #######
  456. Testing
  457. ####### */
  458. // Run Container tests
  459. stage('Test') {
  460. when {
  461. environment name: 'CI', value: 'true'
  462. environment name: 'EXIT_STATUS', value: ''
  463. }
  464. steps {
  465. withCredentials([
  466. string(credentialsId: 'ci-tests-s3-key-id', variable: 'S3_KEY'),
  467. string(credentialsId: 'ci-tests-s3-secret-access-key ', variable: 'S3_SECRET')
  468. ]) {
  469. script{
  470. env.CI_URL = 'https://ci-tests.linuxserver.io/' + env.IMAGE + '/' + env.META_TAG + '/index.html'
  471. }
  472. sh '''#! /bin/bash
  473. set -e
  474. docker pull ghcr.io/linuxserver/lsiodev-ci:latest
  475. if [ "${MULTIARCH}" == "true" ]; then
  476. docker pull ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER}
  477. docker pull ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER}
  478. docker tag ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER} ${IMAGE}:arm32v7-${META_TAG}
  479. docker tag ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} ${IMAGE}:arm64v8-${META_TAG}
  480. fi
  481. docker run --rm \
  482. --shm-size=1gb \
  483. -v /var/run/docker.sock:/var/run/docker.sock \
  484. -e IMAGE=\"${IMAGE}\" \
  485. -e DELAY_START=\"${CI_DELAY}\" \
  486. -e TAGS=\"${CI_TAGS}\" \
  487. -e META_TAG=\"${META_TAG}\" \
  488. -e PORT=\"${CI_PORT}\" \
  489. -e SSL=\"${CI_SSL}\" \
  490. -e BASE=\"${DIST_IMAGE}\" \
  491. -e SECRET_KEY=\"${S3_SECRET}\" \
  492. -e ACCESS_KEY=\"${S3_KEY}\" \
  493. -e DOCKER_ENV=\"${CI_DOCKERENV}\" \
  494. -e WEB_SCREENSHOT=\"${CI_WEB}\" \
  495. -e WEB_AUTH=\"${CI_AUTH}\" \
  496. -e WEB_PATH=\"${CI_WEBPATH}\" \
  497. -e DO_REGION="ams3" \
  498. -e DO_BUCKET="lsio-ci" \
  499. -t ghcr.io/linuxserver/lsiodev-ci:latest \
  500. python /ci/ci.py'''
  501. }
  502. }
  503. }
  504. /* ##################
  505. Release Logic
  506. ################## */
  507. // If this is an amd64 only image only push a single image
  508. stage('Docker-Push-Single') {
  509. when {
  510. environment name: 'MULTIARCH', value: 'false'
  511. environment name: 'EXIT_STATUS', value: ''
  512. }
  513. steps {
  514. withCredentials([
  515. [
  516. $class: 'UsernamePasswordMultiBinding',
  517. credentialsId: '3f9ba4d5-100d-45b0-a3c4-633fd6061207',
  518. usernameVariable: 'DOCKERUSER',
  519. passwordVariable: 'DOCKERPASS'
  520. ]
  521. ]) {
  522. retry(5) {
  523. sh '''#! /bin/bash
  524. set -e
  525. echo $DOCKERPASS | docker login -u $DOCKERUSER --password-stdin
  526. echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin
  527. echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin
  528. for PUSHIMAGE in "${GITHUBIMAGE}" "${GITLABIMAGE}" "${IMAGE}"; do
  529. docker tag ${IMAGE}:${META_TAG} ${PUSHIMAGE}:${META_TAG}
  530. docker tag ${PUSHIMAGE}:${META_TAG} ${PUSHIMAGE}:latest
  531. docker tag ${PUSHIMAGE}:${META_TAG} ${PUSHIMAGE}:${EXT_RELEASE_TAG}
  532. docker push ${PUSHIMAGE}:latest
  533. docker push ${PUSHIMAGE}:${META_TAG}
  534. docker push ${PUSHIMAGE}:${EXT_RELEASE_TAG}
  535. done
  536. '''
  537. }
  538. sh '''#! /bin/bash
  539. for DELETEIMAGE in "${GITHUBIMAGE}" "{GITLABIMAGE}" "${IMAGE}"; do
  540. docker rmi \
  541. ${DELETEIMAGE}:${META_TAG} \
  542. ${DELETEIMAGE}:${EXT_RELEASE_TAG} \
  543. ${DELETEIMAGE}:latest || :
  544. done
  545. '''
  546. }
  547. }
  548. }
  549. // If this is a multi arch release push all images and define the manifest
  550. stage('Docker-Push-Multi') {
  551. when {
  552. environment name: 'MULTIARCH', value: 'true'
  553. environment name: 'EXIT_STATUS', value: ''
  554. }
  555. steps {
  556. withCredentials([
  557. [
  558. $class: 'UsernamePasswordMultiBinding',
  559. credentialsId: '3f9ba4d5-100d-45b0-a3c4-633fd6061207',
  560. usernameVariable: 'DOCKERUSER',
  561. passwordVariable: 'DOCKERPASS'
  562. ]
  563. ]) {
  564. retry(5) {
  565. sh '''#! /bin/bash
  566. set -e
  567. echo $DOCKERPASS | docker login -u $DOCKERUSER --password-stdin
  568. echo $GITHUB_TOKEN | docker login ghcr.io -u LinuxServer-CI --password-stdin
  569. echo $GITLAB_TOKEN | docker login registry.gitlab.com -u LinuxServer.io --password-stdin
  570. if [ "${CI}" == "false" ]; then
  571. docker pull ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER}
  572. docker pull ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER}
  573. docker tag ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER} ${IMAGE}:arm32v7-${META_TAG}
  574. docker tag ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} ${IMAGE}:arm64v8-${META_TAG}
  575. fi
  576. for MANIFESTIMAGE in "${IMAGE}" "${GITLABIMAGE}" "${GITHUBIMAGE}"; do
  577. docker tag ${IMAGE}:amd64-${META_TAG} ${MANIFESTIMAGE}:amd64-${META_TAG}
  578. docker tag ${IMAGE}:arm32v7-${META_TAG} ${MANIFESTIMAGE}:arm32v7-${META_TAG}
  579. docker tag ${IMAGE}:arm64v8-${META_TAG} ${MANIFESTIMAGE}:arm64v8-${META_TAG}
  580. docker tag ${MANIFESTIMAGE}:amd64-${META_TAG} ${MANIFESTIMAGE}:amd64-latest
  581. docker tag ${MANIFESTIMAGE}:arm32v7-${META_TAG} ${MANIFESTIMAGE}:arm32v7-latest
  582. docker tag ${MANIFESTIMAGE}:arm64v8-${META_TAG} ${MANIFESTIMAGE}:arm64v8-latest
  583. docker tag ${MANIFESTIMAGE}:amd64-${META_TAG} ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG}
  584. docker tag ${MANIFESTIMAGE}:arm32v7-${META_TAG} ${MANIFESTIMAGE}:arm32v7-${EXT_RELEASE_TAG}
  585. docker tag ${MANIFESTIMAGE}:arm64v8-${META_TAG} ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG}
  586. docker push ${MANIFESTIMAGE}:amd64-${META_TAG}
  587. docker push ${MANIFESTIMAGE}:arm32v7-${META_TAG}
  588. docker push ${MANIFESTIMAGE}:arm64v8-${META_TAG}
  589. docker push ${MANIFESTIMAGE}:amd64-latest
  590. docker push ${MANIFESTIMAGE}:arm32v7-latest
  591. docker push ${MANIFESTIMAGE}:arm64v8-latest
  592. docker push ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG}
  593. docker push ${MANIFESTIMAGE}:arm32v7-${EXT_RELEASE_TAG}
  594. docker push ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG}
  595. docker manifest push --purge ${MANIFESTIMAGE}:latest || :
  596. docker manifest create ${MANIFESTIMAGE}:latest ${MANIFESTIMAGE}:amd64-latest ${MANIFESTIMAGE}:arm32v7-latest ${MANIFESTIMAGE}:arm64v8-latest
  597. docker manifest annotate ${MANIFESTIMAGE}:latest ${MANIFESTIMAGE}:arm32v7-latest --os linux --arch arm
  598. docker manifest annotate ${MANIFESTIMAGE}:latest ${MANIFESTIMAGE}:arm64v8-latest --os linux --arch arm64 --variant v8
  599. docker manifest push --purge ${MANIFESTIMAGE}:${META_TAG} || :
  600. docker manifest create ${MANIFESTIMAGE}:${META_TAG} ${MANIFESTIMAGE}:amd64-${META_TAG} ${MANIFESTIMAGE}:arm32v7-${META_TAG} ${MANIFESTIMAGE}:arm64v8-${META_TAG}
  601. docker manifest annotate ${MANIFESTIMAGE}:${META_TAG} ${MANIFESTIMAGE}:arm32v7-${META_TAG} --os linux --arch arm
  602. docker manifest annotate ${MANIFESTIMAGE}:${META_TAG} ${MANIFESTIMAGE}:arm64v8-${META_TAG} --os linux --arch arm64 --variant v8
  603. docker manifest create ${MANIFESTIMAGE}:${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:amd64-${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:arm32v7-${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG}
  604. docker manifest annotate ${MANIFESTIMAGE}:${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:arm32v7-${EXT_RELEASE_TAG} --os linux --arch arm
  605. docker manifest annotate ${MANIFESTIMAGE}:${EXT_RELEASE_TAG} ${MANIFESTIMAGE}:arm64v8-${EXT_RELEASE_TAG} --os linux --arch arm64 --variant v8
  606. docker manifest push --purge ${MANIFESTIMAGE}:latest
  607. docker manifest push --purge ${MANIFESTIMAGE}:${META_TAG}
  608. docker manifest push --purge ${MANIFESTIMAGE}:${EXT_RELEASE_TAG}
  609. done
  610. '''
  611. }
  612. sh '''#! /bin/bash
  613. for DELETEIMAGE in "${GITHUBIMAGE}" "${GITLABIMAGE}" "${IMAGE}"; do
  614. docker rmi \
  615. ${DELETEIMAGE}:amd64-${META_TAG} \
  616. ${DELETEIMAGE}:amd64-latest \
  617. ${DELETEIMAGE}:arm32v7-${META_TAG} \
  618. ${DELETEIMAGE}:arm32v7-latest \
  619. ${DELETEIMAGE}:arm64v8-${META_TAG} \
  620. ${DELETEIMAGE}:arm64v8-latest || :
  621. done
  622. docker rmi \
  623. ghcr.io/linuxserver/lsiodev-buildcache:arm32v7-${COMMIT_SHA}-${BUILD_NUMBER} \
  624. ghcr.io/linuxserver/lsiodev-buildcache:arm64v8-${COMMIT_SHA}-${BUILD_NUMBER} || :
  625. '''
  626. }
  627. }
  628. }
  629. // If this is a public release tag it in the LS Github
  630. stage('Github-Tag-Push-Release') {
  631. when {
  632. branch "master"
  633. expression {
  634. env.LS_RELEASE != env.EXT_RELEASE_CLEAN + '-ls' + env.LS_TAG_NUMBER
  635. }
  636. environment name: 'CHANGE_ID', value: ''
  637. environment name: 'EXIT_STATUS', value: ''
  638. }
  639. steps {
  640. echo "Pushing New tag for current commit ${EXT_RELEASE_CLEAN}-ls${LS_TAG_NUMBER}"
  641. sh '''curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/git/tags \
  642. -d '{"tag":"'${EXT_RELEASE_CLEAN}'-ls'${LS_TAG_NUMBER}'",\
  643. "object": "'${COMMIT_SHA}'",\
  644. "message": "Tagging Release '${EXT_RELEASE_CLEAN}'-ls'${LS_TAG_NUMBER}' to master",\
  645. "type": "commit",\
  646. "tagger": {"name": "LinuxServer Jenkins","email": "jenkins@linuxserver.io","date": "'${GITHUB_DATE}'"}}' '''
  647. echo "Pushing New release for Tag"
  648. sh '''#! /bin/bash
  649. echo "Updating to ${EXT_RELEASE_CLEAN}" > releasebody.json
  650. echo '{"tag_name":"'${EXT_RELEASE_CLEAN}'-ls'${LS_TAG_NUMBER}'",\
  651. "target_commitish": "master",\
  652. "name": "'${EXT_RELEASE_CLEAN}'-ls'${LS_TAG_NUMBER}'",\
  653. "body": "**LinuxServer Changes:**\\n\\n'${LS_RELEASE_NOTES}'\\n**Remote Changes:**\\n\\n' > start
  654. printf '","draft": false,"prerelease": false}' >> releasebody.json
  655. paste -d'\\0' start releasebody.json > releasebody.json.done
  656. curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/releases -d @releasebody.json.done'''
  657. }
  658. }
  659. // Use helper container to sync the current README on master to the dockerhub endpoint
  660. stage('Sync-README') {
  661. when {
  662. environment name: 'CHANGE_ID', value: ''
  663. environment name: 'EXIT_STATUS', value: ''
  664. }
  665. steps {
  666. withCredentials([
  667. [
  668. $class: 'UsernamePasswordMultiBinding',
  669. credentialsId: '3f9ba4d5-100d-45b0-a3c4-633fd6061207',
  670. usernameVariable: 'DOCKERUSER',
  671. passwordVariable: 'DOCKERPASS'
  672. ]
  673. ]) {
  674. sh '''#! /bin/bash
  675. set -e
  676. TEMPDIR=$(mktemp -d)
  677. docker pull ghcr.io/linuxserver/jenkins-builder:latest
  678. docker run --rm -e CONTAINER_NAME=${CONTAINER_NAME} -e GITHUB_BRANCH="${BRANCH_NAME}" -v ${TEMPDIR}:/ansible/jenkins ghcr.io/linuxserver/jenkins-builder:latest
  679. docker pull ghcr.io/linuxserver/lsiodev-readme-sync
  680. docker run --rm=true \
  681. -e DOCKERHUB_USERNAME=$DOCKERUSER \
  682. -e DOCKERHUB_PASSWORD=$DOCKERPASS \
  683. -e GIT_REPOSITORY=${LS_USER}/${LS_REPO} \
  684. -e DOCKER_REPOSITORY=${IMAGE} \
  685. -e GIT_BRANCH=master \
  686. -v ${TEMPDIR}/docker-${CONTAINER_NAME}:/mnt \
  687. ghcr.io/linuxserver/lsiodev-readme-sync bash -c 'node sync'
  688. rm -Rf ${TEMPDIR} '''
  689. }
  690. }
  691. }
  692. // If this is a Pull request send the CI link as a comment on it
  693. stage('Pull Request Comment') {
  694. when {
  695. not {environment name: 'CHANGE_ID', value: ''}
  696. environment name: 'CI', value: 'true'
  697. environment name: 'EXIT_STATUS', value: ''
  698. }
  699. steps {
  700. sh '''curl -H "Authorization: token ${GITHUB_TOKEN}" -X POST https://api.github.com/repos/${LS_USER}/${LS_REPO}/issues/${PULL_REQUEST}/comments \
  701. -d '{"body": "I am a bot, here are the test results for this PR: \\n'${CI_URL}' \\n'${SHELLCHECK_URL}'"}' '''
  702. }
  703. }
  704. }
  705. /* ######################
  706. Send status to Discord
  707. ###################### */
  708. post {
  709. always {
  710. script{
  711. if (env.EXIT_STATUS == "ABORTED"){
  712. sh 'echo "build aborted"'
  713. }
  714. else if (currentBuild.currentResult == "SUCCESS"){
  715. sh ''' curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://wiki.jenkins-ci.org/download/attachments/2916393/headshot.png","embeds": [{"color": 1681177,\
  716. "description": "**Build:** '${BUILD_NUMBER}'\\n**CI Results:** '${CI_URL}'\\n**ShellCheck Results:** '${SHELLCHECK_URL}'\\n**Status:** Success\\n**Job:** '${RUN_DISPLAY_URL}'\\n**Change:** '${CODE_URL}'\\n**External Release:**: '${RELEASE_LINK}'\\n**DockerHub:** '${DOCKERHUB_LINK}'\\n"}],\
  717. "username": "Jenkins"}' ${BUILDS_DISCORD} '''
  718. }
  719. else {
  720. sh ''' curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://wiki.jenkins-ci.org/download/attachments/2916393/headshot.png","embeds": [{"color": 16711680,\
  721. "description": "**Build:** '${BUILD_NUMBER}'\\n**CI Results:** '${CI_URL}'\\n**ShellCheck Results:** '${SHELLCHECK_URL}'\\n**Status:** failure\\n**Job:** '${RUN_DISPLAY_URL}'\\n**Change:** '${CODE_URL}'\\n**External Release:**: '${RELEASE_LINK}'\\n**DockerHub:** '${DOCKERHUB_LINK}'\\n"}],\
  722. "username": "Jenkins"}' ${BUILDS_DISCORD} '''
  723. }
  724. }
  725. }
  726. cleanup {
  727. cleanWs()
  728. }
  729. }
  730. }