Skip to content
Snippets Groups Projects
.gitlab-ci.yml 5.59 KiB
Newer Older
Varac's avatar
Varac committed
include:
Mart van Santen's avatar
Mart van Santen committed
  - remote: https://open.greenhost.net/stackspin/stackspin/raw/main/.gitlab/ci_templates/kaniko.yml
Mark's avatar
Mark committed
stages:
Mart van Santen's avatar
Mart van Santen committed
  - build
  - build-test-images
  # TODO: Re-enable after fixing #82
  # - lint
Mart van Santen's avatar
Mart van Santen committed
  # - application-test
  - integration-test
Mark's avatar
Mark committed

#login_test:
#  image: python:3.8
#  stage: unittest
#  needs: []
#  variables:
#    HYDRA_ADMIN_URL: http://localhost/ignored
#    KRATOS_PUBLIC_URL: http://localhost/ignored
#    PUBLIC_URL: http://localhost/ignored
#  cache:
#    paths:
#      - "$CI_PROJECT_DIR/pip-cache"
#    key: "$CI_PROJECT_ID"
#    before_script:
#      - cd login
#      - python -V
#      - pip install -r requirements.txt
#    script:
#      - pytest -v --cov=login --cov-report=term --cov-report=xml tests
#    artifacts:
#      reports:
#        cobertura: login/coverage.xml
#    coverage: '/^TOTAL.+?(\d+\%)$/'
login:
  stage: build
  needs: []
  extends: .kaniko_build
  variables:
Mart van Santen's avatar
Mart van Santen committed
    KANIKO_CONTEXT: "login"
    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
Mart van Santen's avatar
Mart van Santen committed
  before_script:
Mart van Santen's avatar
Mart van Santen committed
    - ls -l ${CI_PROJECT_DIR}/${KANIKO_CONTEXT:-.}/Dockerfile 
  only:
    changes:
      - login/**/*


# A Fake SSO app to test the behaviour
Mart van Santen's avatar
Mart van Santen committed
sso_testapp:
  stage: build-test-images
  variables:
Mart van Santen's avatar
Mart van Santen committed
    KANIKO_CONTEXT: "test/sso_testapp/"
    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
  extends: .kaniko_build
  only:
    changes:
Mart van Santen's avatar
Mart van Santen committed
      - test/sso_testapp/**/*
#      - .gitlab-ci.yml
# Webbrowser tests
Mart van Santen's avatar
Mart van Santen committed
behave:
  stage: build-test-images
  variables:
Mart van Santen's avatar
Mart van Santen committed
    KANIKO_CONTEXT: "test/behave"
    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
  extends: .kaniko_build
  only:
    changes:
Mart van Santen's avatar
Mart van Santen committed
      - test/behave/**/*
#      - .gitlab-ci.yml
#pylint:
#  stage: build-test-images
#  variables:
#    KANIKO_CONTEXT: "test/lint/pylint"
#    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
#  extends: .kaniko_build
#  only:
#    changes:
#      - test/lint/pylint/Dockerfile
#      - test/lint/pylint/requirements.txt
#      - .gitlab-ci.yml
postgres:
  stage: build
  needs: []
  variables:
    KANIKO_CONTEXT: "postgres"
    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
  extends: .kaniko_build
Mart van Santen's avatar
Mart van Santen committed
  only:
    changes:
      - postgres/**/*


kratos:
  stage: build
  needs: []
  variables:
    KANIKO_CONTEXT: "kratos"
    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
  extends: .kaniko_build
Mart van Santen's avatar
Mart van Santen committed
  only:
    changes:
      - kratos/**/*
Mart van Santen's avatar
Mart van Santen committed
hydra:
  stage: build
  needs: []
  variables:
    KANIKO_CONTEXT: "hydra"
    KANIKO_BUILD_IMAGENAME: $CI_JOB_NAME
  extends: .kaniko_build
Mart van Santen's avatar
Mart van Santen committed
  only:
    changes:
      - hydra/**/*

Mark's avatar
Mark committed
behave-integration:
  stage: integration-test
  services:
    - name: ${CI_REGISTRY_IMAGE}/postgres:${CI_COMMIT_REF_NAME}
Mark's avatar
Mark committed
      alias: postgres
Mart van Santen's avatar
Mart van Santen committed
    - name: ${CI_REGISTRY_IMAGE}/kratos:${CI_COMMIT_REF_NAME}
Mart van Santen's avatar
Mart van Santen committed
      alias: kratosmigrate
Mart van Santen's avatar
Mart van Santen committed
      command:
        - migrate
        - sql
        - -e
        - -y
    - name: ${CI_REGISTRY_IMAGE}/kratos:${CI_COMMIT_REF_NAME}
      alias: kratos
      command:
        - serve
        - --config
        - /etc/config/kratos.yaml
Mart van Santen's avatar
Mart van Santen committed
    - name: ${CI_REGISTRY_IMAGE}/hydra:${CI_COMMIT_REF_NAME}
Mart van Santen's avatar
Mart van Santen committed
      alias: hydramigrate
Mark's avatar
Mark committed
      command:
Mart van Santen's avatar
Mart van Santen committed
        - migrate
        - sql
Mart van Santen's avatar
Mart van Santen committed
        - -e
        - -y
Mart van Santen's avatar
Mart van Santen committed
    - name: ${CI_REGISTRY_IMAGE}/hydra:${CI_COMMIT_REF_NAME}
      alias: hydra
      command:
Mart van Santen's avatar
Mart van Santen committed
        - serve
Mart van Santen's avatar
Mart van Santen committed
        - all
        - --dangerous-force-http
        - --dangerous-allow-insecure-redirect-urls
        - http://oidc:5000/login
    - name: ${CI_REGISTRY_IMAGE}/login:${CI_COMMIT_REF_NAME}
Mart van Santen's avatar
Mart van Santen committed
      alias: oidc
    - name: ${CI_REGISTRY_IMAGE}/sso_testapp:${CI_COMMIT_REF_NAME}
      alias: ssoapp
Mark's avatar
Mark committed
  variables:
    # Feature Flag FF_NETWORK_PER_BUILD Enables creation of a docker network per build
    # with the docker executor of the gitlab-runner. This is required for service
    # interconnection. Requires gitlab-runner v12.9.0
    FF_NETWORK_PER_BUILD: 1
    GIT_SUBMODULE_STRATEGY: "recursive"
    OAUTHLIB_INSECURE_TRANSPORT: "true"
Mart van Santen's avatar
Mart van Santen committed
    # For login panel
    FLASK_RUN_HOST: "0.0.0.0"
    FLASK_RUN_PORT: "5000"
    HYDRA_ADMIN_URL: "http://hydra:4445"
    KRATOS_PUBLIC_URL: "http://kratos:4433"
    KRATOS_ADMIN_URL: "http://kratos:4434"
    PUBLIC_URL: "http://localhost:5000/"
Mart van Santen's avatar
Mart van Santen committed
    DATABASE_URL: "postgres://postgres:postgres@postgres/postgres"
    # For hydra & kratos
    # For hydra
    URLS_SELF_ISSUER: http://localhost/
    URLS_CONSENT: http://oidc:5000/login
    URLS_LOGIN: http://oidc:5000/consent
    # For postgres image
Mart van Santen's avatar
Mart van Santen committed
    POSTGRES_PASSWORD: postgres
    POSTGRES_USER: postgres
    POSTGRES_DB: postgres
    # General flask
    DEBUG: "true"
    FLASK_ENV: "development"
    # Others and old
Mark's avatar
Mark committed
    BASE_URL: "http://hydra:4444/"
Mark's avatar
Mark committed
    HYDRA_ADMIN_URL: "http://hydra:4445"
Mark's avatar
Mark committed
    ACCESS_TOKEN_URL: "http://hydra:4444/oauth2/token"
    AUTHORIZE_URL: "http://hydra:4444/oauth2/auth"
    USERINFO_URL: "http://hydra:4444/userinfo"
Mark's avatar
Mark committed
    KEY: "testapp"
    SECRET: "secret"
Mart van Santen's avatar
Mart van Santen committed
  image: ${CI_REGISTRY_IMAGE}/behave:${CI_COMMIT_REF_NAME}
Mark's avatar
Mark committed
  script:
Mart van Santen's avatar
Mart van Santen committed
    - sleep 30
Mart van Santen's avatar
Mart van Santen committed
    - curl http://hydra:4445/health/alive
    - curl http://kratos:4433/health/alive
    - curl http://oidc:5000/status
    # Steps to do:
    # - create user & access roles & grant access
    # - add client applition ID + key for testing
    # - test login etc

Mark's avatar
Mark committed
  artifacts:
    paths:
Mark's avatar
Mark committed
      - test/integration_tests/test/behave/screenshots/
Mark's avatar
Mark committed
    expire_in: 1 month
    when: on_failure
# TODO: Fix https://open.greenhost.net/stackspin/single-sign-on/-/issues/82
#
# pylint-lint:
#   stage: lint
#   variables:
#     GIT_AUTHOR_NAME: "RUNNER"
#     GIT_AUTHOR_EMAIL: "runner@greenhost.net"
#     PYLINT_PLUGINS: "pylint_flask pylint_flask_sqlalchemy"
#   image: ${CI_REGISTRY_IMAGE}/pylint:${CI_COMMIT_REF_NAME}
#   script:
#     - echo "Reverting back to main to squash commits"
#     - git reset --soft main