Skip to content

Commit

Permalink
Merge branch 'master' of github.com:codefresh-io/steps into CR-20802
Browse files Browse the repository at this point in the history
  • Loading branch information
kim-codefresh committed Feb 12, 2024
2 parents 7e51071 + c791f9c commit 7e30fc6
Show file tree
Hide file tree
Showing 13 changed files with 412 additions and 38 deletions.
4 changes: 4 additions & 0 deletions incubating/argo-cd-sync/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Changelog

## [1.4.2] - 2024-01-17
### Changed
New graphql call to speed up query

## [1.4.1] - 2023-10-31
### Changed
Add CA_BUNDLE option
Expand Down
44 changes: 21 additions & 23 deletions incubating/argo-cd-sync/argocd_sync.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@
CF_URL = os.getenv('CF_URL', 'https://g.codefresh.io')
CF_API_KEY = os.getenv('CF_API_KEY')
CF_STEP_NAME= os.getenv('CF_STEP_NAME', 'STEP_NAME')
LOG_LEVEL = os.getenv('LOG_LEVEL', "info")
LOG_LEVEL = os.getenv('LOG_LEVEL', "error")

# Check the certificate or not accessing the API endpoint
VERIFY = True if os.getenv('INSECURE', "False").lower() == "false" else False
Expand Down Expand Up @@ -50,24 +50,24 @@ def main():
ingress_host = get_runtime_ingress_host()
execute_argocd_sync(ingress_host)
namespace=get_runtime_ns()
status = get_app_status(namespace)
status = get_app_status(ingress_host)

if WAIT_HEALTHY:
status=waitHealthy (namespace)
status=waitHealthy (ingress_host)

# if Wait failed, it's time for rollback
if status != "HEALTHY" and ROLLBACK:
logging.info("Application '%s' did not sync properly. Initiating rollback ", APPLICATION)
revision = getRevision(namespace)
logging.info("latest healthy revision is %d", revision)
logging.info("Latest healthy revision is %d", revision)

rollback(ingress_host, namespace, revision)
logging.info("Waiting for rollback to happen")
if WAIT_ROLLBACK:
status=waitHealthy (namespace)
status=waitHealthy (ingress_host)
else:
time.sleep(INTERVAL)
status=get_app_status(namespace)
status=get_app_status(ingress_host)
else:
export_variable('ROLLBACK_EXECUTED', "false")
else:
Expand Down Expand Up @@ -108,7 +108,7 @@ def getRevision(namespace):
}
}
result = client.execute(query, variable_values=variables)
logging.info(result)
logging.debug("getRevision result: %s", result)

loop=0
revision = -1
Expand All @@ -124,18 +124,18 @@ def getRevision(namespace):
loop += 1
# we did not find a HEALTHY one in our page
export_variable('ROLLBACK_EXECUTED', "false")
logging.error("Did not find a HEALTHY release among the lat %d", PAGE_SIZE)
logging.error("Did not find a HEALTHY release among the last %d", PAGE_SIZE)
sys.exit(1)

def waitHealthy (namespace):
logging.debug ("Entering waitHealthy (ns: %s)", namespace)
def waitHealthy (ingress_host):
logging.debug ("Entering waitHealthy (ns: %s)", ingress_host)

time.sleep(INTERVAL)
status = get_app_status(namespace)
status = get_app_status(ingress_host)
logging.info("App status is %s", status)
loop=0
while status != "HEALTHY" and loop < MAX_CHECKS:
status=get_app_status(namespace)
status=get_app_status(ingress_host)
time.sleep(INTERVAL)
logging.info("App status is %s after %d checks", status, loop)
loop += 1
Expand All @@ -160,15 +160,15 @@ def rollback(ingress_host, namespace, revision):
"dryRun": False,
"prune": True
}
logging.info("Rollback app: %s", variables)
logging.debug("Rollback variables: %s", variables)
result = client.execute(query, variable_values=variables)
logging.info(result)
logging.debug("Rollback result: %s", result)
export_variable('ROLLBACK_EXECUTED', "true")


def get_app_status(namespace):
def get_app_status(ingress_host):
## Get the health status of the app
gql_api_endpoint = CF_URL + '/2.0/api/graphql'
gql_api_endpoint = ingress_host + '/app-proxy/api/graphql'
transport = RequestsHTTPTransport(
url=gql_api_endpoint,
headers={'authorization': CF_API_KEY},
Expand All @@ -178,13 +178,12 @@ def get_app_status(namespace):
client = Client(transport=transport, fetch_schema_from_transport=False)
query = get_query('get_app_status') ## gets gql query
variables = {
"runtime": RUNTIME,
"name": APPLICATION,
"namespace": namespace
"name": APPLICATION
}
result = client.execute(query, variable_values=variables)

health = result['application']['healthStatus']
logging.debug("App Status result: %s", result)
health = result['applicationProxyQuery']['status']['health']['status']
return health

def get_query(query_name):
Expand Down Expand Up @@ -245,9 +244,8 @@ def execute_argocd_sync(ingress_host):
"prune": True
}
}
logging.info("Syncing app: %s", variables)
result = client.execute(query, variable_values=variables)
logging.info(result)
logging.debug("Syncing App result: %s", result)


def export_variable(var_name, var_value):
Expand All @@ -260,7 +258,7 @@ def export_variable(var_name, var_value):
with open('/meta/env_vars_to_export', 'a') as a_writer:
a_writer.write(var_name + "=" + var_value+'\n')

logging.info("Exporting variable: %s=%s", var_name, var_value)
logging.debug("Exporting variable: %s=%s", var_name, var_value)

##############################################################

Expand Down
25 changes: 12 additions & 13 deletions incubating/argo-cd-sync/queries/get_app_status.graphql
Original file line number Diff line number Diff line change
@@ -1,18 +1,17 @@
query ApplicationsStatusesQuery(
$runtime: String!
$name: String!
$namespace: String
) {
application(runtime: $runtime, name: $name, namespace: $namespace) {
query appstatus ($name: String!) {
applicationProxyQuery(
name: $name
){
metadata {
runtime
name
namespace
cluster
__typename
}
healthStatus
syncStatus
syncPolicy
status {
health {
status
}
sync {
status
}
}
}
}
18 changes: 18 additions & 0 deletions incubating/argo-cd-sync/queries/get_app_status.orig.graphql
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
query ApplicationsStatusesQuery(
$runtime: String!
$name: String!
$namespace: String
) {
application(runtime: $runtime, name: $name, namespace: $namespace) {
metadata {
runtime
name
namespace
cluster
__typename
}
healthStatus
syncStatus
syncPolicy
}
}
4 changes: 2 additions & 2 deletions incubating/argo-cd-sync/step.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
kind: step-type
metadata:
name: argo-cd-sync
version: 1.4.1
version: 1.4.2
isPublic: true
description: Syncs Argo CD apps managed by our GitOps Runtimes
sources:
Expand Down Expand Up @@ -120,7 +120,7 @@ spec:
},
"IMAGE_TAG": {
"type": "string",
"default": "1.3.1",
"default": "1.4.2",
"description": "OPTIONAL - To overwrite the tag to use"
}
}
Expand Down
9 changes: 9 additions & 0 deletions incubating/aws-sts-assume-role-with-web-identity/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
FROM python:alpine

# using same aws-cli that was used before moving to quay images to prevent regressions
ARG CLI_VERSION=1.16.284

RUN apk -uv add --no-cache groff jq less && \
pip install --no-cache-dir awscli==$CLI_VERSION

WORKDIR /aws
5 changes: 5 additions & 0 deletions incubating/kubescape/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# Changelog

## [1.0.0] - 2024-01-22

Original version
8 changes: 8 additions & 0 deletions incubating/kubescape/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
FROM quay.io/kubescape/kubescape-cli:v3.0.1

# Kubescape uses root privileges for writing the results to a file
USER root

COPY entrypoint.sh /entrypoint.sh

ENTRYPOINT ["/entrypoint.sh"]
11 changes: 11 additions & 0 deletions incubating/kubescape/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# kubescape CLI

Docker image which invokes security script using kubescape CLI

### Prerequisites:

Codefresh Subscription (Dedicated Infrastructure/Hybrid) - https://codefresh.io/

### Documentation:

kubescape CLI: https://github.com/kubescape/kubescape/blob/master/docs/getting-started.md
Loading

0 comments on commit 7e30fc6

Please sign in to comment.