-
Notifications
You must be signed in to change notification settings - Fork 582
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add jib-maven 0.3 with certficate support for registry #691
Conversation
Catlin Output
|
/retest |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Diff for others to look at :
https://paste.gg/p/anonymous/49c36f4075224ea3b242c7003d2fef7d
script: | | ||
#!/bin/sh | ||
|
||
[[ -f /etc/ssl/certs/$(params.CACERTFILE) ]] && \ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
$(workspaces.sscertdir.path)
?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In case of scenarios, like user did not specify workspace but the operator is mounting the cert in taskrun pod, then this is not getting applied, so made it by explicitly specifying the path
workingDir: $(workspaces.source.path)/$(params.DIRECTORY) | ||
env: | ||
- name: HOME | ||
value: /workspace |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do you need to do this ? This usually can get problematic to redefine HOME generally speaking...
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This I just made the same as the previous version. If this is not required I can remove it. Task working fine without this also c @chanseokoh
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
PR which added this #407
TMD=$(mktemp -d) | ||
|
||
# Generate SSL Certificate | ||
openssl req -newkey rsa:4096 -nodes -sha256 -keyout "${TMD}"/ca.key -x509 -days 365 \ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
we should probably make that as default for add_sidecar_registry or add it as a add_sidecar_secure_registry if that's problematics for other tasks...
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sure, I can add a new func for secure registry and use that in all tasks, maybe will handle it in different PR with changes in all tasks
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have done the changes in the same PR now
reason for failure |
05acf9d
to
aaaeaf4
Compare
Catlin Output
|
aaaeaf4
to
7dcb644
Compare
This will add jib-maven 0.3 version with support for providing cert file to talk to insecure registry Fix tektoncd#686
7dcb644
to
3688c2b
Compare
/test pull-catalog-catlin-lint |
3688c2b
to
579f9bc
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: vdemeester The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
/lgtm thanks |
There is the documentation to update tho to add that new add_sidecar_secure_registry, any chances you can update it ? /hold |
/test pull-catalog-catlin-lint |
1 similar comment
/test pull-catalog-catlin-lint |
Catlin Output
|
Created a function to run secure sidecar registry with cert and calling that function from all tests to remove duplication
579f9bc
to
20299cf
Compare
Catlin Output
|
/hold cancel /lgtm thanks |
/test pull-tekton-catalog-integration-tests |
catlin.txt |
/test pull-tekton-catalog-integration-tests |
Error
|
catlin.txt |
/retest |
This will add jib-maven 0.3 version with support for providing cert file
to talk to insecure registry
Fix #686
Submitter Checklist
These are the criteria that every PR should meet, please check them off as you
review them:
File path follows
<kind>/<name>/<version>/name.yaml
Has
README.md
at<kind>/<name>/<version>/README.md
Has mandatory
metadata.labels
-app.kubernetes.io/version
the same as the<version>
of the resourceHas mandatory
metadata.annotations
tekton.dev/pipelines.minVersion
mandatory
spec.description
follows the conventionSee the contribution guide
for more details.