diff --git a/.tekton/hwlab-nc01-v03-pac.yaml b/.tekton/hwlab-nc01-v03-pac.yaml index 45ade9db..02faf270 100644 --- a/.tekton/hwlab-nc01-v03-pac.yaml +++ b/.tekton/hwlab-nc01-v03-pac.yaml @@ -9,7 +9,7 @@ metadata: pipelinesascode.tekton.dev/on-cel-expression: "event == 'push' && target_branch == 'v0.3' && node == 'NC01'" pipelinesascode.tekton.dev/max-keep-runs: "8" unidesk.ai/owning-config-ref: "config/hwlab-node-lanes.yaml#lanes.v03.targets.NC01" - unidesk.ai/effective-config-sha256: sha256:885e9277542653c730816208d4a0607dae143ce9b07fb68a108e9539428162b6 + unidesk.ai/effective-config-sha256: sha256:f42181ba9c079806968bb8374967a2bc710c7a87b56030d512cc00c004be126b unidesk.ai/source-artifact-renderer: hwlab-runtime-lane unidesk.ai/source-artifact-mode: remote-pipeline-annotation pipelinesascode.tekton.dev/pipeline: ci/pipelines/hwlab-nc01-v03-ci-image-publish.yaml diff --git a/ci/pipelines/hwlab-nc01-v03-ci-image-publish.yaml b/ci/pipelines/hwlab-nc01-v03-ci-image-publish.yaml index 5244618f..4052f72d 100644 --- a/ci/pipelines/hwlab-nc01-v03-ci-image-publish.yaml +++ b/ci/pipelines/hwlab-nc01-v03-ci-image-publish.yaml @@ -7,9 +7,9 @@ metadata: app.kubernetes.io/part-of: hwlab hwlab.pikastech.local/gitops-target: v03 annotations: - hwlab.pikastech.local/source-config: "scripts/gitops-render.mjs#tekton-native-primitive-ci" - hwlab.pikastech.local/ci-contract: tekton-native-primitive-tasks - hwlab.pikastech.local/policy: native-per-service-taskrun-image-publish + hwlab.pikastech.local/source-config: "scripts/gitops-render.mjs#bounded-release-taskruns" + hwlab.pikastech.local/ci-contract: plan-build-release-taskruns + hwlab.pikastech.local/policy: reviewed-plan-exact-scope hwlab.pikastech.local/download-profile: jd01-node-default hwlab.pikastech.local/network-profile: jd01-node-ci-egress unidesk.ai/ci-resource-governance-config-ref: "config/hwlab-node-lanes.yaml#lanes.v03.targets.NC01.ciResourceGovernance" @@ -19,7 +19,7 @@ metadata: unidesk.ai/ci-build-batch-count: "9" unidesk.ai/ci-build-max-parallel: "2" unidesk.ai/owning-config-ref: "config/hwlab-node-lanes.yaml#lanes.v03.targets.NC01" - unidesk.ai/effective-config-sha256: sha256:885e9277542653c730816208d4a0607dae143ce9b07fb68a108e9539428162b6 + unidesk.ai/effective-config-sha256: sha256:f42181ba9c079806968bb8374967a2bc710c7a87b56030d512cc00c004be126b unidesk.ai/source-artifact-renderer: hwlab-runtime-lane unidesk.ai/source-artifact-mode: remote-pipeline-annotation spec: @@ -91,7 +91,7 @@ spec: - name: source - name: gitea-auth tasks: - - name: prepare-source + - name: plan-artifacts workspaces: - name: source workspace: source @@ -108,264 +108,6 @@ spec: - name: registry-prefix - name: services - name: revision - workspaces: - - name: source - steps: - - name: prepare-source - image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 - env: - - name: HTTP_PROXY - value: http://127.0.0.1:10808 - - name: HTTPS_PROXY - value: http://127.0.0.1:10808 - - name: ALL_PROXY - value: http://127.0.0.1:10808 - - name: NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: http_proxy - value: http://127.0.0.1:10808 - - name: https_proxy - value: http://127.0.0.1:10808 - - name: all_proxy - value: http://127.0.0.1:10808 - - name: no_proxy - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: HWLAB_NODE_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_ALL_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,hyueapi.com,.hyueapi.com" - - name: HOME - value: /tekton/home - - name: XDG_CONFIG_HOME - value: /tekton/home/.config - script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\nci_now_ms() {\n node -e 'console.log(Date.now())'\n}\n\nci_timing_emit() {\n stage=\"$1\"\n status=\"$2\"\n started_ms=\"$3\"\n finished_ms=\"$(ci_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n service_id=\"${HWLAB_TIMING_SERVICE_ID:-}\"\n node -e 'const [stage,status,durationMs,serviceId]=process.argv.slice(1); const payload={event:\"node-cicd-timing\",schemaVersion:\"v1\",stage,status,durationMs:Number(durationMs),pipelineRun:process.env.HWLAB_TEKTON_PIPELINERUN||null,taskRun:process.env.HWLAB_TEKTON_TASKRUN||null,task:process.env.HWLAB_TEKTON_TASK||null,revision:process.env.HWLAB_SOURCE_REVISION||null,serviceId:serviceId||null,source:\"scripts/gitops-render.mjs\",at:new Date().toISOString()}; console.log(JSON.stringify(payload));' \"$stage\" \"$status\" \"$duration_ms\" \"$service_id\"\n}\ngit_now_ms() {\n node -e 'console.log(Date.now())' 2>/dev/null || date +%s000\n}\n\ngit_timed() {\n phase=\"$1\"\n timeout_seconds=\"$2\"\n shift 2\n started_ms=\"$(git_now_ms)\"\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"started\",\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n set +e\n timeout \"$timeout_seconds\" \"$@\"\n status=\"$?\"\n set -e\n finished_ms=\"$(git_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n if [ \"$status\" -eq 0 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"succeeded\",\"durationMs\":'\"$duration_ms\"'}' >&2\n return 0\n fi\n if [ \"$status\" -eq 124 ] || [ \"$status\" -eq 137 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"reason\":\"timeout\",\"durationMs\":'\"$duration_ms\"',\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n else\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"exitCode\":'\"$status\"',\"durationMs\":'\"$duration_ms\"'}' >&2\n fi\n return \"$status\"\n}\n\nexport HWLAB_TEKTON_PIPELINERUN=\"$(context.pipelineRun.name)\"\nexport HWLAB_TEKTON_TASKRUN=\"$(context.taskRun.name)\"\nexport HWLAB_TEKTON_TASK=\"prepare-source\"\nexport HWLAB_SOURCE_REVISION=\"$(params.revision)\"\necho '{\"event\":\"ci-base-image\",\"phase\":\"prepare-source\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apk\"}'\nfor tool in node git timeout; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\nnode -e 'console.log(JSON.stringify({event:\"ci-base-image\",phase:\"prepare-source\",ok:true,node:process.version}))'\ngit_read_url=\"$(params.git-read-url)\"\ngitops_read_url=\"$(params.gitops-read-url)\"\nrm -rf /workspace/source/repo\nsource_clone_started_ms=\"$(ci_now_ms)\"\ngit_timed source-clone 180 git clone --branch \"$(params.source-branch)\" \"$git_read_url\" /workspace/source/repo\ncd /workspace/source/repo\ngit config --global --add safe.directory /workspace/source/repo\ngit remote set-url origin \"$git_read_url\"\ngit checkout \"$(params.revision)\"\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\ngit merge-base --is-ancestor \"$(params.revision)\" \"origin/$(params.source-branch)\" || { echo '{\"event\":\"source-ancestry\",\"status\":\"failed\",\"revision\":\"'\"$(params.revision)\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\"}'; exit 32; }\nci_timing_emit source-clone succeeded \"$source_clone_started_ms\"\nprepare_source_dependencies_started_ms=\"$(ci_now_ms)\"\necho '{\"event\":\"prepare-source-dependencies\",\"status\":\"skipped\",\"reason\":\"renderer-dependency-install-disabled\",\"dependency\":\"yaml\"}'\nci_timing_emit prepare-source-dependencies succeeded \"$prepare_source_dependencies_started_ms\"\ncatalog_path=\"$(params.catalog-path)\"\nmkdir -p \"$(dirname \"$catalog_path\")\"\ncatalog_fetch_started_ms=\"$(ci_now_ms)\"\nif git_timed catalog-ls-remote 45 git ls-remote --exit-code --heads \"$gitops_read_url\" \"$(params.gitops-branch)\" >/dev/null; then\n git remote set-url gitops-catalog \"$gitops_read_url\" 2>/dev/null || git remote add gitops-catalog \"$gitops_read_url\"\n git_timed catalog-fetch 90 git fetch --depth 1 gitops-catalog \"$(params.gitops-branch)\" >/dev/null || true\n if git cat-file -e FETCH_HEAD:\"$catalog_path\" 2>/dev/null; then\n git show FETCH_HEAD:\"$catalog_path\" > /tmp/hwlab-gitops-artifact-catalog.json\n if node --input-type=module - /tmp/hwlab-gitops-artifact-catalog.json deploy/deploy.yaml \"$(params.services)\" <<'NODE'\nimport fs from \"node:fs\";\nconst [catalogPath, deployPath, selectedServices] = process.argv.slice(2);\nconst ids = (doc) => (doc.services || []).map((service) => service.serviceId).filter(Boolean);\nconst topLevelServiceIds = (text) => {\n const values = [];\n let inServices = false;\n for (const line of text.split(/\\r?\\n/u)) {\n if (/^services:\\s*$/u.test(line)) { inServices = true; continue; }\n if (!inServices) continue;\n if (/^\\S/u.test(line)) break;\n const match = line.match(/^\\s*-\\s+serviceId:\\s*['\"]?([^'\"#\\s]+)['\"]?/u);\n if (match) values.push(match[1]);\n }\n return values;\n};\nconst selected = (selectedServices || \"\").split(\",\").map((item) => item.trim()).filter(Boolean);\nconst uniqueSorted = (items) => [...new Set(items)].sort();\nconst gitops = JSON.parse(fs.readFileSync(catalogPath, \"utf8\"));\nconst expected = selected.length ? selected : topLevelServiceIds(fs.readFileSync(deployPath, \"utf8\"));\nconst actual = ids(gitops);\nconst expectedSet = uniqueSorted(expected);\nconst actualSet = uniqueSorted(actual);\nconst sameServices = expectedSet.length === actualSet.length && expectedSet.every((item, index) => item === actualSet[index]);\nif (!sameServices) {\n const missing = expectedSet.filter((item) => !actualSet.includes(item));\n const extra = actualSet.filter((item) => !expectedSet.includes(item));\n console.error(JSON.stringify({ event: \"gitops-artifact-catalog\", phase: \"prepare-source\", status: \"ignored-stale\", reason: \"service-ids-mismatch\", expected, actual, missing, extra }));\n process.exit(42);\n}\nNODE\n then\n cp /tmp/hwlab-gitops-artifact-catalog.json \"$catalog_path\"\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"loaded\",\"branch\":\"'\"$(params.gitops-branch)\"'\"}'\n else\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"ignored-stale\",\"reason\":\"service-ids-mismatch\",\"branch\":\"'\"$(params.gitops-branch)\"'\"}'\n fi\n else\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"seed\",\"reason\":\"missing-on-gitops-branch\"}'\n fi\nelse\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"seed\",\"reason\":\"gitops-branch-missing\"}'\nfi\nif [ ! -s \"$catalog_path\" ] && [ \"$(params.lane)\" = \"v02\" ]; then\n node --input-type=module - \"$catalog_path\" \"$(params.revision)\" \"$(params.registry-prefix)\" \"$(params.image-tag-mode)\" \"$(params.services)\" <<'NODE'\nimport fs from 'node:fs';\nimport path from 'node:path';\nconst [catalogPath, revision, registryPrefix, imageTagMode, selectedServices] = process.argv.slice(2);\nconst topLevelServiceIds = (text) => {\n const values = [];\n let inServices = false;\n for (const line of text.split(/\\r?\\n/u)) {\n if (/^services:\\s*$/u.test(line)) { inServices = true; continue; }\n if (!inServices) continue;\n if (/^\\S/u.test(line)) break;\n const match = line.match(/^\\s*-\\s+serviceId:\\s*['\"]?([^'\"#\\s]+)['\"]?/u);\n if (match) values.push(match[1]);\n }\n return values;\n};\nconst tag = imageTagMode === 'full' ? revision : revision.slice(0, 7);\nconst namespace = 'hwlab-v02';\nconst selected = (selectedServices || '').split(',').filter(Boolean);\nconst serviceIds = selected.length ? selected : topLevelServiceIds(fs.readFileSync('deploy/deploy.yaml', 'utf8'));\nconst services = serviceIds.map((serviceId) => {\n const service = { serviceId, profile: 'v02', namespace, commitId: tag, sourceCommitId: revision, image: `${registryPrefix}/${serviceId}:${tag}`, imageTag: tag, digest: null, buildBackend: 'contract-skeleton' };\n return service;\n});\nfs.mkdirSync(path.dirname(catalogPath), { recursive: true });\nfs.writeFileSync(catalogPath, JSON.stringify({ catalogVersion: 'v1', kind: 'hwlab-artifact-catalog', environment: 'v02', profile: 'v02', namespace, endpoint: \"https://hwlab.74-48-78-17.nip.io\", commitId: tag, artifactState: 'contract-skeleton', publish: { registryPrefix, sourceCommitId: revision, imageTag: tag, publishedAt: null }, allowedProfiles: ['v02'], forbiddenProfiles: ['dev', 'prod'], services }, null, 2) + '\\n');\nNODE\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"seeded-v02-skeleton\"}'\nfi\nci_timing_emit catalog-fetch succeeded \"$catalog_fetch_started_ms\"\necho 'node prepare-source complete; validation task count=3'\n" - imagePullPolicy: Always - params: - - name: git-url - value: $(params.git-url) - - name: git-read-url - value: $(params.git-read-url) - - name: gitops-read-url - value: $(params.gitops-read-url) - - name: source-branch - value: $(params.source-branch) - - name: gitops-branch - value: $(params.gitops-branch) - - name: lane - value: $(params.lane) - - name: catalog-path - value: $(params.catalog-path) - - name: image-tag-mode - value: $(params.image-tag-mode) - - name: registry-prefix - value: $(params.registry-prefix) - - name: services - value: $(params.services) - - name: revision - value: $(params.revision) - - name: repo-reports-guard - runAfter: - - prepare-source - workspaces: - - name: source - workspace: source - taskSpec: - params: - - name: revision - - name: lane - - name: catalog-path - - name: image-tag-mode - - name: source-branch - - name: gitops-branch - workspaces: - - name: source - steps: - - name: repo-reports-guard - image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 - env: - - name: HTTP_PROXY - value: http://127.0.0.1:10808 - - name: HTTPS_PROXY - value: http://127.0.0.1:10808 - - name: ALL_PROXY - value: http://127.0.0.1:10808 - - name: NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: http_proxy - value: http://127.0.0.1:10808 - - name: https_proxy - value: http://127.0.0.1:10808 - - name: all_proxy - value: http://127.0.0.1:10808 - - name: no_proxy - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: HWLAB_NODE_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_ALL_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,hyueapi.com,.hyueapi.com" - - name: HOME - value: /tekton/home - - name: XDG_CONFIG_HOME - value: /tekton/home/.config - script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\ngit config --global --add safe.directory /workspace/source/repo\ncd /workspace/source/repo\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\nnode scripts/repo-reports-guard.mjs\n" - imagePullPolicy: Always - params: - - name: revision - value: $(params.revision) - - name: lane - value: $(params.lane) - - name: catalog-path - value: $(params.catalog-path) - - name: image-tag-mode - value: $(params.image-tag-mode) - - name: source-branch - value: $(params.source-branch) - - name: gitops-branch - value: $(params.gitops-branch) - - name: node-contract-check - runAfter: - - prepare-source - workspaces: - - name: source - workspace: source - taskSpec: - params: - - name: revision - - name: lane - - name: catalog-path - - name: image-tag-mode - - name: source-branch - - name: gitops-branch - workspaces: - - name: source - steps: - - name: node-contract-check - image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 - env: - - name: HTTP_PROXY - value: http://127.0.0.1:10808 - - name: HTTPS_PROXY - value: http://127.0.0.1:10808 - - name: ALL_PROXY - value: http://127.0.0.1:10808 - - name: NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: http_proxy - value: http://127.0.0.1:10808 - - name: https_proxy - value: http://127.0.0.1:10808 - - name: all_proxy - value: http://127.0.0.1:10808 - - name: no_proxy - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: HWLAB_NODE_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_ALL_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,hyueapi.com,.hyueapi.com" - - name: HOME - value: /tekton/home - - name: XDG_CONFIG_HOME - value: /tekton/home/.config - script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\ngit config --global --add safe.directory /workspace/source/repo\ncd /workspace/source/repo\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\nnode --check scripts/gitops-render.mjs\nnode --input-type=module <<'NODE'\nimport { readdirSync, readFileSync, statSync } from \"node:fs\";\nimport path from \"node:path\";\n\nconst root = process.cwd();\nconst ciFileName = \"CI\" + \".json\";\nconst forbiddenCiFragments = [\n \"ci\" + \"-json\",\n \"HWLAB_NODE_TEKTON\" + \"_SINGLE_IMAGE_PUBLISH\",\n \"single\" + \"-dind\",\n \"docker\" + \":29\",\n \"DOCKER\" + \"_HOST\",\n \"Docker\" + \"-in-Docker\",\n \"D\" + \"IND\",\n \"docker\" + \" push\",\n \"--build\" + \"-backend\",\n \"HWLAB_ARTIFACT\" + \"_BUILD_BACKEND\",\n \"--legacy\" + \"-source-images\",\n \"HWLAB_NODE_USE_DEPLOY_IMAGES\" + \"=0\"\n];\nconst scanTargets = [\n \"scripts/gitops-render.mjs\",\n \"scripts/src/runtime-lane.ts\",\n \"scripts/artifact-publish.mjs\",\n \"scripts/src/ci-plan-lib.mjs\",\n \"deploy/gitops/node/tekton\"\n];\nconst skipDirs = new Set([\".git\", \"node_modules\", \".worktree\"]);\n\nfunction walkFiles(relativePath) {\n const absolutePath = path.join(root, relativePath);\n let stat;\n try {\n stat = statSync(absolutePath);\n } catch {\n return [];\n }\n if (stat.isFile()) return [relativePath];\n if (!stat.isDirectory()) return [];\n const files = [];\n for (const entry of readdirSync(absolutePath, { withFileTypes: true })) {\n if (entry.isDirectory() && skipDirs.has(entry.name)) continue;\n files.push(...walkFiles(path.join(relativePath, entry.name)));\n }\n return files;\n}\n\nconst ciFiles = walkFiles(\".\").filter((filePath) => path.basename(filePath) === ciFileName);\nconst violations = [];\nfor (const filePath of scanTargets.flatMap(walkFiles)) {\n const text = readFileSync(path.join(root, filePath), \"utf8\");\n for (const fragment of forbiddenCiFragments) {\n if (text.includes(fragment)) violations.push({ filePath, fragment });\n }\n}\nif (ciFiles.length || violations.length) {\n console.error(JSON.stringify({ status: \"failed\", ciFiles, violations }, null, 2));\n process.exit(1);\n}\nNODE\nnode --check scripts/artifact-publish.mjs\n" - imagePullPolicy: Always - params: - - name: revision - value: $(params.revision) - - name: lane - value: $(params.lane) - - name: catalog-path - value: $(params.catalog-path) - - name: image-tag-mode - value: $(params.image-tag-mode) - - name: source-branch - value: $(params.source-branch) - - name: gitops-branch - value: $(params.gitops-branch) - - name: codex-api-forwarder-check - runAfter: - - prepare-source - workspaces: - - name: source - workspace: source - taskSpec: - params: - - name: revision - - name: lane - - name: catalog-path - - name: image-tag-mode - - name: source-branch - - name: gitops-branch - workspaces: - - name: source - steps: - - name: codex-api-forwarder-check - image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 - env: - - name: HTTP_PROXY - value: http://127.0.0.1:10808 - - name: HTTPS_PROXY - value: http://127.0.0.1:10808 - - name: ALL_PROXY - value: http://127.0.0.1:10808 - - name: NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: http_proxy - value: http://127.0.0.1:10808 - - name: https_proxy - value: http://127.0.0.1:10808 - - name: all_proxy - value: http://127.0.0.1:10808 - - name: no_proxy - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" - - name: HWLAB_NODE_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_ALL_PROXY_URL - value: http://127.0.0.1:10808 - - name: HWLAB_NODE_NO_PROXY - value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,hyueapi.com,.hyueapi.com" - - name: HOME - value: /tekton/home - - name: XDG_CONFIG_HOME - value: /tekton/home/.config - script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\ngit config --global --add safe.directory /workspace/source/repo\ncd /workspace/source/repo\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\nnode scripts/run-bun.mjs test cmd/hwlab-codex-api-responses-forwarder/main.test.ts\n" - imagePullPolicy: Always - params: - - name: revision - value: $(params.revision) - - name: lane - value: $(params.lane) - - name: catalog-path - value: $(params.catalog-path) - - name: image-tag-mode - value: $(params.image-tag-mode) - - name: source-branch - value: $(params.source-branch) - - name: gitops-branch - value: $(params.gitops-branch) - - name: plan-artifacts - runAfter: - - repo-reports-guard - - node-contract-check - - codex-api-forwarder-check - workspaces: - - name: source - workspace: source - taskSpec: - params: - - name: git-url - - name: gitops-read-url - - name: gitops-branch - - name: lane - - name: revision - - name: catalog-path - - name: registry-prefix - - name: services - name: release-base-commit - name: release-target - name: release-consumer @@ -439,9 +181,42 @@ spec: description: hwlab-agent-skills rollout affected according to ci-plan - name: build-hwlab-agent-skills description: hwlab-agent-skills image build required according to ci-plan + - name: build-required + description: true when at least one planned service image must be built workspaces: - name: source steps: + - name: prepare-source + image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 + env: + - name: HTTP_PROXY + value: http://127.0.0.1:10808 + - name: HTTPS_PROXY + value: http://127.0.0.1:10808 + - name: ALL_PROXY + value: http://127.0.0.1:10808 + - name: NO_PROXY + value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" + - name: http_proxy + value: http://127.0.0.1:10808 + - name: https_proxy + value: http://127.0.0.1:10808 + - name: all_proxy + value: http://127.0.0.1:10808 + - name: no_proxy + value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,kubernetes,kubernetes.default,kubernetes.default.svc,10.0.0.0/8,10.42.0.0/16,10.43.0.0/16,172.16.0.0/12,192.168.0.0/16,82.156.23.220,74.48.78.17,hyueapi.com,.hyueapi.com" + - name: HWLAB_NODE_PROXY_URL + value: http://127.0.0.1:10808 + - name: HWLAB_NODE_ALL_PROXY_URL + value: http://127.0.0.1:10808 + - name: HWLAB_NODE_NO_PROXY + value: "localhost,127.0.0.1,::1,127.0.0.1:5000,localhost:5000,.svc,.svc.cluster.local,.cluster.local,hyueapi.com,.hyueapi.com" + - name: HOME + value: /tekton/home + - name: XDG_CONFIG_HOME + value: /tekton/home/.config + script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\nci_now_ms() {\n node -e 'console.log(Date.now())'\n}\n\nci_timing_emit() {\n stage=\"$1\"\n status=\"$2\"\n started_ms=\"$3\"\n finished_ms=\"$(ci_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n service_id=\"${HWLAB_TIMING_SERVICE_ID:-}\"\n node -e 'const [stage,status,durationMs,serviceId]=process.argv.slice(1); const payload={event:\"node-cicd-timing\",schemaVersion:\"v1\",stage,status,durationMs:Number(durationMs),pipelineRun:process.env.HWLAB_TEKTON_PIPELINERUN||null,taskRun:process.env.HWLAB_TEKTON_TASKRUN||null,task:process.env.HWLAB_TEKTON_TASK||null,revision:process.env.HWLAB_SOURCE_REVISION||null,serviceId:serviceId||null,source:\"scripts/gitops-render.mjs\",at:new Date().toISOString()}; console.log(JSON.stringify(payload));' \"$stage\" \"$status\" \"$duration_ms\" \"$service_id\"\n}\ngit_now_ms() {\n node -e 'console.log(Date.now())' 2>/dev/null || date +%s000\n}\n\ngit_timed() {\n phase=\"$1\"\n timeout_seconds=\"$2\"\n shift 2\n started_ms=\"$(git_now_ms)\"\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"started\",\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n set +e\n timeout \"$timeout_seconds\" \"$@\"\n status=\"$?\"\n set -e\n finished_ms=\"$(git_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n if [ \"$status\" -eq 0 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"succeeded\",\"durationMs\":'\"$duration_ms\"'}' >&2\n return 0\n fi\n if [ \"$status\" -eq 124 ] || [ \"$status\" -eq 137 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"reason\":\"timeout\",\"durationMs\":'\"$duration_ms\"',\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n else\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"exitCode\":'\"$status\"',\"durationMs\":'\"$duration_ms\"'}' >&2\n fi\n return \"$status\"\n}\n\nexport HWLAB_TEKTON_PIPELINERUN=\"$(context.pipelineRun.name)\"\nexport HWLAB_TEKTON_TASKRUN=\"$(context.taskRun.name)\"\nexport HWLAB_TEKTON_TASK=\"prepare-source\"\nexport HWLAB_SOURCE_REVISION=\"$(params.revision)\"\necho '{\"event\":\"ci-base-image\",\"phase\":\"prepare-source\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apk\"}'\nfor tool in node git timeout; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\nnode -e 'console.log(JSON.stringify({event:\"ci-base-image\",phase:\"prepare-source\",ok:true,node:process.version}))'\ngit_read_url=\"$(params.git-read-url)\"\ngitops_read_url=\"$(params.gitops-read-url)\"\nrm -rf /workspace/source/repo\nsource_clone_started_ms=\"$(ci_now_ms)\"\ngit_timed source-clone 180 git clone --branch \"$(params.source-branch)\" \"$git_read_url\" /workspace/source/repo\ncd /workspace/source/repo\ngit config --global --add safe.directory /workspace/source/repo\ngit remote set-url origin \"$git_read_url\"\ngit checkout \"$(params.revision)\"\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\ngit merge-base --is-ancestor \"$(params.revision)\" \"origin/$(params.source-branch)\" || { echo '{\"event\":\"source-ancestry\",\"status\":\"failed\",\"revision\":\"'\"$(params.revision)\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\"}'; exit 32; }\nci_timing_emit source-clone succeeded \"$source_clone_started_ms\"\nprepare_source_dependencies_started_ms=\"$(ci_now_ms)\"\necho '{\"event\":\"prepare-source-dependencies\",\"status\":\"skipped\",\"reason\":\"renderer-dependency-install-disabled\",\"dependency\":\"yaml\"}'\nci_timing_emit prepare-source-dependencies succeeded \"$prepare_source_dependencies_started_ms\"\ncatalog_path=\"$(params.catalog-path)\"\nmkdir -p \"$(dirname \"$catalog_path\")\"\ncatalog_fetch_started_ms=\"$(ci_now_ms)\"\nif git_timed catalog-ls-remote 45 git ls-remote --exit-code --heads \"$gitops_read_url\" \"$(params.gitops-branch)\" >/dev/null; then\n git remote set-url gitops-catalog \"$gitops_read_url\" 2>/dev/null || git remote add gitops-catalog \"$gitops_read_url\"\n git_timed catalog-fetch 90 git fetch --depth 1 gitops-catalog \"$(params.gitops-branch)\" >/dev/null || true\n if git cat-file -e FETCH_HEAD:\"$catalog_path\" 2>/dev/null; then\n git show FETCH_HEAD:\"$catalog_path\" > /tmp/hwlab-gitops-artifact-catalog.json\n if node --input-type=module - /tmp/hwlab-gitops-artifact-catalog.json deploy/deploy.yaml \"$(params.services)\" <<'NODE'\nimport fs from \"node:fs\";\nconst [catalogPath, deployPath, selectedServices] = process.argv.slice(2);\nconst ids = (doc) => (doc.services || []).map((service) => service.serviceId).filter(Boolean);\nconst topLevelServiceIds = (text) => {\n const values = [];\n let inServices = false;\n for (const line of text.split(/\\r?\\n/u)) {\n if (/^services:\\s*$/u.test(line)) { inServices = true; continue; }\n if (!inServices) continue;\n if (/^\\S/u.test(line)) break;\n const match = line.match(/^\\s*-\\s+serviceId:\\s*['\"]?([^'\"#\\s]+)['\"]?/u);\n if (match) values.push(match[1]);\n }\n return values;\n};\nconst selected = (selectedServices || \"\").split(\",\").map((item) => item.trim()).filter(Boolean);\nconst uniqueSorted = (items) => [...new Set(items)].sort();\nconst gitops = JSON.parse(fs.readFileSync(catalogPath, \"utf8\"));\nconst expected = selected.length ? selected : topLevelServiceIds(fs.readFileSync(deployPath, \"utf8\"));\nconst actual = ids(gitops);\nconst expectedSet = uniqueSorted(expected);\nconst actualSet = uniqueSorted(actual);\nconst sameServices = expectedSet.length === actualSet.length && expectedSet.every((item, index) => item === actualSet[index]);\nif (!sameServices) {\n const missing = expectedSet.filter((item) => !actualSet.includes(item));\n const extra = actualSet.filter((item) => !expectedSet.includes(item));\n console.error(JSON.stringify({ event: \"gitops-artifact-catalog\", phase: \"prepare-source\", status: \"ignored-stale\", reason: \"service-ids-mismatch\", expected, actual, missing, extra }));\n process.exit(42);\n}\nNODE\n then\n cp /tmp/hwlab-gitops-artifact-catalog.json \"$catalog_path\"\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"loaded\",\"branch\":\"'\"$(params.gitops-branch)\"'\"}'\n else\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"ignored-stale\",\"reason\":\"service-ids-mismatch\",\"branch\":\"'\"$(params.gitops-branch)\"'\"}'\n fi\n else\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"seed\",\"reason\":\"missing-on-gitops-branch\"}'\n fi\nelse\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"seed\",\"reason\":\"gitops-branch-missing\"}'\nfi\nif [ ! -s \"$catalog_path\" ] && [ \"$(params.lane)\" = \"v02\" ]; then\n node --input-type=module - \"$catalog_path\" \"$(params.revision)\" \"$(params.registry-prefix)\" \"$(params.image-tag-mode)\" \"$(params.services)\" <<'NODE'\nimport fs from 'node:fs';\nimport path from 'node:path';\nconst [catalogPath, revision, registryPrefix, imageTagMode, selectedServices] = process.argv.slice(2);\nconst topLevelServiceIds = (text) => {\n const values = [];\n let inServices = false;\n for (const line of text.split(/\\r?\\n/u)) {\n if (/^services:\\s*$/u.test(line)) { inServices = true; continue; }\n if (!inServices) continue;\n if (/^\\S/u.test(line)) break;\n const match = line.match(/^\\s*-\\s+serviceId:\\s*['\"]?([^'\"#\\s]+)['\"]?/u);\n if (match) values.push(match[1]);\n }\n return values;\n};\nconst tag = imageTagMode === 'full' ? revision : revision.slice(0, 7);\nconst namespace = 'hwlab-v02';\nconst selected = (selectedServices || '').split(',').filter(Boolean);\nconst serviceIds = selected.length ? selected : topLevelServiceIds(fs.readFileSync('deploy/deploy.yaml', 'utf8'));\nconst services = serviceIds.map((serviceId) => {\n const service = { serviceId, profile: 'v02', namespace, commitId: tag, sourceCommitId: revision, image: `${registryPrefix}/${serviceId}:${tag}`, imageTag: tag, digest: null, buildBackend: 'contract-skeleton' };\n return service;\n});\nfs.mkdirSync(path.dirname(catalogPath), { recursive: true });\nfs.writeFileSync(catalogPath, JSON.stringify({ catalogVersion: 'v1', kind: 'hwlab-artifact-catalog', environment: 'v02', profile: 'v02', namespace, endpoint: \"https://hwlab.74-48-78-17.nip.io\", commitId: tag, artifactState: 'contract-skeleton', publish: { registryPrefix, sourceCommitId: revision, imageTag: tag, publishedAt: null }, allowedProfiles: ['v02'], forbiddenProfiles: ['dev', 'prod'], services }, null, 2) + '\\n');\nNODE\n echo '{\"event\":\"gitops-artifact-catalog\",\"phase\":\"prepare-source\",\"status\":\"seeded-v02-skeleton\"}'\nfi\nci_timing_emit catalog-fetch succeeded \"$catalog_fetch_started_ms\"\necho 'node prepare-source complete; validation task count=3'\n" + imagePullPolicy: Always - name: plan image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 env: @@ -477,25 +252,31 @@ spec: value: /tekton/home - name: XDG_CONFIG_HOME value: /tekton/home/.config - script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\necho '{\"event\":\"ci-base-image\",\"phase\":\"plan-artifacts\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apk\"}'\nfor tool in node git; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"phase\":\"plan-artifacts\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\ncd /workspace/source/repo\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps/yaml\" ] && [ ! -e node_modules/yaml ]; then\n mkdir -p node_modules\n ln -s \"$ci_node_deps/yaml\" node_modules/yaml\nfi\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\nHWLAB_CATALOG_PATH=\"$(params.catalog-path)\" HWLAB_GIT_URL=\"$(params.git-url)\" HWLAB_GIT_READ_URL=\"$(params.gitops-read-url)\" HWLAB_GITOPS_BRANCH=\"$(params.gitops-branch)\" HWLAB_SERVICES=\"$(params.services)\" node scripts/ci/restore-artifact-catalog.mjs\nnode scripts/ci-plan.mjs --lane \"$(params.lane)\" --base-ref \"$(params.release-base-commit)\" --target-ref HEAD --deploy-config deploy/deploy.yaml --artifact-catalog \"$(params.catalog-path)\" --registry-prefix \"$(params.registry-prefix)\" --services \"$(params.services)\" --release-target \"$(params.release-target)\" --release-consumer \"$(params.release-consumer)\" --verify-reuse-registry > /workspace/source/ci-plan.json\nnode scripts/ci/verify-reviewed-plan.mjs --actual-plan /workspace/source/ci-plan.json --reviewed-plan \"$(params.reviewed-plan)\"\nnode - <<'NODE'\nconst fs = require(\"node:fs\");\nconst plan = JSON.parse(fs.readFileSync(\"/workspace/source/ci-plan.json\", \"utf8\"));\nconst selected = String(process.env.HWLAB_SELECTED_SERVICES || \"\").split(\",\").map((item) => item.trim()).filter(Boolean);\nconst allServices = selected.length > 0 ? selected : [\"hwlab-cloud-api\",\"hwlab-cloud-web\",\"hwlab-gateway\",\"hwlab-edge-proxy\",\"hwlab-agent-skills\"];\nconst affected = new Set(plan.affectedServices || []);\nconst plannedBuildServices = Array.isArray(plan.buildServices) ? new Set(plan.buildServices) : null;\nconst selectedSet = new Set(selected);\nconst byService = new Map((plan.services || []).map((service) => [service.serviceId, service]));\nconst entries = allServices.map((serviceId) => {\n const service = byService.get(serviceId) || {};\n const serviceSelected = selectedSet.has(serviceId);\n const rolloutAffected = serviceSelected && affected.has(serviceId);\n const envReuse = service.runtimeMode === \"env-reuse-gitea-checkout\" || service.envReuse === true;\n const buildRequired = serviceSelected && (plannedBuildServices ? plannedBuildServices.has(serviceId) : (envReuse ? service.envChanged === true : rolloutAffected));\n return {\n serviceId,\n selected: serviceSelected,\n affected: rolloutAffected,\n buildRequired,\n rolloutAffected,\n runtimeMode: service.runtimeMode || \"service-image\",\n envChanged: service.envChanged ?? null,\n codeChanged: service.codeChanged ?? null\n };\n});\nfor (const entry of entries) {\n fs.writeFileSync(\"/tekton/results/affected-\" + entry.serviceId, entry.affected ? \"true\" : \"false\");\n fs.writeFileSync(\"/tekton/results/build-\" + entry.serviceId, entry.buildRequired ? \"true\" : \"false\");\n}\nfs.writeFileSync(\"/workspace/source/affected-services.json\", JSON.stringify({\n sourceCommitId: plan.sourceCommitId,\n planIdentity: plan.planIdentity || null,\n affectedServices: plan.affectedServices || [],\n rolloutServices: plan.rolloutServices || plan.affectedServices || [],\n buildServices: plan.buildServices || entries.filter((entry) => entry.buildRequired).map((entry) => entry.serviceId),\n rolloutWithoutImageBuildServices: plan.rolloutWithoutImageBuildServices || [],\n reusedServices: plan.reusedServices || [],\n serviceReusedCount: plan.serviceReusedCount || 0,\n imageBuildSkippedServices: plan.imageBuildSkippedServices || [],\n buildSkippedCount: plan.buildSkippedCount || 0,\n artifactCatalog: plan.artifactCatalog || null,\n envArtifactGroups: plan.envArtifactGroups || [],\n changedPathSummary: plan.changedPathSummary || null,\n ciCdPlan: plan.ciCdPlan || null,\n services: plan.services || [],\n entries\n}, null, 2) + String.fromCharCode(10));\nconsole.log(JSON.stringify({ event: \"g14-ci-plan\", sourceCommitId: plan.sourceCommitId, planIdentity: plan.planIdentity || null, affectedServices: plan.affectedServices || [], rolloutServices: plan.rolloutServices || plan.affectedServices || [], buildServices: plan.buildServices || [], rolloutWithoutImageBuildServices: plan.rolloutWithoutImageBuildServices || [], reusedServices: plan.reusedServices || [], serviceReusedCount: plan.serviceReusedCount || 0, imageBuildSkippedServices: plan.imageBuildSkippedServices || [], buildSkippedCount: plan.buildSkippedCount || 0, artifactCatalog: plan.artifactCatalog || null, noImageBuildReason: plan.ciCdPlan?.noImageBuildReason || null, envArtifactGroups: plan.envArtifactGroups || [] }));\nNODE\n" + script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\necho '{\"event\":\"ci-base-image\",\"phase\":\"plan-artifacts\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apk\"}'\nfor tool in node git; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"phase\":\"plan-artifacts\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\ncd /workspace/source/repo\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps/yaml\" ] && [ ! -e node_modules/yaml ]; then\n mkdir -p node_modules\n ln -s \"$ci_node_deps/yaml\" node_modules/yaml\nfi\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\nHWLAB_CATALOG_PATH=\"$(params.catalog-path)\" HWLAB_GIT_URL=\"$(params.git-url)\" HWLAB_GIT_READ_URL=\"$(params.gitops-read-url)\" HWLAB_GITOPS_BRANCH=\"$(params.gitops-branch)\" HWLAB_SERVICES=\"$(params.services)\" node scripts/ci/restore-artifact-catalog.mjs\nnode scripts/ci-plan.mjs --lane \"$(params.lane)\" --base-ref \"$(params.release-base-commit)\" --target-ref HEAD --deploy-config deploy/deploy.yaml --artifact-catalog \"$(params.catalog-path)\" --registry-prefix \"$(params.registry-prefix)\" --services \"$(params.services)\" --release-target \"$(params.release-target)\" --release-consumer \"$(params.release-consumer)\" --verify-reuse-registry > /workspace/source/ci-plan.json\nnode scripts/ci/verify-reviewed-plan.mjs --actual-plan /workspace/source/ci-plan.json --reviewed-plan \"$(params.reviewed-plan)\"\nnode - <<'NODE'\nconst fs = require(\"node:fs\");\nconst plan = JSON.parse(fs.readFileSync(\"/workspace/source/ci-plan.json\", \"utf8\"));\nconst selected = String(process.env.HWLAB_SELECTED_SERVICES || \"\").split(\",\").map((item) => item.trim()).filter(Boolean);\nconst allServices = selected.length > 0 ? selected : [\"hwlab-cloud-api\",\"hwlab-cloud-web\",\"hwlab-gateway\",\"hwlab-edge-proxy\",\"hwlab-agent-skills\"];\nconst affected = new Set(plan.affectedServices || []);\nconst plannedBuildServices = Array.isArray(plan.buildServices) ? new Set(plan.buildServices) : null;\nconst selectedSet = new Set(selected);\nconst byService = new Map((plan.services || []).map((service) => [service.serviceId, service]));\nconst entries = allServices.map((serviceId) => {\n const service = byService.get(serviceId) || {};\n const serviceSelected = selectedSet.has(serviceId);\n const rolloutAffected = serviceSelected && affected.has(serviceId);\n const envReuse = service.runtimeMode === \"env-reuse-gitea-checkout\" || service.envReuse === true;\n const buildRequired = serviceSelected && (plannedBuildServices ? plannedBuildServices.has(serviceId) : (envReuse ? service.envChanged === true : rolloutAffected));\n return {\n serviceId,\n selected: serviceSelected,\n affected: rolloutAffected,\n buildRequired,\n rolloutAffected,\n runtimeMode: service.runtimeMode || \"service-image\",\n envChanged: service.envChanged ?? null,\n codeChanged: service.codeChanged ?? null\n };\n});\nfs.writeFileSync(\"/tekton/results/build-required\", entries.some((entry) => entry.buildRequired) ? \"true\" : \"false\");\nfor (const entry of entries) {\n fs.writeFileSync(\"/tekton/results/affected-\" + entry.serviceId, entry.affected ? \"true\" : \"false\");\n fs.writeFileSync(\"/tekton/results/build-\" + entry.serviceId, entry.buildRequired ? \"true\" : \"false\");\n}\nfs.writeFileSync(\"/workspace/source/affected-services.json\", JSON.stringify({\n sourceCommitId: plan.sourceCommitId,\n planIdentity: plan.planIdentity || null,\n affectedServices: plan.affectedServices || [],\n rolloutServices: plan.rolloutServices || plan.affectedServices || [],\n buildServices: plan.buildServices || entries.filter((entry) => entry.buildRequired).map((entry) => entry.serviceId),\n rolloutWithoutImageBuildServices: plan.rolloutWithoutImageBuildServices || [],\n reusedServices: plan.reusedServices || [],\n serviceReusedCount: plan.serviceReusedCount || 0,\n imageBuildSkippedServices: plan.imageBuildSkippedServices || [],\n buildSkippedCount: plan.buildSkippedCount || 0,\n artifactCatalog: plan.artifactCatalog || null,\n envArtifactGroups: plan.envArtifactGroups || [],\n changedPathSummary: plan.changedPathSummary || null,\n ciCdPlan: plan.ciCdPlan || null,\n services: plan.services || [],\n entries\n}, null, 2) + String.fromCharCode(10));\nconsole.log(JSON.stringify({ event: \"g14-ci-plan\", sourceCommitId: plan.sourceCommitId, planIdentity: plan.planIdentity || null, affectedServices: plan.affectedServices || [], rolloutServices: plan.rolloutServices || plan.affectedServices || [], buildServices: plan.buildServices || [], rolloutWithoutImageBuildServices: plan.rolloutWithoutImageBuildServices || [], reusedServices: plan.reusedServices || [], serviceReusedCount: plan.serviceReusedCount || 0, imageBuildSkippedServices: plan.imageBuildSkippedServices || [], buildSkippedCount: plan.buildSkippedCount || 0, artifactCatalog: plan.artifactCatalog || null, noImageBuildReason: plan.ciCdPlan?.noImageBuildReason || null, envArtifactGroups: plan.envArtifactGroups || [] }));\nNODE\n" imagePullPolicy: Always params: - name: git-url value: $(params.git-url) + - name: git-read-url + value: $(params.git-read-url) - name: gitops-read-url value: $(params.gitops-read-url) + - name: source-branch + value: $(params.source-branch) - name: gitops-branch value: $(params.gitops-branch) - name: lane value: $(params.lane) - - name: revision - value: $(params.revision) - name: catalog-path value: $(params.catalog-path) + - name: image-tag-mode + value: $(params.image-tag-mode) - name: registry-prefix value: $(params.registry-prefix) - name: services value: $(params.services) + - name: revision + value: $(params.revision) - name: release-base-commit value: $(params.release-base-commit) - name: release-target @@ -510,6 +291,11 @@ spec: workspaces: - name: source workspace: source + when: + - input: $(tasks.plan-artifacts.results.build-required) + operator: in + values: + - "true" taskSpec: params: - name: revision @@ -686,12 +472,14 @@ spec: - name: services value: $(params.services) timeout: 20m - - name: collect-artifacts + - name: release-artifacts runAfter: - build-services workspaces: - name: source workspace: source + - name: gitea-auth + workspace: gitea-auth taskSpec: params: - name: revision @@ -701,8 +489,20 @@ spec: - name: registry-prefix - name: services - name: base-image + - name: git-url + - name: git-read-url + - name: gitops-read-url + - name: git-write-url + - name: gitops-username + - name: source-branch + - name: gitops-branch + - name: runtime-path + results: + - name: runtime-ready-required + description: true when GitOps promotion changed runtime desired state and runtime readiness must be observed workspaces: - name: source + - name: gitea-auth steps: - name: collect image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 @@ -735,51 +535,6 @@ spec: value: /tekton/home/.config script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\necho '{\"event\":\"ci-base-image\",\"phase\":\"collect-artifacts\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apk\"}'\nfor tool in node git; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"phase\":\"collect-artifacts\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\ncd /workspace/source/repo\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\nexport HWLAB_CI_ARTIFACT_RUN_ID=\"$(context.pipelineRun.name)-collect\"\nexport HWLAB_CI_ARTIFACT_RUN_OWNER=\"tekton\"\nexport HWLAB_DEV_REGISTRY_PREFIX=\"$(params.registry-prefix)\"\nexport HWLAB_DEV_REGISTRY_K8S_NATIVE=1\nif [ -n \"$(params.base-image)\" ]; then export HWLAB_DEV_BASE_IMAGE=\"$(params.base-image)\"; fi\nexport HWLAB_ARTIFACT_LANE=\"$(params.lane)\"\nexport HWLAB_ARTIFACT_CATALOG_PATH=\"$(params.catalog-path)\"\nexport HWLAB_DEPLOY_MANIFEST_PATH=\"deploy/deploy.yaml\"\nexport HWLAB_ARTIFACT_IMAGE_TAG_MODE=\"$(params.image-tag-mode)\"\nif [ -s /workspace/source/affected-services.json ] && node - /workspace/source/affected-services.json <<'NODE'\nconst fs = require(\"node:fs\");\nconst plan = JSON.parse(fs.readFileSync(process.argv[2], \"utf8\"));\nconst buildServices = Array.isArray(plan.buildServices) ? plan.buildServices : [];\nconst affectedServices = Array.isArray(plan.affectedServices) ? plan.affectedServices : [];\nconst willRunGitopsPromote = plan.ciCdPlan && plan.ciCdPlan.willRunGitopsPromote === true;\nprocess.exit(!willRunGitopsPromote && buildServices.length === 0 && affectedServices.length === 0 ? 0 : 1);\nNODE\nthen\n rm -f /workspace/source/dev-artifacts.json\n echo '{\"event\":\"collect-artifacts\",\"status\":\"skipped\",\"reason\":\"no-build-no-rollout-plan\"}'\n exit 0\nfi\nHWLAB_CI_PLAN_VERIFY_REUSE_REGISTRY=1 node - <<'NODE_UNIDESK_DEPLOY_YAML_OVERLAY'\nconst fs = require('fs');\nconst YAML = require('yaml');\nconst overlay = {\"nodeId\":\"NC01\",\"lane\":\"v03\",\"sourceBranch\":\"v0.3\",\"gitopsBranch\":\"v0.3-gitops\",\"gitopsRoot\":\"deploy/gitops/node/nc01\",\"runtimePath\":\"deploy/gitops/node/nc01/runtime-v03\",\"runtimeRenderDir\":\"runtime-v03\",\"runtimeNamespace\":\"hwlab-v03\",\"environment\":\"development\",\"catalogPath\":\"deploy/artifact-catalog.nc01-v03.json\",\"gitUrl\":\"git@github.com:pikasTech/HWLAB.git\",\"publicWebUrl\":\"https://lab-dev.hwpod.com\",\"publicApiUrl\":\"https://lab-dev.hwpod.com\",\"externalPostgres\":{\"enabled\":true,\"serviceName\":\"nc01-host-postgres\",\"endpointAddress\":\"10.42.0.1\",\"port\":5432,\"runtimeAccess\":{\"routeName\":\"nc01-host-postgres\",\"endpointAddress\":\"10.42.0.1\",\"port\":5432},\"sslmode\":\"require\"},\"runtimeStore\":{\"postgres\":{\"mode\":\"platform-service\",\"serviceName\":\"nc01-host-postgres\",\"poolMax\":16}},\"codeAgentRuntime\":{\"enabled\":true,\"adapter\":\"agentrun-v02\",\"managerUrl\":\"http://agentrun-mgr.agentrun-v02.svc.cluster.local:8080\",\"apiKeySecretName\":\"hwlab-v03-master-server-admin-api-key\",\"apiKeySecretKey\":\"api-key\",\"runnerNamespace\":\"agentrun-v02\",\"secretNamespace\":\"agentrun-v02\",\"providerSecretNames\":{\"codex\":\"agentrun-v01-provider-codex\",\"gpt-pika\":\"agentrun-v02-provider-gpt-pika\",\"grok\":\"agentrun-v02-provider-grok\",\"dsflash-go\":\"agentrun-v01-provider-dsflash-go\"},\"toolSecretNames\":{\"githubPr\":\"agentrun-v01-tool-github-pr\",\"unideskSsh\":\"agentrun-v01-tool-unidesk-ssh\"},\"repoUrlFrom\":\"runtimeGitReadUrl\",\"repoUrl\":\"http://gitea-http.devops-infra.svc.cluster.local:3000/mirrors/pikasTech-HWLAB.git\",\"providerIdFrom\":\"runtimeNodeId\",\"providerId\":\"NC01\",\"defaultProviderProfile\":\"gpt.pika\",\"codexStdioSupervisor\":\"repo-owned\",\"kafkaShadowProducer\":null,\"kafkaEventBridge\":{\"enabled\":true,\"features\":{\"directPublish\":true,\"liveKafkaSse\":true,\"kafkaRefreshReplay\":true,\"transactionalProjector\":false,\"projectionOutboxRelay\":false,\"projectionRealtime\":false},\"refreshReplay\":{\"groupIdPrefix\":\"hwlab-v03-cloud-api-sse\",\"timeoutMs\":30000,\"scanLimit\":1000000,\"matchedEventLimit\":2000,\"liveBufferLimit\":2000},\"configRef\":\"config/platform-infra/kafka.yaml#clients.hwlab-v03-cloud-api\",\"bootstrapServers\":\"platform-infra-kafka-kafka-bootstrap.platform-infra.svc.cluster.local:9092\",\"stdioTopic\":\"codex-stdio.raw.v1\",\"agentRunEventTopic\":\"agentrun.event.v1\",\"hwlabEventTopic\":\"hwlab.event.v1\",\"clientId\":\"hwlab-v03-cloud-api\",\"directPublishConsumerGroupId\":\"hwlab-agentrun-event-direct-publish\",\"transactionalProjectorConsumerGroupId\":\"hwlab-v03-agentrun-event-projector\",\"hwlabEventConsumerGroupId\":\"hwlab-v03-workbench-live-sse\"},\"valuesPrinted\":false},\"observability\":{\"prometheusOperator\":false,\"webProbe\":{\"sentinels\":[{\"id\":\"nc01-web-probe-sentinel\",\"enabled\":true,\"configRef\":\"config/hwlab-web-probe-sentinel/profiles.yaml#nodes.NC01.sentinels.nc01-web-probe-sentinel.sentinel\"}],\"monitor\":{\"configRef\":\"config/hwlab-web-probe-monitor/runtime.yaml#monitor\"},\"monitorRoot\":{\"enabled\":true,\"sentinelId\":\"nc01-web-probe-sentinel\",\"publicBaseUrl\":\"https://monitor.pikapython.com\",\"routePrefix\":\"/\",\"caddyManagedBlockOwner\":\"hwlab-web-probe-sentinel-active-root\"}},\"recordingRules\":[],\"warningAlerts\":[]},\"runtimeImageRewrites\":[{\"source\":\"fatedier/frpc:v0.68.1\",\"target\":\"127.0.0.1:5000/hwlab/frpc:v0.68.1\"},{\"source\":\"openfga/openfga:v1.17.0\",\"target\":\"127.0.0.1:5000/hwlab/openfga:v1.17.0\"},{\"source\":\"ghcr.io/anomalyco/opencode:1.17.7\",\"target\":\"127.0.0.1:5000/hwlab/opencode:1.17.7\"}],\"dockerProxyHttp\":\"http://127.0.0.1:10808\",\"dockerProxyHttps\":\"http://127.0.0.1:10808\",\"dockerNoProxyList\":[\"localhost\",\"127.0.0.1\",\"::1\",\"127.0.0.1:5000\",\"localhost:5000\",\".svc\",\".svc.cluster.local\",\".cluster.local\",\"hyueapi.com\",\".hyueapi.com\"],\"npmRegistry\":\"https://registry.npmmirror.com/\",\"npmFetchTimeoutMs\":120000,\"npmRetries\":3};\nconst file = 'deploy/deploy.yaml';\nif (!fs.existsSync(file)) {\n console.error(JSON.stringify({ event: 'unidesk-deploy-yaml-overlay', ok: false, reason: 'deploy-yaml-missing', file }));\n process.exit(45);\n}\nconst doc = YAML.parse(fs.readFileSync(file, 'utf8'));\ndoc.nodes = doc.nodes || {};\ndoc.nodes[overlay.nodeId] = { ...(doc.nodes[overlay.nodeId] || {}), gitopsRoot: overlay.gitopsRoot, sourceRepo: overlay.gitUrl };\ndoc.lanes = doc.lanes || {};\nconst lane = doc.lanes[overlay.lane] || {};\nconst envRecipe = lane.envRecipe || {};\nconst downloadStack = {\n ...(envRecipe.downloadStack || {}),\n httpProxy: overlay.dockerProxyHttp,\n httpsProxy: overlay.dockerProxyHttps,\n noProxy: overlay.dockerNoProxyList,\n};\nif (overlay.npmRegistry) downloadStack.npmRegistry = overlay.npmRegistry;\nif (overlay.npmFetchTimeoutMs) downloadStack.npmFetchTimeoutMs = overlay.npmFetchTimeoutMs;\ndoc.lanes[overlay.lane] = {\n ...lane,\n node: overlay.nodeId,\n sourceBranch: overlay.sourceBranch,\n gitopsBranch: overlay.gitopsBranch,\n namespace: overlay.runtimeNamespace,\n endpoint: overlay.publicApiUrl,\n publicEndpoints: { frontend: overlay.publicWebUrl, api: overlay.publicApiUrl },\n artifactCatalog: overlay.catalogPath,\n runtimePath: overlay.runtimeRenderDir,\n imageTagMode: 'full',\n sourceRepo: overlay.gitUrl,\n observability: overlay.observability,\n envRecipe: { ...envRecipe, downloadStack },\n};\nif (overlay.externalPostgres === undefined || overlay.externalPostgres === null) delete doc.lanes[overlay.lane].externalPostgres;\nelse doc.lanes[overlay.lane].externalPostgres = overlay.externalPostgres;\nif (overlay.runtimeStore !== undefined) doc.lanes[overlay.lane].runtimeStore = overlay.runtimeStore;\nif (overlay.codeAgentRuntime !== undefined) doc.lanes[overlay.lane].codeAgentRuntime = overlay.codeAgentRuntime;\nfs.writeFileSync(file, YAML.stringify(doc));\nconsole.error(JSON.stringify({ event: 'unidesk-deploy-yaml-overlay', ok: true, lane: overlay.lane, httpProxy: overlay.dockerProxyHttp, noProxyCount: overlay.dockerNoProxyList.length }));\nNODE_UNIDESK_DEPLOY_YAML_OVERLAY\nnode scripts/artifact-publish.mjs --publish --lane \"$(params.lane)\" --catalog-path \"$(params.catalog-path)\" --deploy-config deploy/deploy.yaml --image-tag-mode \"$(params.image-tag-mode)\" --registry-prefix \"$(params.registry-prefix)\" --report /workspace/source/dev-artifacts.json --quiet-build --concurrency 1 --services \"$(params.services)\" --external-service-report-dir /workspace/source/service-results --ci-plan-path /workspace/source/affected-services.json\nnode scripts/refresh-artifact-catalog.mjs --lane \"$(params.lane)\" --catalog-path \"$(params.catalog-path)\" --deploy-config deploy/deploy.yaml --image-tag-mode \"$(params.image-tag-mode)\" --target-ref HEAD --publish-report /workspace/source/dev-artifacts.json --no-write\n" imagePullPolicy: Always - params: - - name: revision - value: $(params.revision) - - name: lane - value: $(params.lane) - - name: catalog-path - value: $(params.catalog-path) - - name: image-tag-mode - value: $(params.image-tag-mode) - - name: registry-prefix - value: $(params.registry-prefix) - - name: services - value: $(params.services) - - name: base-image - value: $(params.base-image) - - name: gitops-promote - runAfter: - - collect-artifacts - workspaces: - - name: source - workspace: source - - name: gitea-auth - workspace: gitea-auth - taskSpec: - params: - - name: git-url - - name: git-read-url - - name: gitops-read-url - - name: git-write-url - - name: gitops-username - - name: source-branch - - name: gitops-branch - - name: lane - - name: catalog-path - - name: image-tag-mode - - name: runtime-path - - name: revision - - name: registry-prefix - results: - - name: runtime-ready-required - description: true when GitOps promotion changed runtime desired state and runtime readiness must be observed - workspaces: - - name: source - - name: gitea-auth - steps: - name: promote image: 127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1 env: @@ -809,7 +564,7 @@ spec: value: /tekton/home - name: XDG_CONFIG_HOME value: /tekton/home/.config - script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\nci_now_ms() {\n node -e 'console.log(Date.now())'\n}\n\nci_timing_emit() {\n stage=\"$1\"\n status=\"$2\"\n started_ms=\"$3\"\n finished_ms=\"$(ci_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n service_id=\"${HWLAB_TIMING_SERVICE_ID:-}\"\n node -e 'const [stage,status,durationMs,serviceId]=process.argv.slice(1); const payload={event:\"node-cicd-timing\",schemaVersion:\"v1\",stage,status,durationMs:Number(durationMs),pipelineRun:process.env.HWLAB_TEKTON_PIPELINERUN||null,taskRun:process.env.HWLAB_TEKTON_TASKRUN||null,task:process.env.HWLAB_TEKTON_TASK||null,revision:process.env.HWLAB_SOURCE_REVISION||null,serviceId:serviceId||null,source:\"scripts/gitops-render.mjs\",at:new Date().toISOString()}; console.log(JSON.stringify(payload));' \"$stage\" \"$status\" \"$duration_ms\" \"$service_id\"\n}\ngit_now_ms() {\n node -e 'console.log(Date.now())' 2>/dev/null || date +%s000\n}\n\ngit_timed() {\n phase=\"$1\"\n timeout_seconds=\"$2\"\n shift 2\n started_ms=\"$(git_now_ms)\"\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"started\",\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n set +e\n timeout \"$timeout_seconds\" \"$@\"\n status=\"$?\"\n set -e\n finished_ms=\"$(git_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n if [ \"$status\" -eq 0 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"succeeded\",\"durationMs\":'\"$duration_ms\"'}' >&2\n return 0\n fi\n if [ \"$status\" -eq 124 ] || [ \"$status\" -eq 137 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"reason\":\"timeout\",\"durationMs\":'\"$duration_ms\"',\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n else\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"exitCode\":'\"$status\"',\"durationMs\":'\"$duration_ms\"'}' >&2\n fi\n return \"$status\"\n}\n\nexport HWLAB_TEKTON_PIPELINERUN=\"$(context.pipelineRun.name)\"\nexport HWLAB_TEKTON_TASKRUN=\"$(context.taskRun.name)\"\nexport HWLAB_TEKTON_TASK=\"gitops-promote\"\nexport HWLAB_SOURCE_REVISION=\"$(params.revision)\"\necho '{\"event\":\"ci-base-image\",\"phase\":\"gitops-promote\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apt\"}'\nfor tool in node git timeout; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"phase\":\"gitops-promote\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\nlane=\"$(params.lane)\"\ncase \"$lane\" in\n node) runtime_lane=false ;;\n *) runtime_lane=true ;;\nesac\nif [ \"$runtime_lane\" = \"true\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required\nelse\n printf 'true' > /tekton/results/runtime-ready-required\nfi\ntest -s /workspace/gitea-auth/token || { echo '{\"event\":\"gitea-auth\",\"phase\":\"gitops-promote\",\"status\":\"failed\",\"reason\":\"token-missing\"}'; exit 31; }\naskpass_dir=\"$(mktemp -d)\"\ncat > \"$askpass_dir/askpass.sh\" <<'SH'\n#!/bin/sh\ncase \"$1\" in\n *sername*) printf '%s\\n' \"$GITEA_USERNAME\" ;;\n *) cat /workspace/gitea-auth/token ;;\nesac\nSH\nchmod 0700 \"$askpass_dir/askpass.sh\"\nexport GITEA_USERNAME=\"$(params.gitops-username)\"\nexport GIT_ASKPASS=\"$askpass_dir/askpass.sh\"\nexport GIT_ASKPASS_REQUIRE=force\nexport GIT_TERMINAL_PROMPT=0\ncd /workspace/source/repo\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\n\ncheck_source_head() {\n phase=\"$1\"\n expected=\"${2:-$(params.revision)}\"\n source_head_url=\"$(params.git-read-url)\"\n latest_file=\"$(mktemp)\"\n if ! git_timed \"source-head-$phase\" 45 git ls-remote \"$source_head_url\" \"refs/heads/$(params.source-branch)\" > \"$latest_file\"; then\n echo '{\"status\":\"failed\",\"reason\":\"source-head-check-failed\",\"phase\":\"'\"$phase\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n exit 1\n fi\n latest=\"$(cut -f1 \"$latest_file\" | head -n 1)\"\n if [ -z \"$latest\" ]; then\n echo '{\"status\":\"failed\",\"reason\":\"source-head-unresolved\",\"phase\":\"'\"$phase\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n exit 1\n fi\n if [ \"$latest\" != \"$expected\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required || true\n echo '{\"status\":\"skipped-stale-source\",\"verdict\":\"superseded\",\"phase\":\"'\"$phase\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\",\"expectedRevision\":\"'\"$expected\"'\",\"latestRevision\":\"'\"$latest\"'\"}'\n exit 0\n fi\n}\n\ncheck_source_head before-render\nif [ -s /workspace/source/affected-services.json ] && node - /workspace/source/affected-services.json <<'NODE'\nconst fs = require(\"node:fs\");\nconst plan = JSON.parse(fs.readFileSync(process.argv[2], \"utf8\"));\nconst buildServices = Array.isArray(plan.buildServices) ? plan.buildServices : [];\nconst affectedServices = Array.isArray(plan.affectedServices) ? plan.affectedServices : [];\nprocess.exit(buildServices.length === 0 && affectedServices.length === 0 ? 0 : 1);\nNODE\nthen\n printf 'false' > /tekton/results/runtime-ready-required || true\n echo '{\"event\":\"gitops-promote\",\"status\":\"continuing\",\"reason\":\"no-build-no-rollout-plan-gitops-verify\"}' >&2\nfi\ngit config --global user.name \"HWLAB node GitOps Bot\"\ngit config --global user.email \"hwlab-node-gitops-bot@users.noreply.github.com\"\ncatalog_path=\"$(params.catalog-path)\"\nruntime_path=\"$(params.runtime-path)\"\nunidesk_legacy_runtime_path='deploy/gitops/node/runtime-v03'\ngitops_root_from_runtime_path() {\n path=\"$1\"\n case \"$path\" in\n */*) printf '%s\n' \"${path%/*}\" ;;\n *) printf '.\n' ;;\n esac\n}\ngitops_root=\"$(gitops_root_from_runtime_path \"$runtime_path\")\"\n\nargo_hard_refresh_runtime_lane() {\n if [ \"$runtime_lane\" != \"true\" ]; then return 0; fi\n ARGO_APPLICATION=\"hwlab-node-$lane\" ARGO_FIELD_MANAGER=\"hwlab-$lane-gitops-promote\" node <<'NODE'\nconst fs = require(\"node:fs\");\nconst https = require(\"node:https\");\n\nconst host = process.env.KUBERNETES_SERVICE_HOST;\nconst port = process.env.KUBERNETES_SERVICE_PORT || \"443\";\nconst startedAt = Date.now();\nconst application = process.env.ARGO_APPLICATION || \"hwlab-node-v02\";\nconst fieldManager = process.env.ARGO_FIELD_MANAGER || \"hwlab-v02-gitops-promote\";\nconst pipelineRun = process.env.HWLAB_TEKTON_PIPELINERUN || null;\nconst taskRun = process.env.HWLAB_TEKTON_TASKRUN || null;\nconst task = process.env.HWLAB_TEKTON_TASK || null;\nconst revision = process.env.HWLAB_SOURCE_REVISION || null;\n\nfunction emit(payload) {\n console.log(JSON.stringify({\n event: \"node-cicd-timing\",\n schemaVersion: \"v1\",\n stage: \"argo-hard-refresh\",\n pipelineRun,\n taskRun,\n task,\n revision,\n application,\n source: \"scripts/gitops-render.mjs\",\n at: new Date().toISOString(),\n ...payload\n }));\n}\n\nfunction safeJson(text) {\n try {\n return JSON.parse(text);\n } catch {\n return null;\n }\n}\n\nfunction request(method, path, body, contentType = \"application/merge-patch+json\") {\n const token = fs.readFileSync(\"/var/run/secrets/kubernetes.io/serviceaccount/token\", \"utf8\");\n const ca = fs.readFileSync(\"/var/run/secrets/kubernetes.io/serviceaccount/ca.crt\");\n const payload = body ? JSON.stringify(body) : \"\";\n const headers = { Authorization: \"Bearer \" + token };\n if (payload) {\n headers[\"Content-Type\"] = contentType;\n headers[\"Content-Length\"] = Buffer.byteLength(payload);\n }\n return new Promise((resolve, reject) => {\n const req = https.request({ host, port, method, path, ca, headers }, (res) => {\n let data = \"\";\n res.setEncoding(\"utf8\");\n res.on(\"data\", (chunk) => { data += chunk; });\n res.on(\"end\", () => resolve({ statusCode: res.statusCode || 0, body: data, json: safeJson(data) }));\n });\n req.on(\"error\", reject);\n if (payload) req.write(payload);\n req.end();\n });\n}\n\n(async () => {\n if (!host) {\n emit({ status: \"skipped\", reason: \"kubernetes-service-host-missing\", durationMs: Date.now() - startedAt });\n return;\n }\n const response = await request(\n \"PATCH\",\n \"/apis/argoproj.io/v1alpha1/namespaces/argocd/applications/\" + encodeURIComponent(application) + \"?fieldManager=\" + encodeURIComponent(fieldManager),\n { metadata: { annotations: { \"argocd.argoproj.io/refresh\": \"hard\" } } }\n );\n if (response.statusCode >= 200 && response.statusCode < 300) {\n emit({ status: \"succeeded\", durationMs: Date.now() - startedAt, statusCode: response.statusCode });\n return;\n }\n emit({ status: \"degraded\", reason: \"argo-refresh-patch-failed\", durationMs: Date.now() - startedAt, statusCode: response.statusCode, body: response.body.slice(0, 1000) });\n})().catch((error) => {\n emit({ status: \"degraded\", reason: \"argo-refresh-patch-error\", durationMs: Date.now() - startedAt, error: error.message });\n});\nNODE\n}\n\nif [ -s /workspace/source/dev-artifacts.json ]; then\n node scripts/refresh-artifact-catalog.mjs --lane \"$lane\" --catalog-path \"$catalog_path\" --deploy-config deploy/deploy.yaml --image-tag-mode \"$(params.image-tag-mode)\" --target-ref \"$(params.revision)\" --publish-report /workspace/source/dev-artifacts.json --write\nfi\ngitops_render_started_ms=\"$(ci_now_ms)\"\nnode - <<'NODE_UNIDESK_DEPLOY_YAML_OVERLAY'\nconst fs = require('fs');\nconst YAML = require('yaml');\nconst overlay = {\"nodeId\":\"NC01\",\"lane\":\"v03\",\"sourceBranch\":\"v0.3\",\"gitopsBranch\":\"v0.3-gitops\",\"gitopsRoot\":\"deploy/gitops/node/nc01\",\"runtimePath\":\"deploy/gitops/node/nc01/runtime-v03\",\"runtimeRenderDir\":\"runtime-v03\",\"runtimeNamespace\":\"hwlab-v03\",\"environment\":\"development\",\"catalogPath\":\"deploy/artifact-catalog.nc01-v03.json\",\"gitUrl\":\"git@github.com:pikasTech/HWLAB.git\",\"publicWebUrl\":\"https://lab-dev.hwpod.com\",\"publicApiUrl\":\"https://lab-dev.hwpod.com\",\"externalPostgres\":{\"enabled\":true,\"serviceName\":\"nc01-host-postgres\",\"endpointAddress\":\"10.42.0.1\",\"port\":5432,\"runtimeAccess\":{\"routeName\":\"nc01-host-postgres\",\"endpointAddress\":\"10.42.0.1\",\"port\":5432},\"sslmode\":\"require\"},\"runtimeStore\":{\"postgres\":{\"mode\":\"platform-service\",\"serviceName\":\"nc01-host-postgres\",\"poolMax\":16}},\"codeAgentRuntime\":{\"enabled\":true,\"adapter\":\"agentrun-v02\",\"managerUrl\":\"http://agentrun-mgr.agentrun-v02.svc.cluster.local:8080\",\"apiKeySecretName\":\"hwlab-v03-master-server-admin-api-key\",\"apiKeySecretKey\":\"api-key\",\"runnerNamespace\":\"agentrun-v02\",\"secretNamespace\":\"agentrun-v02\",\"providerSecretNames\":{\"codex\":\"agentrun-v01-provider-codex\",\"gpt-pika\":\"agentrun-v02-provider-gpt-pika\",\"grok\":\"agentrun-v02-provider-grok\",\"dsflash-go\":\"agentrun-v01-provider-dsflash-go\"},\"toolSecretNames\":{\"githubPr\":\"agentrun-v01-tool-github-pr\",\"unideskSsh\":\"agentrun-v01-tool-unidesk-ssh\"},\"repoUrlFrom\":\"runtimeGitReadUrl\",\"repoUrl\":\"http://gitea-http.devops-infra.svc.cluster.local:3000/mirrors/pikasTech-HWLAB.git\",\"providerIdFrom\":\"runtimeNodeId\",\"providerId\":\"NC01\",\"defaultProviderProfile\":\"gpt.pika\",\"codexStdioSupervisor\":\"repo-owned\",\"kafkaShadowProducer\":null,\"kafkaEventBridge\":{\"enabled\":true,\"features\":{\"directPublish\":true,\"liveKafkaSse\":true,\"kafkaRefreshReplay\":true,\"transactionalProjector\":false,\"projectionOutboxRelay\":false,\"projectionRealtime\":false},\"refreshReplay\":{\"groupIdPrefix\":\"hwlab-v03-cloud-api-sse\",\"timeoutMs\":30000,\"scanLimit\":1000000,\"matchedEventLimit\":2000,\"liveBufferLimit\":2000},\"configRef\":\"config/platform-infra/kafka.yaml#clients.hwlab-v03-cloud-api\",\"bootstrapServers\":\"platform-infra-kafka-kafka-bootstrap.platform-infra.svc.cluster.local:9092\",\"stdioTopic\":\"codex-stdio.raw.v1\",\"agentRunEventTopic\":\"agentrun.event.v1\",\"hwlabEventTopic\":\"hwlab.event.v1\",\"clientId\":\"hwlab-v03-cloud-api\",\"directPublishConsumerGroupId\":\"hwlab-agentrun-event-direct-publish\",\"transactionalProjectorConsumerGroupId\":\"hwlab-v03-agentrun-event-projector\",\"hwlabEventConsumerGroupId\":\"hwlab-v03-workbench-live-sse\"},\"valuesPrinted\":false},\"observability\":{\"prometheusOperator\":false,\"webProbe\":{\"sentinels\":[{\"id\":\"nc01-web-probe-sentinel\",\"enabled\":true,\"configRef\":\"config/hwlab-web-probe-sentinel/profiles.yaml#nodes.NC01.sentinels.nc01-web-probe-sentinel.sentinel\"}],\"monitor\":{\"configRef\":\"config/hwlab-web-probe-monitor/runtime.yaml#monitor\"},\"monitorRoot\":{\"enabled\":true,\"sentinelId\":\"nc01-web-probe-sentinel\",\"publicBaseUrl\":\"https://monitor.pikapython.com\",\"routePrefix\":\"/\",\"caddyManagedBlockOwner\":\"hwlab-web-probe-sentinel-active-root\"}},\"recordingRules\":[],\"warningAlerts\":[]},\"runtimeImageRewrites\":[{\"source\":\"fatedier/frpc:v0.68.1\",\"target\":\"127.0.0.1:5000/hwlab/frpc:v0.68.1\"},{\"source\":\"openfga/openfga:v1.17.0\",\"target\":\"127.0.0.1:5000/hwlab/openfga:v1.17.0\"},{\"source\":\"ghcr.io/anomalyco/opencode:1.17.7\",\"target\":\"127.0.0.1:5000/hwlab/opencode:1.17.7\"}],\"dockerProxyHttp\":\"http://127.0.0.1:10808\",\"dockerProxyHttps\":\"http://127.0.0.1:10808\",\"dockerNoProxyList\":[\"localhost\",\"127.0.0.1\",\"::1\",\"127.0.0.1:5000\",\"localhost:5000\",\".svc\",\".svc.cluster.local\",\".cluster.local\",\"hyueapi.com\",\".hyueapi.com\"],\"npmRegistry\":\"https://registry.npmmirror.com/\",\"npmFetchTimeoutMs\":120000,\"npmRetries\":3};\nconst file = 'deploy/deploy.yaml';\nif (!fs.existsSync(file)) {\n console.error(JSON.stringify({ event: 'unidesk-deploy-yaml-overlay', ok: false, reason: 'deploy-yaml-missing', file }));\n process.exit(45);\n}\nconst doc = YAML.parse(fs.readFileSync(file, 'utf8'));\ndoc.nodes = doc.nodes || {};\ndoc.nodes[overlay.nodeId] = { ...(doc.nodes[overlay.nodeId] || {}), gitopsRoot: overlay.gitopsRoot, sourceRepo: overlay.gitUrl };\ndoc.lanes = doc.lanes || {};\nconst lane = doc.lanes[overlay.lane] || {};\nconst envRecipe = lane.envRecipe || {};\nconst downloadStack = {\n ...(envRecipe.downloadStack || {}),\n httpProxy: overlay.dockerProxyHttp,\n httpsProxy: overlay.dockerProxyHttps,\n noProxy: overlay.dockerNoProxyList,\n};\nif (overlay.npmRegistry) downloadStack.npmRegistry = overlay.npmRegistry;\nif (overlay.npmFetchTimeoutMs) downloadStack.npmFetchTimeoutMs = overlay.npmFetchTimeoutMs;\ndoc.lanes[overlay.lane] = {\n ...lane,\n node: overlay.nodeId,\n sourceBranch: overlay.sourceBranch,\n gitopsBranch: overlay.gitopsBranch,\n namespace: overlay.runtimeNamespace,\n endpoint: overlay.publicApiUrl,\n publicEndpoints: { frontend: overlay.publicWebUrl, api: overlay.publicApiUrl },\n artifactCatalog: overlay.catalogPath,\n runtimePath: overlay.runtimeRenderDir,\n imageTagMode: 'full',\n sourceRepo: overlay.gitUrl,\n observability: overlay.observability,\n envRecipe: { ...envRecipe, downloadStack },\n};\nif (overlay.externalPostgres === undefined || overlay.externalPostgres === null) delete doc.lanes[overlay.lane].externalPostgres;\nelse doc.lanes[overlay.lane].externalPostgres = overlay.externalPostgres;\nif (overlay.runtimeStore !== undefined) doc.lanes[overlay.lane].runtimeStore = overlay.runtimeStore;\nif (overlay.codeAgentRuntime !== undefined) doc.lanes[overlay.lane].codeAgentRuntime = overlay.codeAgentRuntime;\nfs.writeFileSync(file, YAML.stringify(doc));\nconsole.error(JSON.stringify({ event: 'unidesk-deploy-yaml-overlay', ok: true, lane: overlay.lane, httpProxy: overlay.dockerProxyHttp, noProxyCount: overlay.dockerNoProxyList.length }));\nNODE_UNIDESK_DEPLOY_YAML_OVERLAY\nnode scripts/run-bun.mjs scripts/gitops-render.mjs --lane \"$lane\" --catalog-path \"$catalog_path\" --image-tag-mode \"$(params.image-tag-mode)\" --source-revision \"$(params.revision)\" --source-repo \"$(params.git-url)\" --source-branch \"$(params.source-branch)\" --gitops-branch \"$(params.gitops-branch)\" --gitops-root \"deploy/gitops/node/nc01\" --out \"deploy/gitops/node/nc01\" --registry-prefix \"$(params.registry-prefix)\" --use-deploy-images\nUNIDESK_RUNTIME_GITOPS_OVERLAY_FILE=/etc/unidesk-cicd-runtime-gitops/runtime-gitops-overlay.json node /etc/unidesk-cicd-runtime-gitops/runtime-gitops-postprocess.mjs\nfeature_config_schema_started_ms=\"$(date +%s%3N 2>/dev/null || date +%s000)\"\nexport UNIDESK_FEATURE_CONFIG_REPO_DIR=\"$PWD\"\nexport UNIDESK_FEATURE_CONFIG_RENDERED_ROOT=\"deploy/gitops/node/nc01/runtime-v03\"\nexport UNIDESK_PAC_CONSUMER='hwlab-nc01-v03'\nexport OTEL_EXPORTER_OTLP_TRACES_ENDPOINT='http://otel-collector.platform-infra.svc.cluster.local:4318/v1/traces'\nexport OTEL_SERVICE_NAME='unidesk-cicd'\nexport OTEL_TRACES_SAMPLER_ARG='1'\nexport OTEL_EXPORTER_TIMEOUT_MS='300'\nfeature_config_validator_base=''\nfeature_config_validator=''\nif feature_config_validator_base=\"$(mktemp \"${TMPDIR:-/tmp}/unidesk-feature-config-validator.XXXXXX\" 2>/dev/null)\"; then\n feature_config_validator=\"${feature_config_validator_base}.mjs\"\n if ! printf '%s' 'H4sIAAAAAAACA80ba3PbyO17fgXDZjpkT6bttNNp5fo0iq3c+c6vkeS0HdeVaWplM6ZIlQ/bGp/+ewHsm6Rk5a4fmpkk2hcWr8ViAfB373erIt+9i9Ndlj45aTZl7+L5IstL59XJw3SazT8tS1Y4K2eWZ3PHxRndKF8uysw90FPZS1yUxWiZRh0nKcqw5D9zFk4/xwnTrWmcY8OGNys0rEVYPphj2DZ3igBKyYbsP1WcMxvMPJtWCTMn4+JxhhhcDU/tyVWewMx3UZYWJWDGwR3a4D0OKJizMgxggX8g5kfP0+GaJbhl8DWLU2+RZxErigAme37HcRdh9Bjes+BrkaWur2D9s392ClDuk+wuTMYPcRFUaTxlxeM/w3ni9HpOtijjLA0TuYO7hAHXXz/UMfBT23zpn54c98cXw8nVef9L/+S0/+l0APu6nwf98dVwMDm6OP988sOkdR5yir0QUzm02qLR0Y+Ds/7ksj/+EUHCnFl8vzsDvlQ52+HNoIge2Dzk5Gt4syqNkAjnKUziKTDyM191RItGtMbjdBYA+3XlO6/vHEfKbZEdxzn0E9tzVmTJE5PTAzkMnLKEAUyREDhSl6h0hxuo0gvCO9ijKtnIXKiFLrbsGIBpt3jmeO/1KfGaYHwfyAHKU/ivqJLSc23+7XCIO/O4KOL0HqTs8h5nBvrtxIWjR/Y7TlolqK+wdcIkmYhImS+JgY7oA+x/Gl2cB4swL5hnHtgWHGHPqpz9xeUcXDlRWEYPjsfyPMt9AXYrIuKUxA2o3go0EAmHkHBmIWAw7TofXgnwGcgNzo3YZXVrkgdIvFOiEVsNcB7qimgfsygJ8xBVgg95fEslF2tdIFALEpbeg3C/d/b8b6WpFeD13s2aEbGVQVQTq2m1SGJgNyu+AbGnMI/Du4TtqNUN5DTcFvwam9bVSp5ZW7G4NPpfnz7ufdwDOYT8l0ekqXP09QmGUvYsJ3qvTpgkfOcuQKsYHKIyj6NStpSFyPJ5WMKkWZiAuqwEXIAYwAXzM1s+Z/kUwD3yX13HfdkRNnVHEOjKAzpeLhhMwI3o5NAefEMFWO7LSQmibL4ABTW1aJuTQF2OQzN6AGQK8A4P19jlntOUJSGR5UBK+AQnBAXrOl3nLW0097WPkhzalz9QuPy3Ploo5ggcgTY5y25gjDS5ug+Mbs7SKcvZ9O9Z/phk4fRIDnqvYkc5Y5hlIGZtt3WvxA0M+ILl5fI8nDMQ/cXdVxaVAYhYHudAzIhZIShb/WorpZmNtojrSxsDa5aIH1yDLSBfHHZ++cV5HxdDFqFiqvEAtqkAWxw26WlMkEce4e1tR0GcLqrSvCskT51nIQxDfEUaLoqHrGxcImpKLyiq+TwE0YNYbdtLN5s8Ik3cfcsoMGmb+3keLoO4oP89uTzg4+DbOLUuUPTrm4PtRFcxJHyOUgcy7rIKKJ+ClSHbwkWH1s4XMlUWFcRg0ixJVsLd6haQdwCdJWevHd6q6f6weVy2uD5fOBtgxlon6ElNgaEtvCiiR/pDRQlakQfPeQzCu/3wSr4At4bxTAkGlvmrf6W3tFSwQQ+Z9IQFeveKqrxKv5Uo414h2KbFsUjdmmMbzIAF8H9pDH4Th1ct1ykc3wU4mKVha7OSJQPZbfi48JILLsaD08ngH5cXw/FgOLkYn15OxsP+0WA0GZwfX16cnI9xheuaV3IZz1lWlWcojUVWxGX8xE7Skt2z3DP3HKt5Gzcdn5wNLq7Gk7ORdfEX4Ry8ivR+iETDTlb7C55ea7ORNb1tQ0HXqH92eQrb9oc/iP3QMkm2tZpQxVvS3b+HeQobIYNhX9HyXMmvydnJaHRy/oM62+R9yIbindh7a/lbe2sVMAzdq6GlHcLtMlyiBe+KvQ10uzVaVhzWSvHDkLG4nL6JGUqmm3hhHIL/RzZwMg0A+qnA7ciFHvLMPSWfCpY/xRFDT6RrHcaRHmjV1NFg+OXkaDA5758N6PhJrzSKI+2pIX7VnOUatuypA706PzkejH6GF+oRvllHV2eDobygJTTreMnOMg8jBo8tlhpel9FZ34iO2GV/OOBmwxyqrXIVGWn2fFZo6NS09j+Z1vY+mSqkF2FqDvO26dWt09bwOYxl7+e6UJU1sPTHOLwdteOMwWVxAqxDoqhhGhVr0/fqIP1WXX9L09/W8fZbbhsrR1Z7AnZuMDzvn04+w0sEQiH1A05gO//j2+HbLsxfzb1t7cSqzT3bykCs89DE8Tjk8Y2xPjFey9kzglPiVBhXvuxB1tJss8eI13r7f/aDMhsR1zz3gb24ZtCLjpMBVnTUYPxlAwg6zgYE3gYAx+jpQssz9yvDvES9uErjl/MwxWtfwP0U34MSebTcd/7g7E/29vbwb2r6mvLFU2RVHrERYAuW5Vo/Inl/F2QflgD3DoJWaHpATH3VVm9OB5773FAHKVhq1zAztv1uN8+O6oeYWaRss9turk1TbKxE1AJpmicUnDLxqPs8a6DwJ9YEXnVhVLKpKwIlYiKo4EoZ1AjexnW+iW5kW0p3mQKMBAe2G4yxEZYXgB/Me9p3NWxurm3AysR3jC7TivM/QRB4Qo+lTsoncw/OkNOlGD6Oj8SNYM9e+SY0QYSJ/MSKPbvm7Mc4BXj7FoJ1PTUH4e4wh7qbZ2+lhyTMGqbP3BSBLLVlkZ2djSvvkix65Eu5td44GwNQ9ibYs3kN5+KEUjLWUh3s3gyArg9oVGlpA6CBI+w3AdjiZU8g+bqaOXR5bykUpSIbnu6Ej2uv2lqYv0Wcv05EzVWzOC/KCTHUXkwDFAOxQdhcXt3UTkRZFXgMcWs4Luax11PlL/7/igICtUjA2y7ZosUdU26YeZ3Cv2WeJQnLZQT5DkAfqV7z6hGw8J3JSuGaeJ7vHH5vgAlCBIBJOvsZV3+Dw0WzgB9M+ZkKPYMMqRGQNHzIMPh8eTEaK4V6gAQLy4mjmCYrQaV3SohBg6jccMHD7cCuXcqSaWbfZdNl16l5QoJhSnxFfA+5wK5JGO+yHWf0YCUlQfaokghodi1PynQQb38cjy8nH17VQq4ZmI2pdW18GG8Mxpr70bgTA9fDNGLZzCHFdX7/e+6C0s1Nl4VLwqdRF8Pmwq+kyLhwatGXHRwrV/ZXgVaub52eWQwMTpSeJCzMpZqJqb5yKuve5NrMFEGjwKqKGssRCFKKeDeqDT0+3IyCx64dZm5GxWvsfnVEjgBMqkwl5hBxd+YV6Podc0IQCUGWqcLnGCIoGqALCSOdIsIArXSg5YERG8B54cFbGbDkaani01LYA3GOz8IFP7szkIfHJ1+bgf+OSgPwWN+NA+IToXM4STkgtYFum6E2JF+HQWRWblEVD96tnAbZSBOTleRJg1k6cIHnME4r1gw+zBTZNhbXLZmqG31qUeJAsFxNsheZK5S96IcnQTz3/DURry2pI7KmpJ/MaSC1DY1KyhSVrks8uGelZyNMFQ0yyK9WcERN5PzaDA2zaMDs6Gm+rZpacVE7wRFtgSdVyr+hHeEGTUq4XrxrA+wN3SUaXZWd3ff5ojkotXct0GosvJXC/PAqfgHvIRvjlBnIICnjBeT2tS5jUlzvRRUHbseFpLj1WpJCNo+nuJV1ZH59bs7KynXszJuz0sZJqKM5u6GT5qClkWSsjIIIcyJZOV4Xo2IrtUuKC/E5hBt0KqzHCKRv4eqbJgdfSvQwPxA5BqyaII8Tevdkp0yONQYom8SmFJ+2Bg1TRXUYwJAEiILnbRWhOKmcorDJk6dRo/DdobPP1dqAN80ieEbCKMCkyMGx6Cg8XGmYLGMRBE3muOCxumN5ykDyJ9BTeBKYsUqFJ7LpaMEioAgXQ6oPGr0Afi4SnvqD9oFaU7OifC1AtS0B/rGZqUmsYXyfZ9UCUb4mjyiMU3CQMGUZpzF5daLnxsTcgqCWIRQ7syjwu6ZNbjCxaPdQXtEGbIHGqrgGULVfDwNbCFT1YEcrTME4rrHBQ1iAy/jUI2eD1F0cJuokbbWOUht7+R+u2dcYYENYNzLKNBQKxzMqOEwz/fr6pmLbgtJmvf5b/lop07+qR2w4ctz9FNnPrg6ji6CNSk3vSIXZAXSVx2yXCIg6L1BMCD/WS+ysIrDaiQMWu4ECqk6e7LB0VXY2eFMvRqDOrm0hZanMO1M+lyDFEmuajJf5Sr+VlFVuNR1kEfXzZx6+0ABI+iNGyg7MEag9Ax8kw2urOT4Ty0xnbAFs4vHga5t9uOuNNH9TAXZp2b7nB7R4ngBhFSaZz6aoymX8U8xcZAtZDVSDrJUPj0tt8Psahb5TPuTZM1l/nty/bZY5KBjA3DnlBiLGpry+zAa3km6Ncf7pMUCXnKpd9QQ9fj1zRvbfLAYUEzsExXSZeEwUOaKKZblJl3OQeBwBkzNazu8yuMRP4/TRa7GzxlRJyxLnKV6j/2QBZ1g1hct2/xV4ve4y7M2TX/DB6X/YjSsw/AUEZBFj04aR7rQAE8VqseX7SBXdSkDEtlbZEIyVdjZbLQ3fuqAHvH2Y2u5M4xyV7KWkrL9R8ohzVJGjrMQDNiF3NHOs25eCBBKZa6OWEuHDCVJvXj0JO800vxxAl4cv7ieJRpwAcT9S3eLoO8oGROl/GoHIlX/aOkvnqdaiZDJvrf9AZItlsrMXYDSVP5pPwYS5+Jq270yFLPoYVOFj9+ClKXtuWuRo32f8LiNULA4a7BfXXZNWGqiT21ol1PYO5wPKH3V1FdU0A+OaZsJXFO9D98B4DPOIg6gZlhc+xRzsMdOH7rXN6IrKDQ5Y1DnWYaruNnByEIP5OuxpXCW8tqUOU3W3wZSDGGClEl7XeJRAIs8iAe/jXXcFB12ggj8FhNVt/a1ChTkU/XSMMKZjhI11nZV5xp9VtlNPxQtKEyoEz2NAilq9SZ1UPYLl5QkkOcA+FN/t3ldgNxzXl6/vAkw286D+6+Of4DrsqoeL5R9RSHv7eLQVN5bhfsun0AFiHZLvbqhr53Pr0XdNY9fiT8cu++TNeVUSjhYe670eDPIZPiDkcQaCCVvkbcxAvJHOWxtzbwTa14TY7bj65rTHW8x8O+/RluzYNpmzWu871j8GSSlghlcsBcrFNy4tRpNP4Vd+i70kza2ZS1XSrSxk8/sVUdetTOXaGQd2PKGtwqX/0xecOfl0dX6Mn62YZxKumreXtDinAq070O+ELL/3NpiW8jxVFSo+wQHW7EzhDtylfwSjAr4L+BGuFQcXLgQ5SarO8EoXeHsu4OVQHb0ahrAc+nYsjZZYsGuWg7eEmg3ytANU/xpFODTfiAcHbRYNt2ZN+GdZGHsRSSA8vCtZk/VZIOq54vMtMKNimtvZ4Jz5Hp/fEfADsailOogiRPasYMpmIdwpGHK0RxrRVgWD3uOSr67p2uJHBNxtcAVPRPlIzB2CkKODzzpIJdjlKhL8+uwIVRxt89WARIkmH7ylWbcbJQq+Tl4tSscTH+E08yU9M12CyRbKk6z82xYlbEVAXPbmdc3ELazfC3ISwuT7cR60c8C4YAUTTCyUD2d4j2K2kDUPvByaORWwLjocQ5UJ0PO+Ub5OkRVzs5YKYXPDN5iqXSlRJ8Mh1PziWhWWQZaqOypI+c+r+Z2aYDCJ9wMdEgRf4ZNN5YvBYDo92ZBujIlFS/3ub0DkMwb9WBseGDPWzb9BnGAzXo1aqwZW3E8/dHb/vbe3413v7fw13JndvP7x48o3mvt/hqZqfVzRM5C9sMgTouFw7QC8KnCkPXrB9f4NRFSz0+yZ5UchvE58Vdajih3l1I/rpjYufLsUQX5NYmhZLTUmPyex8hjQJXMYdTXXPegDQqYTRCLyGeC0W4tFIQR2awew23Ku7rIMcqSpK/wZKPNxsOsLn88nyshi2/qUNMVVjlOP0h2lWG+JxIhVYr6d+wvtE8md8v0mf2U+OgqrAmKA+AB5KMvFSKS6McU7vajKlvSwKQfb2ydHlyrAuPG3vXuziKvdx1eovJM1VBqllgIqY1CWeii0tfvPP4TbztbrcjRdqmG4/UNRj6Yp4YqLF1nti2pC1/pKWzlhYX7/BMeGFxX7wUPOZvanvzq8ewI/X3gyVS2FBzN0Xsw8d2dHBZgxqMnvX16/8ebnKa+18HPLrkDADpoiYnrXwuG6Of07B0haWZ/ggB9WHvFLDVzh1X8BgBIs15M/AAA=' | base64 -d | gzip -d >\"$feature_config_validator\"; then\n rm -f \"$feature_config_validator_base\" \"$feature_config_validator\" || true\n feature_config_validator=''\n fi\n rm -f \"$feature_config_validator_base\" || true\nfi\nexport UNIDESK_AJV2020_BUNDLE='/etc/unidesk-cicd-runtime-gitops/ajv2020.min.js'\nexport UNIDESK_FEATURE_CONFIG_VALIDATOR=\"${feature_config_validator:-${TMPDIR:-/tmp}/unidesk-feature-config-validator-unavailable.mjs}\"\nif ! node --input-type=module <<'NODE_UNIDESK_FEATURE_CONFIG_SCHEMA'\nimport { pathToFileURL } from 'node:url';\nconst validator = await import(pathToFileURL(process.env.UNIDESK_FEATURE_CONFIG_VALIDATOR).href);\nawait validator.runFeatureConfigSchemaValidation({ repoDir: process.env.UNIDESK_FEATURE_CONFIG_REPO_DIR, renderedRoot: process.env.UNIDESK_FEATURE_CONFIG_RENDERED_ROOT, consumer: process.env.UNIDESK_PAC_CONSUMER });\nNODE_UNIDESK_FEATURE_CONFIG_SCHEMA\nthen\n printf '{\"event\":\"feature-config-schema-validation\",\"warning\":true,\"blocking\":false,\"code\":\"feature-config-validator-process-failure\",\"mutation\":false,\"valuesPrinted\":false}\\n' >&2\nfi\nif [ -n \"$feature_config_validator\" ]; then rm -f \"$feature_config_validator\" || true; fi\nif command -v ci_timing_emit >/dev/null 2>&1; then\n ci_timing_emit feature-config-schema-validation succeeded \"$feature_config_schema_started_ms\"\nelse\n printf '{\"event\":\"ci.stage.timing\",\"stage\":\"feature-config-schema-validation\",\"status\":\"succeeded\",\"blocking\":false}\\n' >&2\nfi\n\nUNIDESK_RUNTIME_GITOPS_OVERLAY_FILE=/etc/unidesk-cicd-runtime-gitops/runtime-gitops-overlay.json node /etc/unidesk-cicd-runtime-gitops/runtime-gitops-verify.mjs\nci_timing_emit gitops-render succeeded \"$gitops_render_started_ms\"\ncheck_source_head before-push\nworkdir=\"$(mktemp -d)\"\ngitops_read_url=\"$(params.gitops-read-url)\"\ngitops_write_url=\"$(params.git-write-url)\"\ngitops_clone_started_ms=\"$(ci_now_ms)\"\ngit_timed gitops-clone 180 git clone --no-checkout \"$gitops_read_url\" \"$workdir/gitops\"\ncd \"$workdir/gitops\"\ngit remote set-url origin \"$gitops_write_url\"\nold_runtime_snapshot=\"$workdir/old-runtime-snapshot\"\nif git_timed gitops-branch-ls 45 git ls-remote --exit-code --heads origin \"$(params.gitops-branch)\" >/dev/null; then\n git_timed gitops-fetch 90 git fetch origin \"$(params.gitops-branch)\"\n git checkout -B \"$(params.gitops-branch)\" \"origin/$(params.gitops-branch)\"\n if [ \"$runtime_lane\" = \"true\" ] && [ -d \"$runtime_path\" ]; then\n mkdir -p \"$old_runtime_snapshot\"\n cp -a \"$runtime_path\"/. \"$old_runtime_snapshot\"/\n fi\n if [ \"$runtime_lane\" = \"true\" ]; then rm -rf \"$runtime_path\" \"$catalog_path\" \"$unidesk_legacy_runtime_path\"; else rm -rf deploy/gitops/node \"$catalog_path\"; fi\nelse\n git checkout --orphan \"$(params.gitops-branch)\"\n git rm -rf . >/dev/null 2>&1 || true\nfi\nci_timing_emit gitops-clone succeeded \"$gitops_clone_started_ms\"\nmkdir -p \"$(dirname \"$runtime_path\")\" \"$(dirname \"$catalog_path\")\"\nif [ \"$runtime_lane\" = \"true\" ]; then\n cp -a \"/workspace/source/repo/$runtime_path\" \"$runtime_path\"\n cp \"/workspace/source/repo/$catalog_path\" \"$catalog_path\"\n git add \"$catalog_path\" \"$runtime_path\"\n if [ -n \"${unidesk_legacy_runtime_path:-}\" ]; then git add -A \"$unidesk_legacy_runtime_path\" || true; fi\nelse\n mkdir -p deploy/gitops\n cp -a /workspace/source/repo/deploy/gitops/node deploy/gitops/node\n cp \"/workspace/source/repo/$catalog_path\" \"$catalog_path\"\n git add \"$catalog_path\" deploy/gitops/node\nfi\nif [ \"$runtime_lane\" = \"true\" ] && [ -s /workspace/source/affected-services.json ]; then\n runtime_noop_decision=\"$(node - \"$runtime_path\" \"$old_runtime_snapshot\" /workspace/source/affected-services.json <<'NODE'\nconst fs = require(\"node:fs\");\nconst path = require(\"node:path\");\n\nconst [runtimePath, oldRuntimePath, planPath] = process.argv.slice(2);\n\nfunction readJson(filePath) {\n return JSON.parse(fs.readFileSync(filePath, \"utf8\"));\n}\n\nfunction stable(value) {\n if (Array.isArray(value)) return \"[\" + value.map(stable).join(\",\") + \"]\";\n if (value && typeof value === \"object\") {\n return \"{\" + Object.keys(value).sort().map((key) => JSON.stringify(key) + \":\" + stable(value[key])).join(\",\") + \"}\";\n }\n return JSON.stringify(value);\n}\n\nfunction scrub(value) {\n if (Array.isArray(value)) return value.map(scrub);\n if (!value || typeof value !== \"object\") return value;\n const result = {};\n for (const [key, child] of Object.entries(value)) {\n if (key === \"hwlab.pikastech.local/source-commit\" ||\n key === \"hwlab.pikastech.local/artifact-source-commit\" ||\n key === \"hwlab.pikastech.local/boot-commit\" ||\n key === \"sourceCommitId\" ||\n key === \"bootCommit\") {\n result[key] = \"\";\n continue;\n }\n const envName = String(value.name || \"\");\n if (key === \"value\" && /^HWLAB_.*COMMIT/.test(envName)) {\n result[key] = \"\";\n continue;\n }\n result[key] = scrub(child);\n }\n return result;\n}\n\nfunction listFiles(rootDir) {\n if (!rootDir || !fs.existsSync(rootDir)) return null;\n const files = [];\n function walk(current) {\n for (const entry of fs.readdirSync(current, { withFileTypes: true })) {\n const fullPath = path.join(current, entry.name);\n if (entry.isDirectory()) walk(fullPath);\n else if (entry.isFile()) files.push(path.relative(rootDir, fullPath).replaceAll(path.sep, \"/\"));\n }\n }\n walk(rootDir);\n return files.sort();\n}\n\nfunction normalizedTree(rootDir) {\n const files = listFiles(rootDir);\n if (!files) return null;\n const entries = {};\n for (const relativePath of files) {\n const filePath = path.join(rootDir, relativePath);\n const text = fs.readFileSync(filePath, \"utf8\");\n try {\n entries[relativePath] = stable(scrub(JSON.parse(text)));\n } catch {\n entries[relativePath] = text.replace(/[a-f0-9]{40}/gu, \"\");\n }\n }\n return stable(entries);\n}\n\nconst plan = readJson(planPath);\nconst buildServices = Array.isArray(plan.buildServices) ? plan.buildServices : [];\nconst rolloutServices = Array.isArray(plan.rolloutServices) ? plan.rolloutServices : [];\nif (buildServices.length > 0 || rolloutServices.length > 0) {\n process.stdout.write(\"runtime-required\");\n process.exit(0);\n}\n\nconst oldTree = normalizedTree(oldRuntimePath);\nconst newTree = normalizedTree(runtimePath);\nprocess.stdout.write(oldTree && newTree && oldTree === newTree ? \"runtime-identity-only\" : \"runtime-required\");\nNODE\n)\"\n if [ \"$runtime_noop_decision\" = \"runtime-identity-only\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required\n echo '{\"status\":\"skipped-runtime-unchanged\",\"reason\":\"runtime-identity-only\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n ci_timing_emit gitops-commit skipped \"$(ci_now_ms)\"\n ci_timing_emit gitops-push skipped \"$(ci_now_ms)\"\n exit 0\n fi\nfi\nif git diff --cached --quiet; then\n printf 'false' > /tekton/results/runtime-ready-required\n echo '{\"status\":\"unchanged\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n ci_timing_emit gitops-commit unchanged \"$(ci_now_ms)\"\n ci_timing_emit gitops-push unchanged \"$(ci_now_ms)\"\n exit 0\nfi\nshort=\"$(printf '%.7s' \"$(params.revision)\")\"\ngitops_commit_started_ms=\"$(ci_now_ms)\"\ngit commit -m \"chore: promote node GitOps source $short\"\nci_timing_emit gitops-commit succeeded \"$gitops_commit_started_ms\"\ngitops_push_started_ms=\"$(ci_now_ms)\"\ngit_timed gitops-push 120 git push origin \"HEAD:$(params.gitops-branch)\"\nci_timing_emit gitops-push succeeded \"$gitops_push_started_ms\"\nif [ \"$runtime_lane\" = \"true\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required\n echo '{\"event\":\"runtime-ready\",\"phase\":\"gitops-promote\",\"status\":\"delegated-post-flush-closeout\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\nfi\nargo_hard_refresh_runtime_lane\necho '{\"status\":\"pushed\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\",\"gitopsWriteUrl\":\"'\"$gitops_write_url\"'\"}'\n" + script: "# unidesk-step-env-bootstrap\nexport HOME='/tekton/home'\nexport XDG_CONFIG_HOME='/tekton/home/.config'\nmkdir -p \"$HOME\"\nmkdir -p \"$XDG_CONFIG_HOME\"\nci_node_deps=\"${HWLAB_CI_NODE_DEPS:-/opt/hwlab-ci-node-deps/node_modules}\"\nif [ -d \"$ci_node_deps\" ]; then\n if [ -d /workspace/source/repo ]; then ci_node_deps_target=/workspace/source/repo/node_modules; else ci_node_deps_target=./node_modules; fi\n mkdir -p \"$ci_node_deps_target\"\n for ci_node_dep in yaml; do if [ -d \"$ci_node_deps/$ci_node_dep\" ] && [ ! -e \"$ci_node_deps_target/$ci_node_dep\" ]; then ln -s \"$ci_node_deps/$ci_node_dep\" \"$ci_node_deps_target/$ci_node_dep\"; fi; done\nfi\n#!/bin/sh\nset -eu\nci_now_ms() {\n node -e 'console.log(Date.now())'\n}\n\nci_timing_emit() {\n stage=\"$1\"\n status=\"$2\"\n started_ms=\"$3\"\n finished_ms=\"$(ci_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n service_id=\"${HWLAB_TIMING_SERVICE_ID:-}\"\n node -e 'const [stage,status,durationMs,serviceId]=process.argv.slice(1); const payload={event:\"node-cicd-timing\",schemaVersion:\"v1\",stage,status,durationMs:Number(durationMs),pipelineRun:process.env.HWLAB_TEKTON_PIPELINERUN||null,taskRun:process.env.HWLAB_TEKTON_TASKRUN||null,task:process.env.HWLAB_TEKTON_TASK||null,revision:process.env.HWLAB_SOURCE_REVISION||null,serviceId:serviceId||null,source:\"scripts/gitops-render.mjs\",at:new Date().toISOString()}; console.log(JSON.stringify(payload));' \"$stage\" \"$status\" \"$duration_ms\" \"$service_id\"\n}\ngit_now_ms() {\n node -e 'console.log(Date.now())' 2>/dev/null || date +%s000\n}\n\ngit_timed() {\n phase=\"$1\"\n timeout_seconds=\"$2\"\n shift 2\n started_ms=\"$(git_now_ms)\"\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"started\",\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n set +e\n timeout \"$timeout_seconds\" \"$@\"\n status=\"$?\"\n set -e\n finished_ms=\"$(git_now_ms)\"\n duration_ms=\"$((finished_ms - started_ms))\"\n if [ \"$status\" -eq 0 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"succeeded\",\"durationMs\":'\"$duration_ms\"'}' >&2\n return 0\n fi\n if [ \"$status\" -eq 124 ] || [ \"$status\" -eq 137 ]; then\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"reason\":\"timeout\",\"durationMs\":'\"$duration_ms\"',\"timeoutSeconds\":'\"$timeout_seconds\"'}' >&2\n else\n echo '{\"event\":\"git-operation\",\"phase\":\"'\"$phase\"'\",\"status\":\"failed\",\"exitCode\":'\"$status\"',\"durationMs\":'\"$duration_ms\"'}' >&2\n fi\n return \"$status\"\n}\n\nexport HWLAB_TEKTON_PIPELINERUN=\"$(context.pipelineRun.name)\"\nexport HWLAB_TEKTON_TASKRUN=\"$(context.taskRun.name)\"\nexport HWLAB_TEKTON_TASK=\"gitops-promote\"\nexport HWLAB_SOURCE_REVISION=\"$(params.revision)\"\necho '{\"event\":\"ci-base-image\",\"phase\":\"gitops-promote\",\"image\":\"127.0.0.1:5000/hwlab/hwlab-ci-node-tools:node22-alpine-bun-v1\",\"policy\":\"no-runtime-apt\"}'\nfor tool in node git timeout; do command -v \"$tool\" >/dev/null 2>&1 || { echo '{\"event\":\"ci-base-image\",\"phase\":\"gitops-promote\",\"ok\":false,\"reason\":\"missing-tool\",\"tool\":\"'\"$tool\"'\"}'; exit 31; }; done\nlane=\"$(params.lane)\"\ncase \"$lane\" in\n node) runtime_lane=false ;;\n *) runtime_lane=true ;;\nesac\nif [ \"$runtime_lane\" = \"true\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required\nelse\n printf 'true' > /tekton/results/runtime-ready-required\nfi\ntest -s /workspace/gitea-auth/token || { echo '{\"event\":\"gitea-auth\",\"phase\":\"gitops-promote\",\"status\":\"failed\",\"reason\":\"token-missing\"}'; exit 31; }\naskpass_dir=\"$(mktemp -d)\"\ncat > \"$askpass_dir/askpass.sh\" <<'SH'\n#!/bin/sh\ncase \"$1\" in\n *sername*) printf '%s\\n' \"$GITEA_USERNAME\" ;;\n *) cat /workspace/gitea-auth/token ;;\nesac\nSH\nchmod 0700 \"$askpass_dir/askpass.sh\"\nexport GITEA_USERNAME=\"$(params.gitops-username)\"\nexport GIT_ASKPASS=\"$askpass_dir/askpass.sh\"\nexport GIT_ASKPASS_REQUIRE=force\nexport GIT_TERMINAL_PROMPT=0\ncd /workspace/source/repo\ntest \"$(git rev-parse HEAD)\" = \"$(params.revision)\"\n\ncheck_source_head() {\n phase=\"$1\"\n expected=\"${2:-$(params.revision)}\"\n source_head_url=\"$(params.git-read-url)\"\n latest_file=\"$(mktemp)\"\n if ! git_timed \"source-head-$phase\" 45 git ls-remote \"$source_head_url\" \"refs/heads/$(params.source-branch)\" > \"$latest_file\"; then\n echo '{\"status\":\"failed\",\"reason\":\"source-head-check-failed\",\"phase\":\"'\"$phase\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n exit 1\n fi\n latest=\"$(cut -f1 \"$latest_file\" | head -n 1)\"\n if [ -z \"$latest\" ]; then\n echo '{\"status\":\"failed\",\"reason\":\"source-head-unresolved\",\"phase\":\"'\"$phase\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n exit 1\n fi\n if [ \"$latest\" != \"$expected\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required || true\n echo '{\"status\":\"skipped-stale-source\",\"verdict\":\"superseded\",\"phase\":\"'\"$phase\"'\",\"sourceBranch\":\"'\"$(params.source-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\",\"expectedRevision\":\"'\"$expected\"'\",\"latestRevision\":\"'\"$latest\"'\"}'\n exit 0\n fi\n}\n\ncheck_source_head before-render\nif [ -s /workspace/source/affected-services.json ] && node - /workspace/source/affected-services.json <<'NODE'\nconst fs = require(\"node:fs\");\nconst plan = JSON.parse(fs.readFileSync(process.argv[2], \"utf8\"));\nconst buildServices = Array.isArray(plan.buildServices) ? plan.buildServices : [];\nconst affectedServices = Array.isArray(plan.affectedServices) ? plan.affectedServices : [];\nprocess.exit(buildServices.length === 0 && affectedServices.length === 0 ? 0 : 1);\nNODE\nthen\n printf 'false' > /tekton/results/runtime-ready-required || true\n echo '{\"event\":\"gitops-promote\",\"status\":\"continuing\",\"reason\":\"no-build-no-rollout-plan-gitops-verify\"}' >&2\nfi\ngit config --global user.name \"HWLAB node GitOps Bot\"\ngit config --global user.email \"hwlab-node-gitops-bot@users.noreply.github.com\"\ncatalog_path=\"$(params.catalog-path)\"\nruntime_path=\"$(params.runtime-path)\"\nunidesk_legacy_runtime_path='deploy/gitops/node/runtime-v03'\ngitops_root_from_runtime_path() {\n path=\"$1\"\n case \"$path\" in\n */*) printf '%s\n' \"${path%/*}\" ;;\n *) printf '.\n' ;;\n esac\n}\ngitops_root=\"$(gitops_root_from_runtime_path \"$runtime_path\")\"\n\nargo_hard_refresh_runtime_lane() {\n if [ \"$runtime_lane\" != \"true\" ]; then return 0; fi\n ARGO_APPLICATION=\"hwlab-node-$lane\" ARGO_FIELD_MANAGER=\"hwlab-$lane-gitops-promote\" node <<'NODE'\nconst fs = require(\"node:fs\");\nconst https = require(\"node:https\");\n\nconst host = process.env.KUBERNETES_SERVICE_HOST;\nconst port = process.env.KUBERNETES_SERVICE_PORT || \"443\";\nconst startedAt = Date.now();\nconst application = process.env.ARGO_APPLICATION || \"hwlab-node-v02\";\nconst fieldManager = process.env.ARGO_FIELD_MANAGER || \"hwlab-v02-gitops-promote\";\nconst pipelineRun = process.env.HWLAB_TEKTON_PIPELINERUN || null;\nconst taskRun = process.env.HWLAB_TEKTON_TASKRUN || null;\nconst task = process.env.HWLAB_TEKTON_TASK || null;\nconst revision = process.env.HWLAB_SOURCE_REVISION || null;\n\nfunction emit(payload) {\n console.log(JSON.stringify({\n event: \"node-cicd-timing\",\n schemaVersion: \"v1\",\n stage: \"argo-hard-refresh\",\n pipelineRun,\n taskRun,\n task,\n revision,\n application,\n source: \"scripts/gitops-render.mjs\",\n at: new Date().toISOString(),\n ...payload\n }));\n}\n\nfunction safeJson(text) {\n try {\n return JSON.parse(text);\n } catch {\n return null;\n }\n}\n\nfunction request(method, path, body, contentType = \"application/merge-patch+json\") {\n const token = fs.readFileSync(\"/var/run/secrets/kubernetes.io/serviceaccount/token\", \"utf8\");\n const ca = fs.readFileSync(\"/var/run/secrets/kubernetes.io/serviceaccount/ca.crt\");\n const payload = body ? JSON.stringify(body) : \"\";\n const headers = { Authorization: \"Bearer \" + token };\n if (payload) {\n headers[\"Content-Type\"] = contentType;\n headers[\"Content-Length\"] = Buffer.byteLength(payload);\n }\n return new Promise((resolve, reject) => {\n const req = https.request({ host, port, method, path, ca, headers }, (res) => {\n let data = \"\";\n res.setEncoding(\"utf8\");\n res.on(\"data\", (chunk) => { data += chunk; });\n res.on(\"end\", () => resolve({ statusCode: res.statusCode || 0, body: data, json: safeJson(data) }));\n });\n req.on(\"error\", reject);\n if (payload) req.write(payload);\n req.end();\n });\n}\n\n(async () => {\n if (!host) {\n emit({ status: \"skipped\", reason: \"kubernetes-service-host-missing\", durationMs: Date.now() - startedAt });\n return;\n }\n const response = await request(\n \"PATCH\",\n \"/apis/argoproj.io/v1alpha1/namespaces/argocd/applications/\" + encodeURIComponent(application) + \"?fieldManager=\" + encodeURIComponent(fieldManager),\n { metadata: { annotations: { \"argocd.argoproj.io/refresh\": \"hard\" } } }\n );\n if (response.statusCode >= 200 && response.statusCode < 300) {\n emit({ status: \"succeeded\", durationMs: Date.now() - startedAt, statusCode: response.statusCode });\n return;\n }\n emit({ status: \"degraded\", reason: \"argo-refresh-patch-failed\", durationMs: Date.now() - startedAt, statusCode: response.statusCode, body: response.body.slice(0, 1000) });\n})().catch((error) => {\n emit({ status: \"degraded\", reason: \"argo-refresh-patch-error\", durationMs: Date.now() - startedAt, error: error.message });\n});\nNODE\n}\n\nif [ -s /workspace/source/dev-artifacts.json ]; then\n node scripts/refresh-artifact-catalog.mjs --lane \"$lane\" --catalog-path \"$catalog_path\" --deploy-config deploy/deploy.yaml --image-tag-mode \"$(params.image-tag-mode)\" --target-ref \"$(params.revision)\" --publish-report /workspace/source/dev-artifacts.json --write\nfi\ngitops_render_started_ms=\"$(ci_now_ms)\"\nnode - <<'NODE_UNIDESK_DEPLOY_YAML_OVERLAY'\nconst fs = require('fs');\nconst YAML = require('yaml');\nconst overlay = {\"nodeId\":\"NC01\",\"lane\":\"v03\",\"sourceBranch\":\"v0.3\",\"gitopsBranch\":\"v0.3-gitops\",\"gitopsRoot\":\"deploy/gitops/node/nc01\",\"runtimePath\":\"deploy/gitops/node/nc01/runtime-v03\",\"runtimeRenderDir\":\"runtime-v03\",\"runtimeNamespace\":\"hwlab-v03\",\"environment\":\"development\",\"catalogPath\":\"deploy/artifact-catalog.nc01-v03.json\",\"gitUrl\":\"git@github.com:pikasTech/HWLAB.git\",\"publicWebUrl\":\"https://lab-dev.hwpod.com\",\"publicApiUrl\":\"https://lab-dev.hwpod.com\",\"externalPostgres\":{\"enabled\":true,\"serviceName\":\"nc01-host-postgres\",\"endpointAddress\":\"10.42.0.1\",\"port\":5432,\"runtimeAccess\":{\"routeName\":\"nc01-host-postgres\",\"endpointAddress\":\"10.42.0.1\",\"port\":5432},\"sslmode\":\"require\"},\"runtimeStore\":{\"postgres\":{\"mode\":\"platform-service\",\"serviceName\":\"nc01-host-postgres\",\"poolMax\":16}},\"codeAgentRuntime\":{\"enabled\":true,\"adapter\":\"agentrun-v02\",\"managerUrl\":\"http://agentrun-mgr.agentrun-v02.svc.cluster.local:8080\",\"apiKeySecretName\":\"hwlab-v03-master-server-admin-api-key\",\"apiKeySecretKey\":\"api-key\",\"runnerNamespace\":\"agentrun-v02\",\"secretNamespace\":\"agentrun-v02\",\"providerSecretNames\":{\"codex\":\"agentrun-v01-provider-codex\",\"gpt-pika\":\"agentrun-v02-provider-gpt-pika\",\"grok\":\"agentrun-v02-provider-grok\",\"dsflash-go\":\"agentrun-v01-provider-dsflash-go\"},\"toolSecretNames\":{\"githubPr\":\"agentrun-v01-tool-github-pr\",\"unideskSsh\":\"agentrun-v01-tool-unidesk-ssh\"},\"repoUrlFrom\":\"runtimeGitReadUrl\",\"repoUrl\":\"http://gitea-http.devops-infra.svc.cluster.local:3000/mirrors/pikasTech-HWLAB.git\",\"providerIdFrom\":\"runtimeNodeId\",\"providerId\":\"NC01\",\"defaultProviderProfile\":\"gpt.pika\",\"codexStdioSupervisor\":\"repo-owned\",\"kafkaShadowProducer\":null,\"kafkaEventBridge\":{\"enabled\":true,\"features\":{\"directPublish\":true,\"liveKafkaSse\":true,\"kafkaRefreshReplay\":true,\"transactionalProjector\":false,\"projectionOutboxRelay\":false,\"projectionRealtime\":false},\"refreshReplay\":{\"groupIdPrefix\":\"hwlab-v03-cloud-api-sse\",\"timeoutMs\":30000,\"scanLimit\":1000000,\"matchedEventLimit\":2000,\"liveBufferLimit\":2000},\"configRef\":\"config/platform-infra/kafka.yaml#clients.hwlab-v03-cloud-api\",\"bootstrapServers\":\"platform-infra-kafka-kafka-bootstrap.platform-infra.svc.cluster.local:9092\",\"stdioTopic\":\"codex-stdio.raw.v1\",\"agentRunEventTopic\":\"agentrun.event.v1\",\"hwlabEventTopic\":\"hwlab.event.v1\",\"clientId\":\"hwlab-v03-cloud-api\",\"directPublishConsumerGroupId\":\"hwlab-agentrun-event-direct-publish\",\"transactionalProjectorConsumerGroupId\":\"hwlab-v03-agentrun-event-projector\",\"hwlabEventConsumerGroupId\":\"hwlab-v03-workbench-live-sse\"},\"valuesPrinted\":false},\"observability\":{\"prometheusOperator\":false,\"webProbe\":{\"sentinels\":[{\"id\":\"nc01-web-probe-sentinel\",\"enabled\":true,\"configRef\":\"config/hwlab-web-probe-sentinel/profiles.yaml#nodes.NC01.sentinels.nc01-web-probe-sentinel.sentinel\"}],\"monitor\":{\"configRef\":\"config/hwlab-web-probe-monitor/runtime.yaml#monitor\"},\"monitorRoot\":{\"enabled\":true,\"sentinelId\":\"nc01-web-probe-sentinel\",\"publicBaseUrl\":\"https://monitor.pikapython.com\",\"routePrefix\":\"/\",\"caddyManagedBlockOwner\":\"hwlab-web-probe-sentinel-active-root\"}},\"recordingRules\":[],\"warningAlerts\":[]},\"runtimeImageRewrites\":[{\"source\":\"fatedier/frpc:v0.68.1\",\"target\":\"127.0.0.1:5000/hwlab/frpc:v0.68.1\"},{\"source\":\"openfga/openfga:v1.17.0\",\"target\":\"127.0.0.1:5000/hwlab/openfga:v1.17.0\"},{\"source\":\"ghcr.io/anomalyco/opencode:1.17.7\",\"target\":\"127.0.0.1:5000/hwlab/opencode:1.17.7\"}],\"dockerProxyHttp\":\"http://127.0.0.1:10808\",\"dockerProxyHttps\":\"http://127.0.0.1:10808\",\"dockerNoProxyList\":[\"localhost\",\"127.0.0.1\",\"::1\",\"127.0.0.1:5000\",\"localhost:5000\",\".svc\",\".svc.cluster.local\",\".cluster.local\",\"hyueapi.com\",\".hyueapi.com\"],\"npmRegistry\":\"https://registry.npmmirror.com/\",\"npmFetchTimeoutMs\":120000,\"npmRetries\":3};\nconst file = 'deploy/deploy.yaml';\nif (!fs.existsSync(file)) {\n console.error(JSON.stringify({ event: 'unidesk-deploy-yaml-overlay', ok: false, reason: 'deploy-yaml-missing', file }));\n process.exit(45);\n}\nconst doc = YAML.parse(fs.readFileSync(file, 'utf8'));\ndoc.nodes = doc.nodes || {};\ndoc.nodes[overlay.nodeId] = { ...(doc.nodes[overlay.nodeId] || {}), gitopsRoot: overlay.gitopsRoot, sourceRepo: overlay.gitUrl };\ndoc.lanes = doc.lanes || {};\nconst lane = doc.lanes[overlay.lane] || {};\nconst envRecipe = lane.envRecipe || {};\nconst downloadStack = {\n ...(envRecipe.downloadStack || {}),\n httpProxy: overlay.dockerProxyHttp,\n httpsProxy: overlay.dockerProxyHttps,\n noProxy: overlay.dockerNoProxyList,\n};\nif (overlay.npmRegistry) downloadStack.npmRegistry = overlay.npmRegistry;\nif (overlay.npmFetchTimeoutMs) downloadStack.npmFetchTimeoutMs = overlay.npmFetchTimeoutMs;\ndoc.lanes[overlay.lane] = {\n ...lane,\n node: overlay.nodeId,\n sourceBranch: overlay.sourceBranch,\n gitopsBranch: overlay.gitopsBranch,\n namespace: overlay.runtimeNamespace,\n endpoint: overlay.publicApiUrl,\n publicEndpoints: { frontend: overlay.publicWebUrl, api: overlay.publicApiUrl },\n artifactCatalog: overlay.catalogPath,\n runtimePath: overlay.runtimeRenderDir,\n imageTagMode: 'full',\n sourceRepo: overlay.gitUrl,\n observability: overlay.observability,\n envRecipe: { ...envRecipe, downloadStack },\n};\nif (overlay.externalPostgres === undefined || overlay.externalPostgres === null) delete doc.lanes[overlay.lane].externalPostgres;\nelse doc.lanes[overlay.lane].externalPostgres = overlay.externalPostgres;\nif (overlay.runtimeStore !== undefined) doc.lanes[overlay.lane].runtimeStore = overlay.runtimeStore;\nif (overlay.codeAgentRuntime !== undefined) doc.lanes[overlay.lane].codeAgentRuntime = overlay.codeAgentRuntime;\nfs.writeFileSync(file, YAML.stringify(doc));\nconsole.error(JSON.stringify({ event: 'unidesk-deploy-yaml-overlay', ok: true, lane: overlay.lane, httpProxy: overlay.dockerProxyHttp, noProxyCount: overlay.dockerNoProxyList.length }));\nNODE_UNIDESK_DEPLOY_YAML_OVERLAY\nnode scripts/run-bun.mjs scripts/gitops-render.mjs --lane \"$lane\" --catalog-path \"$catalog_path\" --image-tag-mode \"$(params.image-tag-mode)\" --source-revision \"$(params.revision)\" --source-repo \"$(params.git-url)\" --source-branch \"$(params.source-branch)\" --gitops-branch \"$(params.gitops-branch)\" --gitops-root \"deploy/gitops/node/nc01\" --out \"deploy/gitops/node/nc01\" --registry-prefix \"$(params.registry-prefix)\" --use-deploy-images\nUNIDESK_RUNTIME_GITOPS_OVERLAY_FILE=/etc/unidesk-cicd-runtime-gitops/runtime-gitops-overlay.json node /etc/unidesk-cicd-runtime-gitops/runtime-gitops-postprocess.mjs\nfeature_config_schema_started_ms=\"$(date +%s%3N 2>/dev/null || date +%s000)\"\nexport UNIDESK_FEATURE_CONFIG_REPO_DIR=\"$PWD\"\nexport UNIDESK_FEATURE_CONFIG_RENDERED_ROOT=\"deploy/gitops/node/nc01/runtime-v03\"\nexport UNIDESK_PAC_CONSUMER='hwlab-nc01-v03'\nexport OTEL_EXPORTER_OTLP_TRACES_ENDPOINT='http://otel-collector.platform-infra.svc.cluster.local:4318/v1/traces'\nexport OTEL_SERVICE_NAME='unidesk-cicd'\nexport OTEL_TRACES_SAMPLER_ARG='1'\nexport OTEL_EXPORTER_TIMEOUT_MS='300'\nfeature_config_validator=''\nfeature_config_validator='/etc/unidesk-cicd-runtime-gitops/feature-config-schema-warning.mjs'\nexport UNIDESK_AJV2020_BUNDLE='/etc/unidesk-cicd-runtime-gitops/ajv2020.min.js'\nexport UNIDESK_FEATURE_CONFIG_VALIDATOR=\"${feature_config_validator:-${TMPDIR:-/tmp}/unidesk-feature-config-validator-unavailable.mjs}\"\nif ! node --input-type=module <<'NODE_UNIDESK_FEATURE_CONFIG_SCHEMA'\nimport { pathToFileURL } from 'node:url';\nconst validator = await import(pathToFileURL(process.env.UNIDESK_FEATURE_CONFIG_VALIDATOR).href);\nawait validator.runFeatureConfigSchemaValidation({ repoDir: process.env.UNIDESK_FEATURE_CONFIG_REPO_DIR, renderedRoot: process.env.UNIDESK_FEATURE_CONFIG_RENDERED_ROOT, consumer: process.env.UNIDESK_PAC_CONSUMER });\nNODE_UNIDESK_FEATURE_CONFIG_SCHEMA\nthen\n printf '{\"event\":\"feature-config-schema-validation\",\"warning\":true,\"blocking\":false,\"code\":\"feature-config-validator-process-failure\",\"mutation\":false,\"valuesPrinted\":false}\\n' >&2\nfi\nif command -v ci_timing_emit >/dev/null 2>&1; then\n ci_timing_emit feature-config-schema-validation succeeded \"$feature_config_schema_started_ms\"\nelse\n printf '{\"event\":\"ci.stage.timing\",\"stage\":\"feature-config-schema-validation\",\"status\":\"succeeded\",\"blocking\":false}\\n' >&2\nfi\n\nUNIDESK_RUNTIME_GITOPS_OVERLAY_FILE=/etc/unidesk-cicd-runtime-gitops/runtime-gitops-overlay.json node /etc/unidesk-cicd-runtime-gitops/runtime-gitops-verify.mjs\nci_timing_emit gitops-render succeeded \"$gitops_render_started_ms\"\ncheck_source_head before-push\nworkdir=\"$(mktemp -d)\"\ngitops_read_url=\"$(params.gitops-read-url)\"\ngitops_write_url=\"$(params.git-write-url)\"\ngitops_clone_started_ms=\"$(ci_now_ms)\"\ngit_timed gitops-clone 180 git clone --no-checkout \"$gitops_read_url\" \"$workdir/gitops\"\ncd \"$workdir/gitops\"\ngit remote set-url origin \"$gitops_write_url\"\nold_runtime_snapshot=\"$workdir/old-runtime-snapshot\"\nif git_timed gitops-branch-ls 45 git ls-remote --exit-code --heads origin \"$(params.gitops-branch)\" >/dev/null; then\n git_timed gitops-fetch 90 git fetch origin \"$(params.gitops-branch)\"\n git checkout -B \"$(params.gitops-branch)\" \"origin/$(params.gitops-branch)\"\n if [ \"$runtime_lane\" = \"true\" ] && [ -d \"$runtime_path\" ]; then\n mkdir -p \"$old_runtime_snapshot\"\n cp -a \"$runtime_path\"/. \"$old_runtime_snapshot\"/\n fi\n if [ \"$runtime_lane\" = \"true\" ]; then rm -rf \"$runtime_path\" \"$catalog_path\" \"$unidesk_legacy_runtime_path\"; else rm -rf deploy/gitops/node \"$catalog_path\"; fi\nelse\n git checkout --orphan \"$(params.gitops-branch)\"\n git rm -rf . >/dev/null 2>&1 || true\nfi\nci_timing_emit gitops-clone succeeded \"$gitops_clone_started_ms\"\nmkdir -p \"$(dirname \"$runtime_path\")\" \"$(dirname \"$catalog_path\")\"\nif [ \"$runtime_lane\" = \"true\" ]; then\n cp -a \"/workspace/source/repo/$runtime_path\" \"$runtime_path\"\n cp \"/workspace/source/repo/$catalog_path\" \"$catalog_path\"\n git add \"$catalog_path\" \"$runtime_path\"\n if [ -n \"${unidesk_legacy_runtime_path:-}\" ]; then git add -A \"$unidesk_legacy_runtime_path\" || true; fi\nelse\n mkdir -p deploy/gitops\n cp -a /workspace/source/repo/deploy/gitops/node deploy/gitops/node\n cp \"/workspace/source/repo/$catalog_path\" \"$catalog_path\"\n git add \"$catalog_path\" deploy/gitops/node\nfi\nif [ \"$runtime_lane\" = \"true\" ] && [ -s /workspace/source/affected-services.json ]; then\n runtime_noop_decision=\"$(node - \"$runtime_path\" \"$old_runtime_snapshot\" /workspace/source/affected-services.json <<'NODE'\nconst fs = require(\"node:fs\");\nconst path = require(\"node:path\");\n\nconst [runtimePath, oldRuntimePath, planPath] = process.argv.slice(2);\n\nfunction readJson(filePath) {\n return JSON.parse(fs.readFileSync(filePath, \"utf8\"));\n}\n\nfunction stable(value) {\n if (Array.isArray(value)) return \"[\" + value.map(stable).join(\",\") + \"]\";\n if (value && typeof value === \"object\") {\n return \"{\" + Object.keys(value).sort().map((key) => JSON.stringify(key) + \":\" + stable(value[key])).join(\",\") + \"}\";\n }\n return JSON.stringify(value);\n}\n\nfunction scrub(value) {\n if (Array.isArray(value)) return value.map(scrub);\n if (!value || typeof value !== \"object\") return value;\n const result = {};\n for (const [key, child] of Object.entries(value)) {\n if (key === \"hwlab.pikastech.local/source-commit\" ||\n key === \"hwlab.pikastech.local/artifact-source-commit\" ||\n key === \"hwlab.pikastech.local/boot-commit\" ||\n key === \"sourceCommitId\" ||\n key === \"bootCommit\") {\n result[key] = \"\";\n continue;\n }\n const envName = String(value.name || \"\");\n if (key === \"value\" && /^HWLAB_.*COMMIT/.test(envName)) {\n result[key] = \"\";\n continue;\n }\n result[key] = scrub(child);\n }\n return result;\n}\n\nfunction listFiles(rootDir) {\n if (!rootDir || !fs.existsSync(rootDir)) return null;\n const files = [];\n function walk(current) {\n for (const entry of fs.readdirSync(current, { withFileTypes: true })) {\n const fullPath = path.join(current, entry.name);\n if (entry.isDirectory()) walk(fullPath);\n else if (entry.isFile()) files.push(path.relative(rootDir, fullPath).replaceAll(path.sep, \"/\"));\n }\n }\n walk(rootDir);\n return files.sort();\n}\n\nfunction normalizedTree(rootDir) {\n const files = listFiles(rootDir);\n if (!files) return null;\n const entries = {};\n for (const relativePath of files) {\n const filePath = path.join(rootDir, relativePath);\n const text = fs.readFileSync(filePath, \"utf8\");\n try {\n entries[relativePath] = stable(scrub(JSON.parse(text)));\n } catch {\n entries[relativePath] = text.replace(/[a-f0-9]{40}/gu, \"\");\n }\n }\n return stable(entries);\n}\n\nconst plan = readJson(planPath);\nconst buildServices = Array.isArray(plan.buildServices) ? plan.buildServices : [];\nconst rolloutServices = Array.isArray(plan.rolloutServices) ? plan.rolloutServices : [];\nif (buildServices.length > 0 || rolloutServices.length > 0) {\n process.stdout.write(\"runtime-required\");\n process.exit(0);\n}\n\nconst oldTree = normalizedTree(oldRuntimePath);\nconst newTree = normalizedTree(runtimePath);\nprocess.stdout.write(oldTree && newTree && oldTree === newTree ? \"runtime-identity-only\" : \"runtime-required\");\nNODE\n)\"\n if [ \"$runtime_noop_decision\" = \"runtime-identity-only\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required\n echo '{\"status\":\"skipped-runtime-unchanged\",\"reason\":\"runtime-identity-only\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n ci_timing_emit gitops-commit skipped \"$(ci_now_ms)\"\n ci_timing_emit gitops-push skipped \"$(ci_now_ms)\"\n exit 0\n fi\nfi\nif git diff --cached --quiet; then\n printf 'false' > /tekton/results/runtime-ready-required\n echo '{\"status\":\"unchanged\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\n ci_timing_emit gitops-commit unchanged \"$(ci_now_ms)\"\n ci_timing_emit gitops-push unchanged \"$(ci_now_ms)\"\n exit 0\nfi\nshort=\"$(printf '%.7s' \"$(params.revision)\")\"\ngitops_commit_started_ms=\"$(ci_now_ms)\"\ngit commit -m \"chore: promote node GitOps source $short\"\nci_timing_emit gitops-commit succeeded \"$gitops_commit_started_ms\"\ngitops_push_started_ms=\"$(ci_now_ms)\"\ngit_timed gitops-push 120 git push origin \"HEAD:$(params.gitops-branch)\"\nci_timing_emit gitops-push succeeded \"$gitops_push_started_ms\"\nif [ \"$runtime_lane\" = \"true\" ]; then\n printf 'false' > /tekton/results/runtime-ready-required\n echo '{\"event\":\"runtime-ready\",\"phase\":\"gitops-promote\",\"status\":\"delegated-post-flush-closeout\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\"}'\nfi\nargo_hard_refresh_runtime_lane\necho '{\"status\":\"pushed\",\"gitopsBranch\":\"'\"$(params.gitops-branch)\"'\",\"sourceRevision\":\"'\"$(params.revision)\"'\",\"gitopsWriteUrl\":\"'\"$gitops_write_url\"'\"}'\n" imagePullPolicy: Always volumeMounts: - name: unidesk-runtime-gitops-scripts @@ -821,6 +576,20 @@ spec: name: hwlab-nc01-v03-ci-image-publish-runtime-gitops-scripts defaultMode: 493 params: + - name: revision + value: $(params.revision) + - name: lane + value: $(params.lane) + - name: catalog-path + value: $(params.catalog-path) + - name: image-tag-mode + value: $(params.image-tag-mode) + - name: registry-prefix + value: $(params.registry-prefix) + - name: services + value: $(params.services) + - name: base-image + value: $(params.base-image) - name: git-url value: $(params.git-url) - name: git-read-url @@ -835,15 +604,5 @@ spec: value: $(params.source-branch) - name: gitops-branch value: $(params.gitops-branch) - - name: lane - value: $(params.lane) - - name: catalog-path - value: $(params.catalog-path) - - name: image-tag-mode - value: $(params.image-tag-mode) - name: runtime-path value: $(params.runtime-path) - - name: revision - value: $(params.revision) - - name: registry-prefix - value: $(params.registry-prefix) diff --git a/scripts/ci-plan.test.mjs b/scripts/ci-plan.test.mjs index 12c0c7bc..f78e572e 100644 --- a/scripts/ci-plan.test.mjs +++ b/scripts/ci-plan.test.mjs @@ -129,14 +129,23 @@ test("tracked PaC remote pipelines pass selected services to catalog restore", a for (const target of targets) { const pipeline = await readStructuredFile(process.cwd(), target.pipelinePath); assert.equal(pipeline.metadata?.name, target.pipelineName, `${target.node} tracked Pipeline name`); + assert.deepEqual(pipeline.spec?.tasks?.map((task) => task.name), ["plan-artifacts", "build-services", "release-artifacts"]); const planArtifacts = pipeline.spec?.tasks?.find((task) => task.name === "plan-artifacts"); assert.ok(planArtifacts, `${target.node} tracked Pipeline plan-artifacts task`); assert.ok(planArtifacts.taskSpec?.params?.some((param) => param.name === "services"), `${target.node} plan-artifacts services param`); assert.ok(planArtifacts.params?.some((param) => param.name === "services" && param.value === "$(params.services)"), `${target.node} plan-artifacts services binding`); - const script = planArtifacts.taskSpec?.steps?.[0]?.script ?? ""; + assert.deepEqual(planArtifacts.taskSpec?.steps?.map((step) => step.name), [ + "prepare-source", + "plan" + ]); + const script = planArtifacts.taskSpec?.steps?.find((step) => step.name === "plan")?.script ?? ""; assert.match(script, /HWLAB_SERVICES="\$\(params\.services\)" node scripts\/ci\/restore-artifact-catalog\.mjs/u); assert.match(script, /rolloutWithoutImageBuildServices/u); assert.match(script, /artifactCatalog: plan\.artifactCatalog/u); + const buildServices = pipeline.spec?.tasks?.find((task) => task.name === "build-services"); + assert.deepEqual(buildServices?.when, [{ input: "$(tasks.plan-artifacts.results.build-required)", operator: "in", values: ["true"] }]); + const releaseArtifacts = pipeline.spec?.tasks?.find((task) => task.name === "release-artifacts"); + assert.deepEqual(releaseArtifacts?.taskSpec?.steps?.map((step) => step.name), ["collect", "promote"]); const pac = await readStructuredFile(process.cwd(), target.pacPath); assert.equal(pac.metadata?.annotations?.["pipelinesascode.tekton.dev/pipeline"], target.pipelinePath, `${target.node} PaC remote Pipeline path`); diff --git a/scripts/src/gitops-render/tekton-manifests.mjs b/scripts/src/gitops-render/tekton-manifests.mjs index 5fe20637..75af5c39 100644 --- a/scripts/src/gitops-render/tekton-manifests.mjs +++ b/scripts/src/gitops-render/tekton-manifests.mjs @@ -322,7 +322,7 @@ function planArtifactsTask({ serviceIds = defaultServiceIds } = {}) { results: serviceIds.flatMap((serviceId) => [ { name: affectedResultName(serviceId), description: `${serviceId} rollout affected according to ci-plan` }, { name: buildResultName(serviceId), description: `${serviceId} image build required according to ci-plan` } - ]), + ]).concat([{ name: "build-required", description: "true when at least one planned service image must be built" }]), workspaces: [{ name: "source" }], steps: [{ name: "plan", @@ -402,12 +402,46 @@ function perServiceBuildTask(serviceId, { runAfter = ["plan-artifacts"] } = {}) function perServiceBuildMatrixTask(serviceIds, { runAfter = ["plan-artifacts"] } = {}) { const task = perServiceBuildTask(serviceIds[0], { runAfter }); task.name = "build-services"; - delete task.when; + task.when = [{ input: "$(tasks.plan-artifacts.results.build-required)", operator: "in", values: ["true"] }]; task.params = task.params.filter((param) => param.name !== "service-id"); task.matrix = { params: [{ name: "service-id", value: serviceIds }] }; return task; } +function mergeNamedEntries(...groups) { + const entries = new Map(); + for (const group of groups) { + for (const entry of group || []) { + if (!entries.has(entry.name)) entries.set(entry.name, entry); + } + } + return [...entries.values()]; +} + +function releasePlanTask({ serviceIds = defaultServiceIds } = {}) { + const plan = planArtifactsTask({ serviceIds }); + const prepareParams = [ + { name: "git-url" }, { name: "git-read-url" }, { name: "gitops-read-url" }, { name: "source-branch" }, + { name: "gitops-branch" }, { name: "lane" }, { name: "catalog-path" }, { name: "image-tag-mode" }, + { name: "registry-prefix" }, { name: "services" }, { name: "revision" } + ]; + const prepareBindings = prepareParams.map(({ name }) => ({ name, value: `$(params.${name})` })); + return { + name: "plan-artifacts", + workspaces: [{ name: "source", workspace: "source" }], + taskSpec: { + params: mergeNamedEntries(prepareParams, plan.taskSpec.params), + results: plan.taskSpec.results, + workspaces: [{ name: "source" }], + steps: [ + { name: "prepare-source", image: ciToolsRunnerImage, env: proxyEnv(), script: prepareSourceScript() }, + plan.taskSpec.steps[0] + ] + }, + params: mergeNamedEntries(prepareBindings, plan.params) + }; +} + function collectArtifactsTask({ serviceIds = defaultServiceIds } = {}) { return { name: "collect-artifacts", @@ -438,6 +472,52 @@ function collectArtifactsTask({ serviceIds = defaultServiceIds } = {}) { }; } +function gitopsPromoteTask() { + return { + name: "gitops-promote", + workspaces: [ + { name: "source", workspace: "source" }, + { name: "gitea-auth", workspace: "gitea-auth" } + ], + taskSpec: { + params: [ + { name: "git-url" }, { name: "git-read-url" }, { name: "gitops-read-url" }, { name: "git-write-url" }, { name: "gitops-username" }, + { name: "source-branch" }, { name: "gitops-branch" }, { name: "lane" }, { name: "catalog-path" }, + { name: "image-tag-mode" }, { name: "runtime-path" }, { name: "revision" }, { name: "registry-prefix" } + ], + results: [{ name: "runtime-ready-required", description: "true when GitOps promotion changed runtime desired state and runtime readiness must be observed" }], + workspaces: [{ name: "source" }, { name: "gitea-auth" }], + steps: [{ name: "promote", image: ciToolsRunnerImage, env: proxyEnv(), script: gitopsPromoteScript() }] + }, + params: [ + { name: "git-url", value: "$(params.git-url)" }, { name: "git-read-url", value: "$(params.git-read-url)" }, + { name: "gitops-read-url", value: "$(params.gitops-read-url)" }, { name: "git-write-url", value: "$(params.git-write-url)" }, + { name: "gitops-username", value: "$(params.gitops-username)" }, { name: "source-branch", value: "$(params.source-branch)" }, + { name: "gitops-branch", value: "$(params.gitops-branch)" }, { name: "lane", value: "$(params.lane)" }, + { name: "catalog-path", value: "$(params.catalog-path)" }, { name: "image-tag-mode", value: "$(params.image-tag-mode)" }, + { name: "runtime-path", value: "$(params.runtime-path)" }, { name: "revision", value: "$(params.revision)" }, + { name: "registry-prefix", value: "$(params.registry-prefix)" } + ] + }; +} + +function releaseArtifactsTask({ serviceIds = defaultServiceIds } = {}) { + const collect = collectArtifactsTask({ serviceIds }); + const promote = gitopsPromoteTask(); + return { + name: "release-artifacts", + runAfter: ["build-services"], + workspaces: promote.workspaces, + taskSpec: { + params: mergeNamedEntries(collect.taskSpec.params, promote.taskSpec.params), + results: promote.taskSpec.results, + workspaces: promote.taskSpec.workspaces, + steps: [collect.taskSpec.steps[0], promote.taskSpec.steps[0]] + }, + params: mergeNamedEntries(collect.params, promote.params) + }; +} + function runtimeReadyScript() { return `#!/bin/sh set -eu @@ -549,12 +629,13 @@ function tektonTasks(args = { lane: "node" }, deploy = null) { function tektonPipeline(args = { lane: "node" }, deploy = null) { const settings = ciLaneSettings(args, deploy); + const serviceIds = serviceIdsForLane(args.lane, deploy); const runtimePath = gitopsPathForProfile(args, settings.profile, deploy); const preFlushRuntimeReadyTasks = isRuntimeLane(settings.lane) ? [] : [{ ...runtimeReadyTask({ profile: settings.profile, deploy }), - when: [{ input: "$(tasks.gitops-promote.results.runtime-ready-required)", operator: "in", values: ["true"] }] + when: [{ input: "$(tasks.release-artifacts.results.runtime-ready-required)", operator: "in", values: ["true"] }] }]; return { apiVersion: "tekton.dev/v1", @@ -567,9 +648,9 @@ function tektonPipeline(args = { lane: "node" }, deploy = null) { "hwlab.pikastech.local/gitops-target": settings.gitopsTarget }, annotations: { - "hwlab.pikastech.local/source-config": "scripts/gitops-render.mjs#tekton-native-primitive-ci", - "hwlab.pikastech.local/ci-contract": "tekton-native-primitive-tasks", - "hwlab.pikastech.local/policy": "native-per-service-taskrun-image-publish" + "hwlab.pikastech.local/source-config": "scripts/gitops-render.mjs#bounded-release-taskruns", + "hwlab.pikastech.local/ci-contract": "plan-build-release-taskruns", + "hwlab.pikastech.local/policy": "reviewed-plan-exact-scope" } }, spec: { @@ -601,87 +682,9 @@ function tektonPipeline(args = { lane: "node" }, deploy = null) { { name: "gitea-auth" } ], tasks: [ - { - name: "prepare-source", - workspaces: [ - { name: "source", workspace: "source" } - ], - taskSpec: { - params: [ - { name: "git-url" }, - { name: "git-read-url" }, - { name: "gitops-read-url" }, - { name: "source-branch" }, - { name: "gitops-branch" }, - { name: "lane" }, - { name: "catalog-path" }, - { name: "image-tag-mode" }, - { name: "registry-prefix" }, - { name: "services" }, - { name: "revision" } - ], - workspaces: [{ name: "source" }], - steps: [{ name: "prepare-source", image: ciToolsRunnerImage, env: proxyEnv(), script: prepareSourceScript() }] - }, - params: [ - { name: "git-url", value: "$(params.git-url)" }, - { name: "git-read-url", value: "$(params.git-read-url)" }, - { name: "gitops-read-url", value: "$(params.gitops-read-url)" }, - { name: "source-branch", value: "$(params.source-branch)" }, - { name: "gitops-branch", value: "$(params.gitops-branch)" }, - { name: "lane", value: "$(params.lane)" }, - { name: "catalog-path", value: "$(params.catalog-path)" }, - { name: "image-tag-mode", value: "$(params.image-tag-mode)" }, - { name: "registry-prefix", value: "$(params.registry-prefix)" }, - { name: "services", value: "$(params.services)" }, - { name: "revision", value: "$(params.revision)" } - ] - }, - ...primitiveValidationTasks.map(primitiveValidationTask), - ...imagePublishTaskSet(args, deploy), - { - name: "gitops-promote", - runAfter: ["collect-artifacts"], - workspaces: [ - { name: "source", workspace: "source" }, - { name: "gitea-auth", workspace: "gitea-auth" } - ], - taskSpec: { - params: [ - { name: "git-url" }, - { name: "git-read-url" }, - { name: "gitops-read-url" }, - { name: "git-write-url" }, - { name: "gitops-username" }, - { name: "source-branch" }, - { name: "gitops-branch" }, - { name: "lane" }, - { name: "catalog-path" }, - { name: "image-tag-mode" }, - { name: "runtime-path" }, - { name: "revision" }, - { name: "registry-prefix" } - ], - results: [{ name: "runtime-ready-required", description: "true when GitOps promotion changed runtime desired state and runtime readiness must be observed" }], - workspaces: [{ name: "source" }, { name: "gitea-auth" }], - steps: [{ name: "promote", image: ciToolsRunnerImage, env: proxyEnv(), script: gitopsPromoteScript() }] - }, - params: [ - { name: "git-url", value: "$(params.git-url)" }, - { name: "git-read-url", value: "$(params.git-read-url)" }, - { name: "gitops-read-url", value: "$(params.gitops-read-url)" }, - { name: "git-write-url", value: "$(params.git-write-url)" }, - { name: "gitops-username", value: "$(params.gitops-username)" }, - { name: "source-branch", value: "$(params.source-branch)" }, - { name: "gitops-branch", value: "$(params.gitops-branch)" }, - { name: "lane", value: "$(params.lane)" }, - { name: "catalog-path", value: "$(params.catalog-path)" }, - { name: "image-tag-mode", value: "$(params.image-tag-mode)" }, - { name: "runtime-path", value: "$(params.runtime-path)" }, - { name: "revision", value: "$(params.revision)" }, - { name: "registry-prefix", value: "$(params.registry-prefix)" } - ] - }, + releasePlanTask({ serviceIds }), + perServiceBuildMatrixTask(serviceIds, { runAfter: ["plan-artifacts"] }), + releaseArtifactsTask({ serviceIds }), ...preFlushRuntimeReadyTasks ] } diff --git a/scripts/src/gitops-render/templates/plan-artifacts.sh b/scripts/src/gitops-render/templates/plan-artifacts.sh index 6fd07c5e..b74224d7 100644 --- a/scripts/src/gitops-render/templates/plan-artifacts.sh +++ b/scripts/src/gitops-render/templates/plan-artifacts.sh @@ -38,6 +38,7 @@ const entries = allServices.map((serviceId) => { codeChanged: service.codeChanged ?? null }; }); +fs.writeFileSync("/tekton/results/build-required", entries.some((entry) => entry.buildRequired) ? "true" : "false"); for (const entry of entries) { fs.writeFileSync("/tekton/results/affected-" + entry.serviceId, entry.affected ? "true" : "false"); fs.writeFileSync("/tekton/results/build-" + entry.serviceId, entry.buildRequired ? "true" : "false");