ci: use the dind containerd snapshotter so the docker driver can push/cache to Harbor over plain HTTP
This commit is contained in:
+38
-21
@@ -4,7 +4,6 @@ stages:
|
||||
|
||||
variables:
|
||||
DOCKER_HOST: tcp://docker:2375
|
||||
DOCKER_DRIVER: overlay2
|
||||
DOCKER_TLS_CERTDIR: ""
|
||||
DOCKER_BUILDKIT: "1"
|
||||
# apt mirror used inside both images (override per pipeline if needed)
|
||||
@@ -14,13 +13,29 @@ variables:
|
||||
HARBOR_PROJECT: "openra3"
|
||||
IMAGE: "$HARBOR_HOST/$HARBOR_PROJECT/$CI_PROJECT_NAME"
|
||||
|
||||
# dind pulls docker.io images through the intranet Harbor pull-through cache.
|
||||
# NOTE: anchor only the *array* so `services: *dind` stays an array.
|
||||
# dind: pull docker.io through the intranet Harbor proxy (plain HTTP ->
|
||||
# --insecure-registry) and enable the containerd snapshotter so the *docker*
|
||||
# driver can export the registry BuildKit cache (the classic overlay2 driver
|
||||
# rejects it). Anchor is an array, so `services: *dind` stays an array.
|
||||
.dind: &dind
|
||||
- name: docker:dind
|
||||
command:
|
||||
- --registry-mirror=http://192.168.1.11:9090/dockerhub
|
||||
- --insecure-registry=192.168.1.11:9090
|
||||
- --feature=containerd-snapshotter=true
|
||||
|
||||
# Retry helper for transient network failures (login / build / push / pull).
|
||||
.retry: &retry
|
||||
- |
|
||||
retry() {
|
||||
n=0
|
||||
until "$@"; do
|
||||
n=$((n + 1))
|
||||
[ "$n" -ge 5 ] && { echo "failed after $n tries: $*" >&2; return 1; }
|
||||
echo "attempt $n failed, retrying: $*" >&2
|
||||
sleep 15
|
||||
done
|
||||
}
|
||||
|
||||
# --- build the two isolated toolchain images and push them to Harbor ----------
|
||||
linux_image:
|
||||
@@ -29,19 +44,18 @@ linux_image:
|
||||
services: *dind
|
||||
tags:
|
||||
- docker
|
||||
before_script: *retry
|
||||
script:
|
||||
- echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin
|
||||
# Registry cache export needs the docker-container driver, not the default
|
||||
# docker driver ("Cache export is not supported for the docker driver").
|
||||
- docker buildx create --use --name ci-builder --driver docker-container
|
||||
- retry sh -c 'echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin'
|
||||
- |
|
||||
docker buildx build \
|
||||
--cache-from type=registry,ref=$IMAGE:cache-linux \
|
||||
--cache-to type=registry,ref=$IMAGE:cache-linux,mode=max \
|
||||
retry docker build \
|
||||
--cache-from type=registry,ref=$IMAGE:cache-linux,insecure=true \
|
||||
--cache-to type=registry,ref=$IMAGE:cache-linux,mode=max,insecure=true \
|
||||
--build-arg APT_MIRROR=$APT_MIRROR \
|
||||
--target dev \
|
||||
-t $IMAGE:$CI_COMMIT_SHORT_SHA-linux \
|
||||
--push -f Dockerfile .
|
||||
-f Dockerfile .
|
||||
- retry docker push $IMAGE:$CI_COMMIT_SHORT_SHA-linux
|
||||
|
||||
windows_image:
|
||||
stage: image
|
||||
@@ -49,17 +63,18 @@ windows_image:
|
||||
services: *dind
|
||||
tags:
|
||||
- docker
|
||||
before_script: *retry
|
||||
script:
|
||||
- echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin
|
||||
- docker buildx create --use --name ci-builder --driver docker-container
|
||||
- retry sh -c 'echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin'
|
||||
- |
|
||||
docker buildx build \
|
||||
--cache-from type=registry,ref=$IMAGE:cache-windows \
|
||||
--cache-to type=registry,ref=$IMAGE:cache-windows,mode=max \
|
||||
retry docker build \
|
||||
--cache-from type=registry,ref=$IMAGE:cache-windows,insecure=true \
|
||||
--cache-to type=registry,ref=$IMAGE:cache-windows,mode=max,insecure=true \
|
||||
--build-arg APT_MIRROR=$APT_MIRROR \
|
||||
--target dev \
|
||||
-t $IMAGE:$CI_COMMIT_SHORT_SHA-windows \
|
||||
--push -f Dockerfile.win .
|
||||
-f Dockerfile.win .
|
||||
- retry docker push $IMAGE:$CI_COMMIT_SHORT_SHA-windows
|
||||
|
||||
# --- build and test each target ----------------------------------------------
|
||||
build_linux:
|
||||
@@ -70,9 +85,10 @@ build_linux:
|
||||
- docker
|
||||
needs:
|
||||
- linux_image
|
||||
before_script: *retry
|
||||
script:
|
||||
- echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin
|
||||
- docker pull $IMAGE:$CI_COMMIT_SHORT_SHA-linux
|
||||
- retry sh -c 'echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin'
|
||||
- retry docker pull $IMAGE:$CI_COMMIT_SHORT_SHA-linux
|
||||
- docker run --rm -v "$(pwd):/work" -w /work $IMAGE:$CI_COMMIT_SHORT_SHA-linux cmake -S . -B build/linux -G Ninja -DCMAKE_BUILD_TYPE=Release
|
||||
- docker run --rm -v "$(pwd):/work" -w /work $IMAGE:$CI_COMMIT_SHORT_SHA-linux cmake --build build/linux -j
|
||||
- docker run --rm -v "$(pwd):/work" -w /work $IMAGE:$CI_COMMIT_SHORT_SHA-linux ctest --test-dir build/linux --output-on-failure
|
||||
@@ -91,9 +107,10 @@ build_windows:
|
||||
- docker
|
||||
needs:
|
||||
- windows_image
|
||||
before_script: *retry
|
||||
script:
|
||||
- echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin
|
||||
- docker pull $IMAGE:$CI_COMMIT_SHORT_SHA-windows
|
||||
- retry sh -c 'echo "$HARBOR_PASSWORD" | docker login "$HARBOR_HOST" -u "$HARBOR_USERNAME" --password-stdin'
|
||||
- retry docker pull $IMAGE:$CI_COMMIT_SHORT_SHA-windows
|
||||
- docker run --rm -v "$(pwd):/work" -w /work $IMAGE:$CI_COMMIT_SHORT_SHA-windows
|
||||
cmake -S . -B build/windows -G Ninja
|
||||
-DCMAKE_TOOLCHAIN_FILE=cmake/toolchains/llvm-mingw-x86_64.cmake
|
||||
|
||||
Reference in New Issue
Block a user