initial commit

This commit is contained in:
Gildas Fargeas
2025-02-21 16:54:41 +09:00
commit 335ca9c71e
12 changed files with 659 additions and 0 deletions
+8
View File
@@ -0,0 +1,8 @@
forge 'forge.puppetlabs.com'
mod 'puppetlabs-stdlib', '9.7.0'
mod 'puppetlabs-docker', '10.1.0'
mod 'puppetlabs-apt', '9.4.0'
mod 'puppetlabs-powershell', '6.0.2'
mod 'puppetlabs-reboot', '5.1.0'
mod 'puppet-archive', '7.1.0'
mod 'nerd', :local => true
@@ -0,0 +1,13 @@
{
<%= @docker_config_host %>
"log-driver": "json-file",
"log-opts": {
"max-size": "10m",
"max-file": "3"
},
"userland-proxy": false,
"default-address-pools": [{
"base": "172.16.0.0/16",
"size": 26
}]
}
@@ -0,0 +1,4 @@
FROM jenkins/agent:latest
USER root
RUN apt update && apt install -y curl cmake build-essential
USER jenkins
@@ -0,0 +1,6 @@
FROM jenkins/jenkins:2.479.3-lts
USER jenkins
ENV JAVA_OPTS -Djenkins.install.runSetupWizard=false
COPY --chown=jenkins:jenkins plugins.txt /usr/share/jenkins/ref/plugins.txt
RUN jenkins-plugin-cli -f /usr/share/jenkins/ref/plugins.txt --latest false
@@ -0,0 +1,49 @@
version: "3.5"
networks:
default:
internal: false
ipam:
config:
- subnet: 172.16.10.0/26
services:
nginx:
image: nginx:alpine
ports:
- 80:80
volumes:
- /srv/docker/proxy/nginx-conf:/etc/nginx/conf.d:ro
- /srv/docker/proxy/nginx-logs:/var/log/nginx
restart: always
jenkins_server:
build: ../jenkins_server
container_name: server
hostname: server
restart: unless-stopped
expose:
- "8080"
- "50000"
volumes:
- /srv/docker/jenkins_server/home:/var/jenkins_home
- /srv/docker/jenkins_server/logs:/var/jenkins_home/logs
- /srv/docker/jenkins_server/tmp:/var/jenkins_home/tmp
- repos:/srv/scm
env_file:
- /srv/docker/jenkins_server/jenkins.env
jenkins_agent:
build: ../jenkins_agent
container_name: agent
hostname: agent
restart: unless-stopped
command: java -jar /usr/share/jenkins/agent.jar -jnlpUrl http://server:8080/computer/jenkins%5Fagent/jenkins-agent.jnlp
volumes:
- /srv/docker/jenkins_agent/data:/home/jenkins/agent
- repos:/srv/scm
volumes:
repos:
driver: local
driver_opts:
type: 'none'
o: 'bind'
device: '/srv/scm'
@@ -0,0 +1,115 @@
antisamy-markup-formatter:162.v0e6ec0fcfcf6
apache-httpcomponents-client-4-api:4.5.14-208.v438351942757
asm-api:9.7.1-97.v4cc844130d97
authentication-tokens:1.119.v50285141b_7e1
blueocean-autofavorite:1.2.5
blueocean-bitbucket-pipeline:1.27.16
blueocean-commons:1.27.16
blueocean-config:1.27.16
blueocean-core-js:1.27.16
blueocean-dashboard:1.27.16
blueocean-display-url:2.4.3
blueocean-events:1.27.16
blueocean-git-pipeline:1.27.16
blueocean-github-pipeline:1.27.16
blueocean-i18n:1.27.16
blueocean-jwt:1.27.16
blueocean-personalization:1.27.16
blueocean-pipeline-api-impl:1.27.16
blueocean-pipeline-editor:1.27.16
blueocean-pipeline-scm-api:1.27.16
blueocean-rest-impl:1.27.16
blueocean-rest:1.27.16
blueocean-web:1.27.16
blueocean:1.27.16
bootstrap5-api:5.3.3-1
bouncycastle-api:2.30.1.80-256.vf98926042a_9b_
branch-api:2.1208.vf528356feca_4
caffeine-api:3.1.8-133.v17b_1ff2e0599
checks-api:2.2.1
cloudbees-bitbucket-branch-source:934.4.0
cloudbees-folder:6.980.v5a_cc0cb_25881
command-launcher:118.v72741845c17a_
commons-compress-api:1.26.1-2
commons-lang3-api:3.17.0-84.vb_b_938040b_078
commons-text-api:1.13.0-153.v91dcd89e2a_22
configuration-as-code:1929.v036b_5a_e1f123
credentials-binding:687.v619cb_15e923f
credentials:1405.vb_cda_74a_f8974
display-url-api:2.209.v582ed814ff2f
durable-task:581.v299a_5609d767
echarts-api:5.5.1-5
eddsa-api:0.3.0-4.v84c6f0f4969e
favorite:2.225.v68765b_b_a_1fa_3
font-awesome-api:6.6.0-2
git-client:6.1.1
git-parameter:0.10.0
git:5.7.0
github-api:1.321-478.vc9ce627ce001
github-branch-source:1810.v913311241fa_9
github:1.41.0
gson-api:2.11.0-109.v1ef91dd0829a_
handy-uri-templates-2-api:2.1.8-30.v7e777411b_148
htmlpublisher:1.37
instance-identity:201.vd2a_b_5a_468a_a_6
ionicons-api:74.v93d5eb_813d5f
jackson2-api:2.17.0-379.v02de8ec9f64c
jakarta-activation-api:2.1.3-1
jakarta-mail-api:2.1.3-1
javax-activation-api:1.2.0-7
javax-mail-api:1.6.2-10
jaxb:2.3.9-1
jdk-tool:83.v417146707a_3d
jenkins-design-language:1.27.16
jjwt-api:0.11.5-112.ve82dfb_224b_a_d
joda-time-api:2.13.0-93.v9934da_29b_a_e9
jquery:1.12.4-3
jquery3-api:3.7.1-2
jsch:0.2.16-86.v42e010d9484b_
json-api:20250107-125.v28b_a_ffa_eb_f01
json-path-api:2.9.0-138.vc943da_d833b_6
junit:1312.v1a_235a_b_94a_31
mailer:489.vd4b_25144138f
matrix-auth:3.2.4
matrix-project:845.vffd7fa_f27555
mina-sshd-api-common:2.14.0-143.v2b_362fc39576
mina-sshd-api-core:2.14.0-143.v2b_362fc39576
okhttp-api:4.11.0-183.va_87fc7a_89810
pipeline-build-step:551.v178956c49ef8
pipeline-graph-analysis:216.vfd8b_ece330ca_
pipeline-groovy-lib:749.v70084559234a_
pipeline-input-step:508.v584c0e9a_2177
pipeline-milestone-step:119.vdfdc43fc3b_9a_
pipeline-model-api:2.2221.vc657003fb_d93
pipeline-model-definition:2.2221.vc657003fb_d93
pipeline-model-extensions:2.2221.vc657003fb_d93
pipeline-rest-api:2.34
pipeline-stage-step:312.v8cd10304c27a_
pipeline-stage-tags-metadata:2.2221.vc657003fb_d93
pipeline-utility-steps:2.18.0
plain-credentials:183.va_de8f1dd5a_2b_
plugin-util-api:5.1.0
prism-api:1.29.0-18
pubsub-light:1.18
scm-api:703.v72ff4b_259600
script-security:1369.v9b_98a_4e95b_2d
snakeyaml-api:2.3-123.v13484c65210a_
sse-gateway:1.27
ssh-credentials:349.vb_8b_6b_9709f5b_
sshd:3.330.vc866a_8389b_58
structs:338.v848422169819
theme-manager:278.v2e3c063e42cc
token-macro:400.v35420b_922dcb_
trilead-api:2.147.vb_73cc728a_32e
variant:70.va_d9f17f859e0
versioncolumn:320.v6b_b_814ca_01f7
workflow-aggregator:600.vb_57cdd26fdd7
workflow-api:1363.v03f731255494
workflow-basic-steps:1079.vce64b_a_929c5a_
workflow-cps:4014.vcd7dc51d8b_30
workflow-durable-task-step:1405.v1fcd4a_d00096
workflow-job:1498.v33a_0c6f3a_4b_4
workflow-multibranch:800.v5f0a_a_660950e
workflow-scm-step:427.v4ca_6512e7df1
workflow-step-api:686.v603d058a_e148
workflow-support:944.v5a_859593b_98a_
+129
View File
@@ -0,0 +1,129 @@
###############################################################################
# Puppet standalone manifest to be applied to setup Exercise environment
###############################################################################
# No need to filter by hostname here.
node default {
include ::stdlib
# This will install all docker stack with default value
# FIXME Debian on WSL will be an issue due to systemd being chosen as default service provider.
include 'docker'
# enforce custom root password
user { 'root':
password => pw_hash('secret_root_password', 'SHA-512', stdlib::fqdn_rand_string(10))
}
# enforce custom user password
user { 'nerd':
password => pw_hash('secret_nerd_password', 'SHA-512', stdlib::fqdn_rand_string(10))
}
# enforce directory layout for clarity
file {[
'/srv/docker', '/srv/scm',
'/srv/docker/proxy', '/srv/docker/proxy/nginx-conf'
]:
ensure => directory
}
# enforce more directory layout for clarity
# those are likely to be written by the docker execution.
file {[
'/srv/docker/jenkins_server', '/srv/docker/jenkins_server/home',
'/srv/docker/jenkins_server/logs', '/srv/docker/jenkins_server/tmp',
'/srv/docker/jenkins_agent', '/srv/docker/jenkins_agent/data'
]:
ensure => directory,
owner => 1000,
group => 1000
}
#############################################################################
## Below Directives are required to setup the exercise environment.
## You can look into the archives or into the deployed content but
## MODIFY THE ARCHIVES CONTENT or the exercise might environment might
## be compromised.
archive { '/var/local/jenkins_home.tar':
source => 'puppet:///modules/nerd/jenkins_home.tar',
extract => true,
extract_path => '/srv/docker/jenkins_server/home',
creates => '/srv/docker/jenkins_server/home/config.xml'
}
## Above Directives are meant to setup the exercise environment.
#############################################################################
#############################################################################
## This archive contains the source code repository that will be used in
## the Jenkins job both in the Server and Agent instances
## This archive contains a bare repository that can be changed is needed
archive { '/var/local/repos.tar':
source => 'puppet:///modules/nerd/repos.tar',
extract => true,
extract_path => '/srv/scm',
creates => '/srv/scm/test_app'
}
#############################################################################
# simple http proxypass
file {'/srv/docker/proxy/nginx-conf/nginx-conf.conf':
content => @("U_NGINX"/$)
server {
listen 80;
server_name _;
access_log /var/log/nginx/access.log main;
error_log /var/log/nginx/error.log info;
# skip favicon.ico
location = /favicon.ico {
access_log off;
return 204;
}
location / {
proxy_pass http://server:8080;
proxy_set_header Host \$http_host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_buffering off;
tcp_nodelay on;
}
}
|-U_NGINX
}
# Jenkins Server Dockerfile
file {'/srv/docker/jenkins_server/Dockerfile':
content => template('nerd/jenkins/Dockerfile.server.erb'),
notify => Docker_compose['jenkins_stack']
}
-> file {'/srv/docker/jenkins_server/plugins.txt':
content => template('nerd/jenkins/plugins.txt'),
notify => Docker_compose['jenkins_stack']
}
-> file {'/srv/docker/jenkins_server/jenkins.env':
content => @("env"/$L)
TZ=Europe/Paris
LC_ALL=C.UTF-8
JAVA_OPTS=-Djenkins.install.runSetupWizard=false
JENKINS_SLAVE_AGENT_PORT=50000
JENKINS_OPTS=-Dhudson.plugins.git.GitSCM.ALLOW_LOCAL_CHECKOUT=true
| env
,
mode => '0400',
require => File['/srv/docker/jenkins_server'],
notify => Docker_compose['jenkins_stack']
}
# Jenkins Agent Dockerfile
file {'/srv/docker/jenkins_agent/Dockerfile':
content => template('nerd/jenkins/Dockerfile.agent.erb'),
notify => Docker_compose['jenkins_stack']
}
# Jenkins Stack Compose file
file {'/srv/docker/proxy/docker-compose.yml':
content => template('nerd/jenkins/docker-compose.yml.erb'),
require => [File['/srv/docker/proxy']]
}
# Launch the stack
docker_compose { 'jenkins_stack':
ensure => present,
compose_files => ['/srv/docker/proxy/docker-compose.yml']
}
}