ci: test shared buildx pipeline
This commit is contained in:
parent
4e04aabb12
commit
dfb67ac850
|
|
@ -5,76 +5,22 @@ stages:
|
||||||
- deploy
|
- deploy
|
||||||
|
|
||||||
variables:
|
variables:
|
||||||
# Disable the shared image build jobs from turniere-infra; this repo owns buildx builds below.
|
DOCKER_IMAGE_ENVS: "production test"
|
||||||
DOCKER_IMAGE_ENVS: ""
|
DOCKER_IMAGE_PLATFORMS: "linux/amd64,linux/arm64"
|
||||||
DOCKER_BUILDKIT: "1"
|
DOCKERFILE_PATH: "Dockerfile"
|
||||||
BUILDX_PLATFORMS: "linux/amd64,linux/arm64"
|
DOCKER_BUILD_TARGETS: "production=production test=test"
|
||||||
|
|
||||||
include:
|
include:
|
||||||
- project: 'turniere/turniere-infra'
|
- project: 'turniere/turniere-infra'
|
||||||
|
ref: 'codex/buildx-multiarch-template'
|
||||||
file: '/ci/pipeline.yaml'
|
file: '/ci/pipeline.yaml'
|
||||||
|
|
||||||
.buildx-image:
|
|
||||||
stage: build
|
|
||||||
tags:
|
|
||||||
- shell
|
|
||||||
before_script:
|
|
||||||
- echo "$CI_REGISTRY_PASSWORD" | docker login -u "$CI_REGISTRY_USER" --password-stdin "$CI_REGISTRY"
|
|
||||||
- export BUILDX_BUILDER_NAME="turniere-buildx-$CI_PIPELINE_ID-$CI_JOB_ID"
|
|
||||||
- docker buildx create --name "$BUILDX_BUILDER_NAME" --driver docker-container --use
|
|
||||||
- docker buildx inspect --builder "$BUILDX_BUILDER_NAME" --bootstrap
|
|
||||||
after_script:
|
|
||||||
- export BUILDX_BUILDER_NAME="turniere-buildx-$CI_PIPELINE_ID-$CI_JOB_ID"
|
|
||||||
- docker buildx rm "$BUILDX_BUILDER_NAME" || true
|
|
||||||
- docker logout "$CI_REGISTRY" || true
|
|
||||||
|
|
||||||
build production image:
|
|
||||||
extends: .buildx-image
|
|
||||||
script:
|
|
||||||
- >-
|
|
||||||
docker buildx build
|
|
||||||
--builder "$BUILDX_BUILDER_NAME"
|
|
||||||
--file Dockerfile
|
|
||||||
--target production
|
|
||||||
--platform "$BUILDX_PLATFORMS"
|
|
||||||
--cache-from "type=registry,ref=$CI_REGISTRY_IMAGE/buildcache:production"
|
|
||||||
--cache-to "type=registry,ref=$CI_REGISTRY_IMAGE/buildcache:production,mode=max"
|
|
||||||
--tag "$CI_REGISTRY_IMAGE/production/commits:$CI_COMMIT_SHA"
|
|
||||||
--push
|
|
||||||
.
|
|
||||||
rules:
|
|
||||||
- if: $CI_PIPELINE_SOURCE != "push"
|
|
||||||
when: never
|
|
||||||
- when: always
|
|
||||||
|
|
||||||
build test image:
|
|
||||||
extends: .buildx-image
|
|
||||||
script:
|
|
||||||
- >-
|
|
||||||
docker buildx build
|
|
||||||
--builder "$BUILDX_BUILDER_NAME"
|
|
||||||
--file Dockerfile
|
|
||||||
--target test
|
|
||||||
--platform "$BUILDX_PLATFORMS"
|
|
||||||
--cache-from "type=registry,ref=$CI_REGISTRY_IMAGE/buildcache:production"
|
|
||||||
--cache-from "type=registry,ref=$CI_REGISTRY_IMAGE/buildcache:test"
|
|
||||||
--cache-to "type=registry,ref=$CI_REGISTRY_IMAGE/buildcache:test,mode=max"
|
|
||||||
--tag "$CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA"
|
|
||||||
--push
|
|
||||||
.
|
|
||||||
rules:
|
|
||||||
- if: $CI_PIPELINE_SOURCE != "push"
|
|
||||||
when: never
|
|
||||||
- when: always
|
|
||||||
|
|
||||||
rails spec:
|
rails spec:
|
||||||
stage: test
|
stage: test
|
||||||
needs:
|
|
||||||
- job: build_image
|
|
||||||
tags:
|
tags:
|
||||||
- docker
|
- docker
|
||||||
needs:
|
needs:
|
||||||
- build test image
|
- job: build_image
|
||||||
image: $CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA
|
image: $CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
|
|
@ -101,13 +47,10 @@ rails spec:
|
||||||
|
|
||||||
rails e2e spec:
|
rails e2e spec:
|
||||||
stage: e2e
|
stage: e2e
|
||||||
needs:
|
|
||||||
- job: build_image
|
|
||||||
tags:
|
tags:
|
||||||
- docker
|
- docker
|
||||||
needs:
|
needs:
|
||||||
- build production image
|
- job: build_image
|
||||||
- build test image
|
|
||||||
image: $CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA
|
image: $CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA
|
||||||
services:
|
services:
|
||||||
- name: postgres:16
|
- name: postgres:16
|
||||||
|
|
@ -157,13 +100,10 @@ rails e2e spec:
|
||||||
|
|
||||||
rails follow sync e2e spec:
|
rails follow sync e2e spec:
|
||||||
stage: e2e
|
stage: e2e
|
||||||
needs:
|
|
||||||
- job: build_image
|
|
||||||
tags:
|
tags:
|
||||||
- docker
|
- docker
|
||||||
needs:
|
needs:
|
||||||
- build production image
|
- job: build_image
|
||||||
- build test image
|
|
||||||
image: $CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA
|
image: $CI_REGISTRY_IMAGE/test/commits:$CI_COMMIT_SHA
|
||||||
services:
|
services:
|
||||||
- name: postgres:16
|
- name: postgres:16
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,60 @@
|
||||||
|
# Buildx Migration Notes
|
||||||
|
|
||||||
|
This backend branch temporarily pins the shared GitLab include to the infra branch
|
||||||
|
`codex/buildx-multiarch-template` so the new shared image build flow can be tested
|
||||||
|
end to end before the infra MR is merged.
|
||||||
|
|
||||||
|
After the infra MR is merged:
|
||||||
|
|
||||||
|
- remove the temporary `ref:` override from `.gitlab-ci.yml`
|
||||||
|
- keep the repo-level variables that describe how this repo maps images to a single
|
||||||
|
multi-stage `Dockerfile`
|
||||||
|
|
||||||
|
## Backend pattern
|
||||||
|
|
||||||
|
Backend now uses:
|
||||||
|
|
||||||
|
- one root `Dockerfile`
|
||||||
|
- `DOCKER_IMAGE_ENVS: "production test"`
|
||||||
|
- `DOCKERFILE_PATH: "Dockerfile"`
|
||||||
|
- `DOCKER_BUILD_TARGETS: "production=production test=test"`
|
||||||
|
- `DOCKER_IMAGE_PLATFORMS: "linux/amd64,linux/arm64"`
|
||||||
|
|
||||||
|
## turniere-frontend
|
||||||
|
|
||||||
|
Frontend can move in two steps.
|
||||||
|
|
||||||
|
1. No Dockerfile restructuring required for the shared buildx rollout itself.
|
||||||
|
Its current `docker/production/Dockerfile` already fits the shared template.
|
||||||
|
2. To add Raspberry Pi support, verify the current production image really builds on
|
||||||
|
`linux/arm64`.
|
||||||
|
The current file uses `node:16-alpine` and `alpine`; that should be checked in CI.
|
||||||
|
|
||||||
|
Recommended frontend CI change after infra is merged:
|
||||||
|
|
||||||
|
- keep `DOCKER_IMAGE_ENVS: "production"`
|
||||||
|
- add `DOCKER_IMAGE_PLATFORMS: "linux/amd64,linux/arm64"`
|
||||||
|
|
||||||
|
Optional frontend follow-up:
|
||||||
|
|
||||||
|
- if you want the same repo shape as backend, replace `docker/production/Dockerfile`
|
||||||
|
with a root multi-stage `Dockerfile`, then add:
|
||||||
|
`DOCKERFILE_PATH: "Dockerfile"` and
|
||||||
|
`DOCKER_BUILD_TARGETS: "production=production"`
|
||||||
|
|
||||||
|
## turniere-match
|
||||||
|
|
||||||
|
Match also does not need a Dockerfile restructuring for the shared buildx rollout.
|
||||||
|
Its current `docker/production/Dockerfile` already matches the default shared
|
||||||
|
template contract.
|
||||||
|
|
||||||
|
Recommended match CI change after infra is merged:
|
||||||
|
|
||||||
|
- keep `DOCKER_IMAGE_ENVS: "production"`
|
||||||
|
- add `DOCKER_IMAGE_PLATFORMS: "linux/amd64,linux/arm64"`
|
||||||
|
|
||||||
|
Suggested follow-up:
|
||||||
|
|
||||||
|
- run a multi-arch build smoke test for the Alpine-based Python image
|
||||||
|
- if packaging or native wheels become slow on arm64, consider a multi-stage
|
||||||
|
Dockerfile with a slimmer runtime image similar to the backend pattern
|
||||||
Loading…
Reference in New Issue