STAC-25557: remove YAML-level comments from workflows #36
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Process-agent CI | |
| on: | |
| pull_request: | |
| push: | |
| branches: | |
| - master | |
| workflow_dispatch: | |
| permissions: {} | |
| concurrency: | |
| group: process-agent-ci-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| IMAGE: quay.io/stackstate/stackstate-k8s-process-agent | |
| jobs: | |
| build-and-test: | |
| name: Prebuild, generated-code check, build, and unit tests (${{ matrix.arch }}) | |
| runs-on: ${{ matrix.runner }} | |
| permissions: | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - arch: amd64 | |
| runner: ubuntu-24.04 | |
| llvm-arch: x86_64 | |
| prebuild-image: quay.io/stackstate/datadog_build_system-probe_x64:61b4ad67 | |
| builder-image: quay.io/stackstate/datadog_build_deb_x64:61b4ad67 | |
| - arch: arm64 | |
| runner: ubuntu-24.04-arm | |
| llvm-arch: arm64 | |
| prebuild-image: quay.io/stackstate/datadog_build_system-probe_arm64:61b4ad67 | |
| builder-image: quay.io/stackstate/datadog_build_deb_arm64:61b4ad67 | |
| steps: | |
| - name: Check out source commit | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Generate DataDog eBPF and Go artifacts | |
| env: | |
| LLVM_ARCH: ${{ matrix.llvm-arch }} | |
| PREBUILD_IMAGE: ${{ matrix.prebuild-image }} | |
| run: | | |
| set -euo pipefail | |
| docker run --rm \ | |
| --volume "${GITHUB_WORKSPACE}:/workspace" \ | |
| --workdir /workspace \ | |
| --env LLVM_ARCH="${LLVM_ARCH}" \ | |
| --env OUTPUT_USER_ID="$(id -u)" \ | |
| --env OUTPUT_GROUP_ID="$(id -g)" \ | |
| "${PREBUILD_IMAGE}" \ | |
| bash -c ' | |
| set -euo pipefail | |
| ./prebuild-datadog-agent.sh --generate-no-docker | |
| ' | |
| - name: Verify generated code, build, and test | |
| env: | |
| BUILDER_IMAGE: ${{ matrix.builder-image }} | |
| SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| set -euo pipefail | |
| short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" | |
| docker run --rm \ | |
| --volume "${GITHUB_WORKSPACE}:/workspace" \ | |
| --workdir /workspace \ | |
| --env CI=true \ | |
| --env GO111MODULE=on \ | |
| --env GOPATH=/workspace/.go \ | |
| --env PROCESS_AGENT_VERSION="${short_sha}" \ | |
| "${BUILDER_IMAGE}" \ | |
| bash -c ' | |
| source /root/.bashrc | |
| conda activate ddpy3 | |
| # The RVM directory hook reads an unset rvm_saved_env variable. | |
| # Keep fail-fast/pipefail without nounset in this legacy builder. | |
| set -eo pipefail | |
| export PATH="${GOPATH}/bin:${PATH}" | |
| go mod verify | |
| gogo_version="$(go list -m -f "{{.Version}}" github.com/gogo/protobuf)" | |
| go install "github.com/gogo/protobuf/protoc-gen-gogofaster@${gogo_version}" | |
| rake protobuf | |
| git diff --exit-code -- model | |
| rake ci | |
| ./prebuild-datadog-agent.sh --install-ebpf | |
| git diff --exit-code | |
| ' | |
| - name: Upload process-agent image inputs | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: process-agent-${{ matrix.arch }} | |
| path: | | |
| process-agent | |
| ebpf-object-files | |
| if-no-files-found: error | |
| retention-days: 1 | |
| image-smoke-and-scan: | |
| name: BCI image smoke test, Trivy secrets/CVEs, and Grype (${{ matrix.arch }}) | |
| needs: build-and-test | |
| runs-on: ${{ matrix.runner }} | |
| permissions: | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - arch: amd64 | |
| runner: ubuntu-24.04 | |
| long-arch: x86_64 | |
| llvm-arch: x86_64 | |
| - arch: arm64 | |
| runner: ubuntu-24.04-arm | |
| long-arch: aarch64 | |
| llvm-arch: arm64 | |
| steps: | |
| - name: Check out source commit | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| persist-credentials: false | |
| - name: Download process-agent image inputs | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: process-agent-${{ matrix.arch }} | |
| path: . | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 | |
| - name: Resolve image metadata | |
| id: image | |
| env: | |
| SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| set -euo pipefail | |
| short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" | |
| echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" | |
| - name: Build local BCI runtime image | |
| uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0 | |
| with: | |
| context: . | |
| file: BCI.dockerfile | |
| platforms: linux/${{ matrix.arch }} | |
| load: true | |
| push: false | |
| provenance: false | |
| sbom: false | |
| build-args: | | |
| EBPF_SUBFOLDER=${{ matrix.llvm-arch }} | |
| LONG_ARCH=${{ matrix.long-arch }} | |
| SHORT_ARCH=${{ matrix.arch }} | |
| tags: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} | |
| - name: Smoke test packaged process-agent binary | |
| env: | |
| ARCH: ${{ matrix.arch }} | |
| TAG: ${{ steps.image.outputs.tag }} | |
| run: | | |
| set -euo pipefail | |
| image="${IMAGE}:${TAG}-${ARCH}" | |
| output="$(docker run --rm \ | |
| --entrypoint /opt/stackstate-agent/bin/agent/process-agent \ | |
| "${image}" -version)" | |
| printf '%s\n' "${output}" | |
| grep -F "Version: ${TAG}" <<< "${output}" | |
| healthcheck="$(docker image inspect --format '{{json .Config.Healthcheck.Test}}' "${image}")" | |
| grep -F '/probe.sh' <<< "${healthcheck}" | |
| - name: Scan image with VEX-aware Trivy and Grype | |
| uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 | |
| with: | |
| image: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} | |
| mode: gate | |
| severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL | |
| with-grype: true | |
| exceptions-path: exceptions | |
| upload-sarif: false | |
| sarif-category: process-agent-${{ matrix.arch }} | |
| publish-image: | |
| name: Publish and sign commit image (${{ matrix.arch }}) | |
| needs: image-smoke-and-scan | |
| if: >- | |
| (github.event_name == 'pull_request' && | |
| github.event.pull_request.head.repo.full_name == github.repository) || | |
| ((github.event_name == 'push' || github.event_name == 'workflow_dispatch') && | |
| github.ref == 'refs/heads/master') | |
| runs-on: ${{ matrix.runner }} | |
| permissions: | |
| contents: read | |
| id-token: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - arch: amd64 | |
| runner: ubuntu-24.04 | |
| long-arch: x86_64 | |
| llvm-arch: x86_64 | |
| - arch: arm64 | |
| runner: ubuntu-24.04-arm | |
| long-arch: aarch64 | |
| llvm-arch: arm64 | |
| steps: | |
| - name: Check out source commit | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| persist-credentials: false | |
| - name: Download process-agent image inputs | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: process-agent-${{ matrix.arch }} | |
| path: . | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 | |
| - name: Resolve image tag | |
| id: image | |
| env: | |
| SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| set -euo pipefail | |
| short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" | |
| echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" | |
| - name: Resolve canonical OCI labels | |
| id: oci | |
| uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 | |
| with: | |
| image-name: stackstate-k8s-process-agent | |
| tag: ${{ steps.image.outputs.tag }} | |
| title: SUSE Observability Process Agent | |
| description: Process agent collecting per-process and per-container telemetry for SUSE Observability. | |
| component: stackstate-k8s-process-agent | |
| dockerfile: BCI.dockerfile | |
| base-name: registry.suse.com/bci/bci-micro:15.7 | |
| - name: Build, publish, and sign architecture image | |
| uses: StackVista/image-pipeline/.github/actions/push-single-arch@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 | |
| with: | |
| image: ${{ env.IMAGE }} | |
| tag: ${{ steps.image.outputs.tag }} | |
| arch: ${{ matrix.arch }} | |
| dockerfile: BCI.dockerfile | |
| labels: | | |
| ${{ steps.oci.outputs.labels }} | |
| org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} | |
| build-args: | | |
| EBPF_SUBFOLDER=${{ matrix.llvm-arch }} | |
| LONG_ARCH=${{ matrix.long-arch }} | |
| SHORT_ARCH=${{ matrix.arch }} | |
| target-registry: quay.io | |
| target-registry-user: ${{ vars.QUAY_USER }} | |
| target-registry-password: ${{ secrets.QUAY_PASSWORD }} | |
| merge-multiarch-manifest: | |
| name: Publish and sign multi-architecture commit image | |
| needs: publish-image | |
| if: >- | |
| (github.event_name == 'pull_request' && | |
| github.event.pull_request.head.repo.full_name == github.repository) || | |
| ((github.event_name == 'push' || github.event_name == 'workflow_dispatch') && | |
| github.ref == 'refs/heads/master') | |
| runs-on: ubuntu-24.04 | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - name: Resolve image tag | |
| id: image | |
| env: | |
| SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | |
| run: | | |
| set -euo pipefail | |
| short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" | |
| echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" | |
| - name: Merge and sign multi-architecture manifest | |
| uses: StackVista/image-pipeline/.github/actions/merge-multiarch@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 | |
| with: | |
| image: ${{ env.IMAGE }} | |
| tag: ${{ steps.image.outputs.tag }} | |
| target-registry: quay.io | |
| target-registry-user: ${{ vars.QUAY_USER }} | |
| target-registry-password: ${{ secrets.QUAY_PASSWORD }} | |
| ci-success: | |
| name: Process-agent CI | |
| needs: | |
| - build-and-test | |
| - image-smoke-and-scan | |
| - publish-image | |
| - merge-multiarch-manifest | |
| if: always() | |
| runs-on: ubuntu-24.04 | |
| permissions: {} | |
| steps: | |
| - name: Verify all required jobs succeeded | |
| env: | |
| NEEDS: ${{ toJSON(needs) }} | |
| run: | | |
| set -euo pipefail | |
| failed="$(jq -r ' | |
| to_entries[] | | |
| select(.value.result != "success" and .value.result != "skipped") | | |
| .key | |
| ' <<< "${NEEDS}")" | |
| if [ -n "${failed}" ]; then | |
| echo "Required process-agent jobs failed:" | |
| printf '%s\n' "${failed}" | |
| exit 1 | |
| fi | |
| echo "All required process-agent jobs passed." | |
| cerberus-notify: | |
| name: Report failure to Slack (Cerberus) | |
| needs: ci-success | |
| if: >- | |
| failure() && | |
| github.ref == 'refs/heads/master' && | |
| github.event_name == 'push' | |
| uses: ./.github/workflows/cerberus-notify.yml | |
| with: | |
| suite: build | |
| secrets: | |
| CERBERUS_LAMBDA_URL: ${{ secrets.CERBERUS_LAMBDA_URL }} | |
| CERBERUS_API_TOKEN: ${{ secrets.CERBERUS_API_TOKEN }} |