Skip to content

Commit d35c5ad

Browse files
committed
ci: fix SonarQube scan step and add CD pipeline for S3 asset publishing
Switch SonarQube Scan to the sonarsource/sonar-scanner-cli image with native PR decoration, removing the separate Post Quality Gate step that raced with analysis completion. Add reactclient_cd_s3 pipeline mirroring split_synchronizer_cd_s3's pattern to publish built umd/ assets to S3 (stage on push to development, prod on push to main). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> AI-Session-Id: 7cc4f2fa-2bef-4add-b7a7-abe2b510985e AI-Tool: claude-code AI-Model: unknown
1 parent 0b0561a commit d35c5ad

3 files changed

Lines changed: 159 additions & 55 deletions

File tree

Lines changed: 115 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,115 @@
1+
pipeline:
2+
name: reactclient_cd_s3
3+
identifier: reactclient_cd_s3
4+
projectIdentifier: Harness_Split
5+
orgIdentifier: PROD
6+
tags: {}
7+
properties:
8+
ci:
9+
codebase:
10+
connectorRef: fmegithubharnessgitops
11+
repoName: react-client
12+
build: <+input>
13+
stages:
14+
- stage:
15+
name: Deploy to Stage
16+
identifier: Deploy_to_Stage
17+
type: CI
18+
when:
19+
pipelineStatus: Success
20+
condition: <+codebase.branch> == "development"
21+
spec:
22+
cloneCodebase: true
23+
buildIntelligence:
24+
enabled: false
25+
execution:
26+
steps:
27+
- step:
28+
type: Run
29+
name: Build Release Assets
30+
identifier: Build_Release_Assets
31+
spec:
32+
connectorRef: account.harnessImage
33+
image: node:lts
34+
shell: Bash
35+
command: |-
36+
npm ci
37+
npm run build
38+
- step:
39+
type: Run
40+
name: Deploy to S3
41+
identifier: Deploy_to_S3
42+
when:
43+
stageStatus: Success
44+
condition: <+trigger.event> == "PUSH"
45+
spec:
46+
connectorRef: account.harnessImage
47+
image: amazon/aws-cli:2.31.5
48+
shell: Bash
49+
command: |-
50+
aws s3 sync ./umd s3://split-public-stage/sdk \
51+
--acl public-read --follow-symlinks --cache-control max-age=31536000,public
52+
envVariables:
53+
AWS_DEFAULT_REGION: us-east-1
54+
infrastructure:
55+
type: KubernetesDirect
56+
spec:
57+
connectorRef: use1prod1cd
58+
namespace: harness-delegate
59+
serviceAccountName: use1-prod-1-reactclient-stage
60+
automountServiceAccountToken: false
61+
nodeSelector: {}
62+
os: Linux
63+
delegateSelectors:
64+
- use1-prod-1-cd
65+
- stage:
66+
name: Deploy to Prod
67+
identifier: Deploy_to_Prod
68+
type: CI
69+
when:
70+
pipelineStatus: Success
71+
condition: <+codebase.branch> == "main"
72+
spec:
73+
cloneCodebase: true
74+
buildIntelligence:
75+
enabled: false
76+
execution:
77+
steps:
78+
- step:
79+
type: Run
80+
name: Build Release Assets
81+
identifier: Build_Release_Assets
82+
spec:
83+
connectorRef: account.harnessImage
84+
image: node:lts
85+
shell: Bash
86+
command: |-
87+
npm ci
88+
npm run build
89+
- step:
90+
type: Run
91+
name: Deploy to S3
92+
identifier: Deploy_to_S3
93+
when:
94+
stageStatus: Success
95+
condition: <+trigger.event> == "PUSH"
96+
spec:
97+
connectorRef: account.harnessImage
98+
image: amazon/aws-cli:2.31.5
99+
shell: Bash
100+
command: |-
101+
aws s3 sync ./umd s3://split-public/sdk \
102+
--acl public-read --follow-symlinks --cache-control max-age=31536000,public
103+
envVariables:
104+
AWS_DEFAULT_REGION: us-east-1
105+
infrastructure:
106+
type: KubernetesDirect
107+
spec:
108+
connectorRef: use1prod1cd
109+
namespace: harness-delegate
110+
serviceAccountName: use1-prod-1-reactclient-prod
111+
automountServiceAccountToken: false
112+
nodeSelector: {}
113+
os: Linux
114+
delegateSelectors:
115+
- use1-prod-1-cd
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
inputSet:
2+
name: reactclient_cd_s3_push
3+
identifier: reactclient_cd_s3_push
4+
orgIdentifier: PROD
5+
projectIdentifier: Harness_Split
6+
pipeline:
7+
identifier: reactclient_cd_s3
8+
properties:
9+
ci:
10+
codebase:
11+
build:
12+
type: branch
13+
spec:
14+
branch: <+trigger.branch>

‎.harness/pipeline.yaml‎

Lines changed: 30 additions & 55 deletions
Original file line numberDiff line numberDiff line change
@@ -93,64 +93,39 @@ pipeline:
9393
stageStatus: Success
9494
condition: <+matrix.nodeVersion> == "lts"
9595
spec:
96-
shell: Sh
97-
command: |-
98-
export SONAR_SCANNER_VERSION=5.0.1.3006
99-
curl -sSLo sonar-scanner.zip \
100-
"https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-${SONAR_SCANNER_VERSION}-linux.zip"
101-
unzip -q sonar-scanner.zip
102-
export PATH="$PWD/sonar-scanner-${SONAR_SCANNER_VERSION}-linux/bin:$PATH"
103-
apt-get install -y openjdk-17-jdk -qq
104-
sonar-scanner \
105-
-Dsonar.projectKey=react-client \
106-
-Dsonar.sources=src \
107-
-Dsonar.tests=src/__tests__ \
108-
-Dsonar.host.url=https://sonar.harness.io \
109-
-Dsonar.token=<+secrets.getValue("sonarqube-token")> \
110-
-Dsonar.exclusions="**/node_modules/**,**/umd/**,**/es/**,**/lib/**,src/__tests__/**"
111-
- step:
112-
type: Run
113-
name: Post Quality Gate
114-
identifier: Post_Quality_Gate
115-
when:
116-
stageStatus: Success
117-
condition: <+matrix.nodeVersion> == "lts"
118-
spec:
96+
connectorRef: account.harnessImage
97+
image: sonarsource/sonar-scanner-cli
11998
shell: Bash
120-
command: |-
121-
#!/bin/bash
122-
set -e
123-
124-
SONAR_TOKEN="<+secrets.getValue("sonarqube-token")>"
125-
SONAR_URL="https://sonar.harness.io"
126-
SONAR_PROJECT_KEY="react-client"
127-
GITHUB_TOKEN="<+secrets.getValue("github-devops-token")>"
128-
GITHUB_REPO="react-client"
129-
COMMIT_SHA="<+codebase.commitSha>"
130-
131-
STATUS_JSON=$(curl -sf \
132-
-H "Authorization: Bearer ${SONAR_TOKEN}" \
133-
"${SONAR_URL}/api/qualitygates/project_status?projectKey=${SONAR_PROJECT_KEY}")
134-
135-
QG_STATUS=$(echo "$STATUS_JSON" | python3 -c "import sys,json; print(json.load(sys.stdin)['projectStatus']['status'])")
136-
137-
case "$QG_STATUS" in
138-
OK) GH_STATE="success"; DESCRIPTION="Quality gate passed" ;;
139-
ERROR) GH_STATE="failure"; DESCRIPTION="Quality gate failed" ;;
140-
WARN) GH_STATE="success"; DESCRIPTION="Quality gate passed with warnings" ;;
141-
*) GH_STATE="pending"; DESCRIPTION="Quality gate status unknown" ;;
142-
esac
143-
144-
TARGET_URL="${SONAR_URL}/dashboard?id=${SONAR_PROJECT_KEY}"
99+
command: |
100+
set -euo pipefail
145101
146-
curl -sf -X POST \
147-
-H "Authorization: token ${GITHUB_TOKEN}" \
148-
-H "Accept: application/vnd.github.v3+json" \
149-
-H "Content-Type: application/json" \
150-
-d "{\"state\":\"${GH_STATE}\",\"description\":\"${DESCRIPTION}\",\"context\":\"sonarqube/quality-gate\",\"target_url\":\"${TARGET_URL}\"}" \
151-
"https://api.github.com/repos/splitio/${GITHUB_REPO}/statuses/${COMMIT_SHA}"
102+
COMMON_ARGS="
103+
-Dsonar.host.url=https://sonar.harness.io
104+
-Dsonar.token=$SONAR_TOKEN
105+
-Dsonar.projectKey=react-client
106+
-Dsonar.sources=src
107+
-Dsonar.tests=src/__tests__
108+
-Dsonar.exclusions=**/node_modules/**,**/umd/**,**/es/**,**/lib/**,src/__tests__/**
109+
-Dsonar.scanner.skipJreProvisioning=true
110+
-Dsonar.scanner.skipSystemTruststore=true
111+
"
152112
153-
echo "Posted SonarQube quality gate status: ${GH_STATE}"
113+
if [ "<+codebase.prNumber>" != "" ] && [ "<+codebase.prNumber>" != "null" ]; then
114+
echo "Pull Request Analysis"
115+
sonar-scanner \
116+
$COMMON_ARGS \
117+
-Dsonar.pullrequest.key=<+codebase.prNumber> \
118+
-Dsonar.pullrequest.branch=<+codebase.sourceBranch> \
119+
-Dsonar.pullrequest.base=<+codebase.targetBranch>
120+
else
121+
echo "Branch Analysis"
122+
sonar-scanner \
123+
$COMMON_ARGS \
124+
-Dsonar.branch.name=<+codebase.branch>
125+
fi
126+
envVariables:
127+
SONAR_TOKEN: <+secrets.getValue("sonarqube-token")>
128+
timeout: 10m
154129
strategy:
155130
matrix:
156131
nodeVersion:

0 commit comments

Comments
 (0)