diff --git a/.drone.yml b/.drone.yml index c038f5bca2a..a3c806b1f06 100644 --- a/.drone.yml +++ b/.drone.yml @@ -446,7 +446,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -490,6 +490,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -507,37 +512,64 @@ steps: - name: Install Go Toolchain commands: - set -u - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz - - tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz + - tar -C /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains -xzf $RUNTIME.darwin-amd64.tar.gz - rm -rf $RUNTIME.darwin-amd64.tar.gz environment: RUNTIME: go1.18.3 - name: Install Rust Toolchain commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - rustup toolchain install $RUST_VERSION environment: WORKSPACE_DIR: /tmp/push-build-darwin-amd64 +- name: Install Node Toolchain + commands: + - set -u + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - mkdir -p $TOOLCHAIN_DIR + - curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz + - tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz + - rm -f node-v$NODE_VERSION-darwin-x64.tar.gz + - export PATH=$NODE_DIR/bin:$PATH + - corepack enable yarn + - echo Node reporting version $(node --version) + - echo Yarn reporting version $(yarn --version) + environment: + WORKSPACE_DIR: /tmp/push-build-darwin-amd64 - name: Build Mac artifacts commands: - set -u + - echo HOME=$${HOME} + - export HOME=/Users/$(whoami) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME - - export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup + - export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - build.assets/build-fido2-macos.sh build - export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)" - rustup override set $RUST_VERSION - make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - yarn install --frozen-lockfile && yarn build-term && yarn package-term environment: ARCH: amd64 GOCACHE: /tmp/push-build-darwin-amd64/go/cache @@ -547,15 +579,16 @@ steps: - name: Clean up toolchains (post) commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - rustup override unset - rustup toolchain uninstall $RUST_VERSION - - rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - rm -rf /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED environment: WORKSPACE_DIR: /tmp/push-build-darwin-amd64 when: @@ -1054,7 +1087,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1211,7 +1244,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1367,7 +1400,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1521,7 +1554,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1675,7 +1708,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -1856,7 +1889,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2034,7 +2067,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2201,7 +2234,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2365,7 +2398,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -2519,7 +2552,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2700,7 +2733,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2867,7 +2900,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -2908,6 +2941,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -2928,39 +2966,74 @@ steps: - name: Install Go Toolchain commands: - set -u - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz - - tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz + - tar -C /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains -xzf $RUNTIME.darwin-amd64.tar.gz - rm -rf $RUNTIME.darwin-amd64.tar.gz environment: RUNTIME: go1.18.3 - name: Install Rust Toolchain commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - rustup toolchain install $RUST_VERSION environment: WORKSPACE_DIR: /tmp/build-darwin-amd64 +- name: Install Node Toolchain + commands: + - set -u + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - mkdir -p $TOOLCHAIN_DIR + - curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz + - tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz + - rm -f node-v$NODE_VERSION-darwin-x64.tar.gz + - export PATH=$NODE_DIR/bin:$PATH + - corepack enable yarn + - echo Node reporting version $(node --version) + - echo Yarn reporting version $(yarn --version) + environment: + WORKSPACE_DIR: /tmp/build-darwin-amd64 - name: Build Mac release artifacts commands: - set -u + - echo HOME=$${HOME} + - export HOME=/Users/$(whoami) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME - - export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup + - export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - build.assets/build-fido2-macos.sh build - export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)" - rustup override set $RUST_VERSION + - security unlock-keychain -p $${BUILDBOX_PASSWORD} login.keychain + - security find-identity -v - make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - yarn install --frozen-lockfile && yarn build-term && yarn package-term environment: + APPLE_PASSWORD: + from_secret: APPLE_PASSWORD + APPLE_USERNAME: + from_secret: APPLE_USERNAME ARCH: amd64 + BUILDBOX_PASSWORD: + from_secret: BUILDBOX_PASSWORD GOCACHE: /tmp/build-darwin-amd64/go/cache GOPATH: /tmp/build-darwin-amd64/go OS: darwin @@ -2971,8 +3044,12 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - cp teleport*.tar.gz $WORKSPACE_DIR/go/artifacts - cp e/teleport-ent*.tar.gz $WORKSPACE_DIR/go/artifacts + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps/packages/teleterm/build/release + - cp *.dmg $WORKSPACE_DIR/go/artifacts - cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l + - cd $WORKSPACE_DIR/go/artifacts && for FILE in *.dmg; do shasum -a 256 "$FILE" + > "$FILE.sha256"; done && ls -l environment: WORKSPACE_DIR: /tmp/build-darwin-amd64 - name: Upload to S3 @@ -3036,15 +3113,16 @@ steps: - name: Clean up toolchains (post) commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - rustup override unset - rustup toolchain uninstall $RUST_VERSION - - rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - rm -rf /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED environment: WORKSPACE_DIR: /tmp/build-darwin-amd64 when: @@ -3063,7 +3141,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -3106,6 +3184,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -3244,7 +3327,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -3287,6 +3370,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -3425,7 +3513,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -3579,7 +3667,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -3733,7 +3821,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -3900,7 +3988,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -4067,7 +4155,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -4248,7 +4336,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -4429,7 +4517,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -4589,7 +4677,7 @@ name: build-docker-images environment: BUILDBOX_VERSION: "teleport10" - RUNTIME: go1.18.2 + RUNTIME: go1.17.9 trigger: event: @@ -5192,7 +5280,7 @@ steps: - if [ "${DRONE_REPO}" != "gravitational/teleport" ]; then echo "---> Not publishing ${DRONE_REPO} packages to RPM and DEB repos" && exit 78; fi - name: Check if tag is prerelease - image: golang:1.18-alpine + image: golang:1.17-alpine commands: - cd /go/src/github.com/gravitational/teleport/build.assets/tooling - go run ./cmd/check -tag ${DRONE_TAG} -check prerelease || (echo '---> Not publishing ${DRONE_TAG} packages to RPM and DEB repos' && exit 78) @@ -5273,7 +5361,7 @@ steps: # that would cause apt users to downgrade. For more info see: # https://github.com/gravitational/teleport/issues/8166 - name: Check if tag is latest - image: golang:1.18-alpine + image: golang:1.17-alpine commands: - cd /go/src/github.com/gravitational/teleport/build.assets/tooling - go run ./cmd/check -tag ${DRONE_TAG} -check latest || (echo '---> Not publishing ${DRONE_REPO} packages to DEB repo' && exit 78) @@ -5392,6 +5480,6 @@ volumes: name: drone-s3-debrepo-pvc --- kind: signature -hmac: b76936baf6cfee569080bcdf91de2167bdbfe0603d1b607026b666e820302ff8 +hmac: e83f39ac80fa38122a8cf34a6202f36a6d08163e8a31c30ce2e7599222f8b103 ... diff --git a/build.assets/Dockerfile-teleterm b/build.assets/Dockerfile-teleterm index 325576c03a3..c57377cb095 100644 --- a/build.assets/Dockerfile-teleterm +++ b/build.assets/Dockerfile-teleterm @@ -15,7 +15,7 @@ RUN BIN="/usr/local/bin" && \ chmod +x "${BIN}/${BINARY_NAME}" # Install node -ARG NODE_VERSION=v15.14.0 +ARG NODE_VERSION ENV NODE_URL="https://nodejs.org/dist/${NODE_VERSION}/node-${NODE_VERSION}-linux-${BUILDARCH}.tar.xz" ENV NODE_PATH="/usr/local/lib/node-${NODE_VERSION}-linux-${BUILDARCH}" ENV PATH="$PATH:${NODE_PATH}/bin" diff --git a/build.assets/Makefile b/build.assets/Makefile index 5ce9b0f594b..598e7bd1e3a 100644 --- a/build.assets/Makefile +++ b/build.assets/Makefile @@ -19,6 +19,7 @@ ARCH ?= amd64 BUILDBOX_VERSION ?= teleport10 GOLANG_VERSION ?= go1.18.3 RUST_VERSION ?= 1.61.0 +NODE_VERSION ?= 16.13.2 BORINGCRYPTO_RUNTIME=$(GOLANG_VERSION)b7 LIBBPF_VERSION ?= 0.3.1 @@ -213,6 +214,7 @@ buildbox-teleterm: buildbox @if [[ $${DRONE} == "true" ]] && ! docker inspect --type=image $(BUILDBOX_TELETERM) 2>&1 >/dev/null; then docker pull $(BUILDBOX_TELETERM) || true; fi; docker build \ --build-arg BUILDBOX_VERSION=$(BUILDBOX_VERSION) \ + --build-arg NODE_VERSION=$(NODE_VERSION) \ --build-arg BUILDARCH=$(RUNTIME_ARCH) \ --build-arg GRPC_NODE_PLUGIN_BINARY_TYPE=$(GRPC_NODE_PLUGIN_BINARY_TYPE) \ --cache-from $(BUILDBOX) \ @@ -444,6 +446,13 @@ print-go-version: print-rust-version: @echo $(RUST_VERSION) +# +# Print the Node version used to build Teleport Connect. +# +.PHONY:print-node-version +print-node-version: + @echo $(NODE_VERSION) + # # Print the buildbox version used to build Teleport. # diff --git a/build.assets/tooling/cmd/get-webapps-version/main.go b/build.assets/tooling/cmd/get-webapps-version/main.go new file mode 100644 index 00000000000..189d45fbfed --- /dev/null +++ b/build.assets/tooling/cmd/get-webapps-version/main.go @@ -0,0 +1,48 @@ +// Copyright 2022 Gravitational, Inc +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +// Command get-webapps-version determines the appropriate version +// of webapps to check out for a given version of teleport. +package main + +import ( + "fmt" + "os" + "strings" +) + +func main() { + fmt.Println(webappsVersion( + os.Getenv("DRONE_TAG"), + os.Getenv("DRONE_TARGET_BRANCH"), + )) +} + +func webappsVersion(tag, targetBranch string) string { + // if this build was triggered from a tag on the + // gravitational/teleport repo, assume that same + // tag exists on gravitational/webapps + if tag != "" { + return tag + } + + // if this build is on one of the teleport release branches, + // map to the equivalent release branch in webapps + if strings.HasPrefix(targetBranch, "branch/") { + return "teleport-" + strings.TrimPrefix(targetBranch, "branch/") + } + + // otherwise, this is a build on master, so just use master on webapps + return "master" +} diff --git a/build.assets/tooling/cmd/get-webapps-version/main_test.go b/build.assets/tooling/cmd/get-webapps-version/main_test.go new file mode 100644 index 00000000000..2d7d399f087 --- /dev/null +++ b/build.assets/tooling/cmd/get-webapps-version/main_test.go @@ -0,0 +1,39 @@ +// Copyright 2022 Gravitational, Inc +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package main + +import ( + "testing" + + "github.com/stretchr/testify/require" +) + +func TestWebappsVersion(t *testing.T) { + for _, test := range []struct { + desc string + droneTag string + targetBranch string + want string + }{ + {desc: "prefer tag", droneTag: "v9.2.0", want: "v9.2.0"}, + {desc: "maps branches", targetBranch: "branch/v9", want: "teleport-v9"}, + {desc: "fallback master", targetBranch: "foobar", want: "master"}, + } { + t.Run(test.desc, func(t *testing.T) { + require.Equal(t, test.want, + webappsVersion(test.droneTag, test.targetBranch)) + }) + } +} diff --git a/dronegen/common.go b/dronegen/common.go index 9e04e3d8e37..9be6ea574cf 100644 --- a/dronegen/common.go +++ b/dronegen/common.go @@ -162,6 +162,10 @@ func (b *buildType) Description(packageType string, extraQualifications ...strin return result } +func (b *buildType) hasTeleportConnect() bool { + return b.os == "darwin" && b.arch == "amd64" +} + // dockerService generates a docker:dind service // It includes the Docker socket volume by default, plus any extra volumes passed in func dockerService(v ...volumeRef) service { diff --git a/dronegen/mac.go b/dronegen/mac.go index 1b7293ec1a1..9b159482377 100644 --- a/dronegen/mac.go +++ b/dronegen/mac.go @@ -19,6 +19,13 @@ import ( "path" ) +const ( + perBuildDir = "/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED" + perBuildToolchainsDir = perBuildDir + "/toolchains" + perBuildCargoDir = perBuildToolchainsDir + "/cargo" + perBuildRustupDir = perBuildToolchainsDir + "/rustup" +) + // escapedPreformatted returns expr wrapped in escaped backticks, // resulting in Slack "preformatted" string, but safe to use in bash // without triggering the command expansion. @@ -37,8 +44,13 @@ func newDarwinPipeline(name string) pipeline { } func darwinPushPipeline() pipeline { + b := buildType{os: "darwin", arch: "amd64"} p := newDarwinPipeline("push-build-darwin-amd64") - p.Trigger = triggerPush + p.Trigger = trigger{ + Event: triggerRef{Include: []string{"push"}, Exclude: []string{"pull_request"}}, + Branch: triggerRef{Include: []string{"master", "branch/*"}}, + Repo: triggerRef{Include: []string{"gravitational/*"}}, + } p.Steps = []step{ setUpExecStorageStep(p.Workspace.Path), { @@ -47,10 +59,11 @@ func darwinPushPipeline() pipeline { "WORKSPACE_DIR": {raw: p.Workspace.Path}, "GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"}, }, - Commands: pushCheckoutCommandsDarwin(), + Commands: pushCheckoutCommandsDarwin(b), }, installGoToolchainStep(), installRustToolchainStep(p.Workspace.Path), + installNodeToolchainStep(p.Workspace.Path), { Name: "Build Mac artifacts", Environment: map[string]value{ @@ -60,7 +73,7 @@ func darwinPushPipeline() pipeline { "ARCH": {raw: "amd64"}, "WORKSPACE_DIR": {raw: p.Workspace.Path}, }, - Commands: darwinTagBuildCommands(), + Commands: darwinTagBuildCommands(b, darwinBuildOptions{unlockKeychain: false}), }, cleanUpToolchainsStep(p.Workspace.Path), cleanUpExecStorageStep(p.Workspace.Path), @@ -101,27 +114,36 @@ func darwinTagPipeline() pipeline { "WORKSPACE_DIR": {raw: p.Workspace.Path}, "GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"}, }, - Commands: darwinTagCheckoutCommands(), + Commands: darwinTagCheckoutCommands(b), }, installGoToolchainStep(), installRustToolchainStep(p.Workspace.Path), + installNodeToolchainStep(p.Workspace.Path), { Name: "Build Mac release artifacts", Environment: map[string]value{ - "GOPATH": {raw: path.Join(p.Workspace.Path, "/go")}, - "GOCACHE": {raw: path.Join(p.Workspace.Path, "/go/cache")}, - "OS": {raw: b.os}, - "ARCH": {raw: b.arch}, - "WORKSPACE_DIR": {raw: p.Workspace.Path}, + "GOPATH": {raw: path.Join(p.Workspace.Path, "/go")}, + "GOCACHE": {raw: path.Join(p.Workspace.Path, "/go/cache")}, + "OS": {raw: b.os}, + "ARCH": {raw: b.arch}, + "WORKSPACE_DIR": {raw: p.Workspace.Path}, + "BUILDBOX_PASSWORD": {fromSecret: "BUILDBOX_PASSWORD"}, + + // These credentials are necessary for the signing and notarization of + // Teleport Connect, which is built in to the Electron tooling. + // The rest of the mac artifacts are signed and notarized with gon + // in the darwin pkg pipeline. + "APPLE_USERNAME": {fromSecret: "APPLE_USERNAME"}, + "APPLE_PASSWORD": {fromSecret: "APPLE_PASSWORD"}, }, - Commands: darwinTagBuildCommands(), + Commands: darwinTagBuildCommands(b, darwinBuildOptions{unlockKeychain: true}), }, { Name: "Copy Mac artifacts", Environment: map[string]value{ "WORKSPACE_DIR": {raw: p.Workspace.Path}, }, - Commands: darwinTagCopyPackageArtifactCommands(), + Commands: darwinTagCopyPackageArtifactCommands(b), }, { Name: "Upload to S3", @@ -140,8 +162,8 @@ func darwinTagPipeline() pipeline { Failure: "ignore", Environment: map[string]value{ "WORKSPACE_DIR": {raw: p.Workspace.Path}, - "RELEASES_CERT": value{fromSecret: "RELEASES_CERT_STAGING"}, - "RELEASES_KEY": value{fromSecret: "RELEASES_KEY_STAGING"}, + "RELEASES_CERT": {fromSecret: "RELEASES_CERT_STAGING"}, + "RELEASES_KEY": {fromSecret: "RELEASES_KEY_STAGING"}, }, }, cleanUpToolchainsStep(p.Workspace.Path), @@ -150,13 +172,27 @@ func darwinTagPipeline() pipeline { return p } -func pushCheckoutCommandsDarwin() []string { - return []string{ +func pushCheckoutCommandsDarwin(b buildType) []string { + commands := []string{ `set -u`, `mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, `git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .`, `git checkout ${DRONE_TAG:-$DRONE_COMMIT}`, + } + + // clone github.com/gravitational/webapps for the Teleport Connect source code + if b.hasTeleportConnect() { + commands = append(commands, + `mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`, + `git clone https://github.com/gravitational/webapps.git .`, + `git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)`, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, + ) + } + + commands = append(commands, // fetch enterprise submodules // suppressing the newline on the end of the private key makes git operations fail on MacOS // with an error like 'Load key "/path/.ssh/id_rsa": invalid format' @@ -168,7 +204,9 @@ func pushCheckoutCommandsDarwin() []string { `GIT_SSH_COMMAND='ssh -i $WORKSPACE_DIR/.ssh/id_rsa -o UserKnownHostsFile=$WORKSPACE_DIR/.ssh/known_hosts -F /dev/null' git submodule update --init --recursive webassets || true`, `rm -rf $WORKSPACE_DIR/.ssh`, `mkdir -p $WORKSPACE_DIR/go/cache`, - } + ) + + return commands } func setUpExecStorageStep(path string) step { @@ -192,9 +230,9 @@ func installGoToolchainStep() step { }, Commands: []string{ `set -u`, - `mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `mkdir -p ` + perBuildToolchainsDir, `curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz`, - `tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz`, + `tar -C ` + perBuildToolchainsDir + ` -xzf $RUNTIME.darwin-amd64.tar.gz`, `rm -rf $RUNTIME.darwin-amd64.tar.gz`, }, } @@ -206,16 +244,38 @@ func installRustToolchainStep(path string) step { Environment: map[string]value{"WORKSPACE_DIR": {raw: path}}, Commands: []string{ `set -u`, - `export PATH=/Users/build/.cargo/bin:$PATH`, - `mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export PATH=/Users/$(whoami)/.cargo/bin:$PATH`, // use the system-installed rustup to install our custom Rust version + `mkdir -p ` + perBuildToolchainsDir, `export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`, - `export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export CARGO_HOME=` + perBuildCargoDir, `export RUST_HOME=$CARGO_HOME`, + `export RUSTUP_HOME=` + perBuildRustupDir, `rustup toolchain install $RUST_VERSION`, }, } } +func installNodeToolchainStep(workspacePath string) step { + return step{ + Name: "Install Node Toolchain", + Environment: map[string]value{"WORKSPACE_DIR": {raw: workspacePath}}, + Commands: []string{ + `set -u`, + `export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-node-version)`, + `export TOOLCHAIN_DIR=` + perBuildToolchainsDir, + `export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64`, + `mkdir -p $TOOLCHAIN_DIR`, + `curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz`, + `tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz`, + `rm -f node-v$NODE_VERSION-darwin-x64.tar.gz`, + `export PATH=$NODE_DIR/bin:$PATH`, + `corepack enable yarn`, + `echo Node reporting version $(node --version)`, + `echo Yarn reporting version $(yarn --version)`, + }, + } +} + func cleanUpToolchainsStep(path string) step { return step{ Name: "Clean up toolchains (post)", @@ -225,16 +285,17 @@ func cleanUpToolchainsStep(path string) step { }, Commands: []string{ `set -u`, - `export PATH=/Users/build/.cargo/bin:$PATH`, - `export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export PATH=/Users/$(whoami)/.cargo/bin:$PATH`, + `export CARGO_HOME=` + perBuildCargoDir, `export RUST_HOME=$CARGO_HOME`, + `export RUSTUP_HOME=` + perBuildRustupDir, `export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, // clean up the rust toolchain even though we're about to delete the directory // this ensures we don't leave behind a broken link `rustup override unset`, `rustup toolchain uninstall $RUST_VERSION`, - `rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `rm -rf ` + perBuildDir, }, } } @@ -251,39 +312,87 @@ func cleanUpExecStorageStep(path string) step { } } -func darwinTagCheckoutCommands() []string { - return append(pushCheckoutCommandsDarwin(), +func darwinTagCheckoutCommands(b buildType) []string { + return append( + pushCheckoutCommandsDarwin(b), `mkdir -p $WORKSPACE_DIR/go/artifacts`, `echo "${DRONE_TAG##v}" > $WORKSPACE_DIR/go/.version.txt`, `cat $WORKSPACE_DIR/go/.version.txt`, ) } -func darwinTagBuildCommands() []string { - return []string{ +type darwinBuildOptions struct { + unlockKeychain bool +} + +func darwinTagBuildCommands(b buildType, opts darwinBuildOptions) []string { + commands := []string{ `set -u`, + `echo HOME=$${HOME}`, + `export HOME=/Users/$(whoami)`, + `export TOOLCHAIN_DIR=` + perBuildToolchainsDir, + `export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-node-version)`, `export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`, - `export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export CARGO_HOME=` + perBuildCargoDir, `export RUST_HOME=$CARGO_HOME`, - `export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH`, + `export RUSTUP_HOME=` + perBuildRustupDir, + `export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64`, + `export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, `build.assets/build-fido2-macos.sh build`, `export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)"`, `rustup override set $RUST_VERSION`, - `make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes`, } + + if opts.unlockKeychain { + commands = append(commands, + `security unlock-keychain -p $${BUILDBOX_PASSWORD} login.keychain`, + `security find-identity -v`, + ) + } + + commands = append(commands, + `make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes`, + ) + + if b.hasTeleportConnect() { + commands = append(commands, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`, + `yarn install --frozen-lockfile && yarn build-term && yarn package-term`, + ) + } + + return commands } -func darwinTagCopyPackageArtifactCommands() []string { - return []string{ +func darwinTagCopyPackageArtifactCommands(b buildType) []string { + commands := []string{ `set -u`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, // copy release archives to artifact directory `cp teleport*.tar.gz $WORKSPACE_DIR/go/artifacts`, `cp e/teleport-ent*.tar.gz $WORKSPACE_DIR/go/artifacts`, - // generate checksums (for mac) - `cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l`, } + + // copy Teleport Connect artifacts + if b.hasTeleportConnect() { + commands = append(commands, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps/packages/teleterm/build/release`, + `cp *.dmg $WORKSPACE_DIR/go/artifacts`, + ) + } + + // generate checksums + commands = append(commands, + `cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l`, + ) + if b.hasTeleportConnect() { + commands = append(commands, + `cd $WORKSPACE_DIR/go/artifacts && for FILE in *.dmg; do shasum -a 256 "$FILE" > "$FILE.sha256"; done && ls -l`, + ) + } + + return commands } func darwinUploadToS3Commands() []string { diff --git a/dronegen/mac_pkg.go b/dronegen/mac_pkg.go index 395ce5bc9f5..77406ddaa2b 100644 --- a/dronegen/mac_pkg.go +++ b/dronegen/mac_pkg.go @@ -36,7 +36,7 @@ func darwinPkgPipeline(name, makeTarget string, pkgGlobs []string, extraQualific "WORKSPACE_DIR": {raw: p.Workspace.Path}, "GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"}, }, - Commands: darwinTagCheckoutCommands(), + Commands: darwinTagCheckoutCommands(b), }, { Name: "Download built tarball artifacts from S3", diff --git a/dronegen/tag.go b/dronegen/tag.go index a2cade6f34b..922fc105f5e 100644 --- a/dronegen/tag.go +++ b/dronegen/tag.go @@ -82,6 +82,16 @@ func tagBuildCommands(b buildType) []string { ), ) + // Build Teleport Connect on suported OS/arch + if b.hasTeleportConnect() { + commands = append(commands, + `cd /go/src/github.com/gravitational/webapps`, + `yarn install --frozen-lockfile && yarn build-term && yarn package-term`, + `cd -`, + ) + + } + if b.os == "windows" { commands = append(commands, `rm -f windows-signing-cert.pfx`,