From 86f3a3d618996a9d086c0dd55a9d465f271a67db Mon Sep 17 00:00:00 2001 From: Zac Bergquist Date: Thu, 2 Jun 2022 20:19:42 -0600 Subject: [PATCH] Build Teleport Connect on darwin/amd64 (#12257) This commit updates drone to build Teleport Connect by: * cloning `gravitational/webapps` as a sibling directory to gravitational/teleport * checkout out the right version of webapps by running a simple Go program (this step is only necessary until we move webapps into the teleport repo) * Running the Teleport Connect build and copying artifacts Code signing should run on tag builds automatically as part the electron build, assuming the Apple Account credentials are properly loaded into the keychain. Notarization will also happen automatically if both `$APPLE_USERNAME` and `$APPLE_PASSWORD` are set. In order to make the above happen, this patch also includes: * Installing and removing a per-build Node instance in the toolchain directory on Darwin * Moving the toolchain temporary directory out of ~/ and into /tmp. Drone usually sets `$HOME` to a temporary directory for each build, but unfortunately we need it to point to the actual build user's home directory in order for the notarisation tooling to find the right keychain. Having $HOME point to a long-lived directory risks both pollution from build detritus and builds stomping on one another. In an in an attempt to isolate the builds from each other and protect `~build` as best we can, as much of the build state as possible (including ephemeral toolchains) has been moved under `/tmp`. Co-authored-by: Trent Clarke --- .drone.yml | 180 +++++++++++++----- build.assets/Dockerfile-teleterm | 2 +- build.assets/Makefile | 9 + .../tooling/cmd/get-webapps-version/main.go | 48 +++++ .../cmd/get-webapps-version/main_test.go | 39 ++++ dronegen/common.go | 4 + dronegen/mac.go | 179 +++++++++++++---- dronegen/mac_pkg.go | 2 +- dronegen/tag.go | 10 + 9 files changed, 390 insertions(+), 83 deletions(-) create mode 100644 build.assets/tooling/cmd/get-webapps-version/main.go create mode 100644 build.assets/tooling/cmd/get-webapps-version/main_test.go diff --git a/.drone.yml b/.drone.yml index c038f5bca2a..a3c806b1f06 100644 --- a/.drone.yml +++ b/.drone.yml @@ -446,7 +446,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -490,6 +490,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -507,37 +512,64 @@ steps: - name: Install Go Toolchain commands: - set -u - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz - - tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz + - tar -C /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains -xzf $RUNTIME.darwin-amd64.tar.gz - rm -rf $RUNTIME.darwin-amd64.tar.gz environment: RUNTIME: go1.18.3 - name: Install Rust Toolchain commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - rustup toolchain install $RUST_VERSION environment: WORKSPACE_DIR: /tmp/push-build-darwin-amd64 +- name: Install Node Toolchain + commands: + - set -u + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - mkdir -p $TOOLCHAIN_DIR + - curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz + - tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz + - rm -f node-v$NODE_VERSION-darwin-x64.tar.gz + - export PATH=$NODE_DIR/bin:$PATH + - corepack enable yarn + - echo Node reporting version $(node --version) + - echo Yarn reporting version $(yarn --version) + environment: + WORKSPACE_DIR: /tmp/push-build-darwin-amd64 - name: Build Mac artifacts commands: - set -u + - echo HOME=$${HOME} + - export HOME=/Users/$(whoami) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME - - export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup + - export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - build.assets/build-fido2-macos.sh build - export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)" - rustup override set $RUST_VERSION - make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - yarn install --frozen-lockfile && yarn build-term && yarn package-term environment: ARCH: amd64 GOCACHE: /tmp/push-build-darwin-amd64/go/cache @@ -547,15 +579,16 @@ steps: - name: Clean up toolchains (post) commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - rustup override unset - rustup toolchain uninstall $RUST_VERSION - - rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - rm -rf /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED environment: WORKSPACE_DIR: /tmp/push-build-darwin-amd64 when: @@ -1054,7 +1087,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1211,7 +1244,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1367,7 +1400,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1521,7 +1554,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -1675,7 +1708,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -1856,7 +1889,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2034,7 +2067,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2201,7 +2234,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2365,7 +2398,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -2519,7 +2552,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2700,7 +2733,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -2867,7 +2900,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -2908,6 +2941,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -2928,39 +2966,74 @@ steps: - name: Install Go Toolchain commands: - set -u - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz - - tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz + - tar -C /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains -xzf $RUNTIME.darwin-amd64.tar.gz - rm -rf $RUNTIME.darwin-amd64.tar.gz environment: RUNTIME: go1.18.3 - name: Install Rust Toolchain commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - rustup toolchain install $RUST_VERSION environment: WORKSPACE_DIR: /tmp/build-darwin-amd64 +- name: Install Node Toolchain + commands: + - set -u + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - mkdir -p $TOOLCHAIN_DIR + - curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz + - tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz + - rm -f node-v$NODE_VERSION-darwin-x64.tar.gz + - export PATH=$NODE_DIR/bin:$PATH + - corepack enable yarn + - echo Node reporting version $(node --version) + - echo Yarn reporting version $(yarn --version) + environment: + WORKSPACE_DIR: /tmp/build-darwin-amd64 - name: Build Mac release artifacts commands: - set -u + - echo HOME=$${HOME} + - export HOME=/Users/$(whoami) + - export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains + - export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets + print-node-version) - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME - - export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup + - export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64 + - export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - build.assets/build-fido2-macos.sh build - export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)" - rustup override set $RUST_VERSION + - security unlock-keychain -p $${BUILDBOX_PASSWORD} login.keychain + - security find-identity -v - make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - yarn install --frozen-lockfile && yarn build-term && yarn package-term environment: + APPLE_PASSWORD: + from_secret: APPLE_PASSWORD + APPLE_USERNAME: + from_secret: APPLE_USERNAME ARCH: amd64 + BUILDBOX_PASSWORD: + from_secret: BUILDBOX_PASSWORD GOCACHE: /tmp/build-darwin-amd64/go/cache GOPATH: /tmp/build-darwin-amd64/go OS: darwin @@ -2971,8 +3044,12 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - cp teleport*.tar.gz $WORKSPACE_DIR/go/artifacts - cp e/teleport-ent*.tar.gz $WORKSPACE_DIR/go/artifacts + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps/packages/teleterm/build/release + - cp *.dmg $WORKSPACE_DIR/go/artifacts - cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l + - cd $WORKSPACE_DIR/go/artifacts && for FILE in *.dmg; do shasum -a 256 "$FILE" + > "$FILE.sha256"; done && ls -l environment: WORKSPACE_DIR: /tmp/build-darwin-amd64 - name: Upload to S3 @@ -3036,15 +3113,16 @@ steps: - name: Clean up toolchains (post) commands: - set -u - - export PATH=/Users/build/.cargo/bin:$PATH - - export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - export PATH=/Users/$(whoami)/.cargo/bin:$PATH + - export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo - export RUST_HOME=$CARGO_HOME + - export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup - export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version) - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - rustup override unset - rustup toolchain uninstall $RUST_VERSION - - rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains + - rm -rf /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED environment: WORKSPACE_DIR: /tmp/build-darwin-amd64 when: @@ -3063,7 +3141,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -3106,6 +3184,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -3244,7 +3327,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/mac.go:32 +# Generated at dronegen/mac.go:39 ################################################ kind: pipeline @@ -3287,6 +3370,11 @@ steps: - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git . - git checkout ${DRONE_TAG:-$DRONE_COMMIT} + - mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps + - git clone https://github.com/gravitational/webapps.git . + - git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go) + - cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport - mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa && chmod 600 $WORKSPACE_DIR/.ssh/id_rsa - ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null @@ -3425,7 +3513,7 @@ steps: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -3579,7 +3667,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -3733,7 +3821,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -3900,7 +3988,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -4067,7 +4155,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -4248,7 +4336,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:451 +# Generated at dronegen/tag.go:461 ################################################ kind: pipeline @@ -4429,7 +4517,7 @@ volumes: ################################################ # Generated using dronegen, do not edit by hand! # Use 'make dronegen' to update. -# Generated at dronegen/tag.go:240 +# Generated at dronegen/tag.go:250 ################################################ kind: pipeline @@ -4589,7 +4677,7 @@ name: build-docker-images environment: BUILDBOX_VERSION: "teleport10" - RUNTIME: go1.18.2 + RUNTIME: go1.17.9 trigger: event: @@ -5192,7 +5280,7 @@ steps: - if [ "${DRONE_REPO}" != "gravitational/teleport" ]; then echo "---> Not publishing ${DRONE_REPO} packages to RPM and DEB repos" && exit 78; fi - name: Check if tag is prerelease - image: golang:1.18-alpine + image: golang:1.17-alpine commands: - cd /go/src/github.com/gravitational/teleport/build.assets/tooling - go run ./cmd/check -tag ${DRONE_TAG} -check prerelease || (echo '---> Not publishing ${DRONE_TAG} packages to RPM and DEB repos' && exit 78) @@ -5273,7 +5361,7 @@ steps: # that would cause apt users to downgrade. For more info see: # https://github.com/gravitational/teleport/issues/8166 - name: Check if tag is latest - image: golang:1.18-alpine + image: golang:1.17-alpine commands: - cd /go/src/github.com/gravitational/teleport/build.assets/tooling - go run ./cmd/check -tag ${DRONE_TAG} -check latest || (echo '---> Not publishing ${DRONE_REPO} packages to DEB repo' && exit 78) @@ -5392,6 +5480,6 @@ volumes: name: drone-s3-debrepo-pvc --- kind: signature -hmac: b76936baf6cfee569080bcdf91de2167bdbfe0603d1b607026b666e820302ff8 +hmac: e83f39ac80fa38122a8cf34a6202f36a6d08163e8a31c30ce2e7599222f8b103 ... diff --git a/build.assets/Dockerfile-teleterm b/build.assets/Dockerfile-teleterm index 325576c03a3..c57377cb095 100644 --- a/build.assets/Dockerfile-teleterm +++ b/build.assets/Dockerfile-teleterm @@ -15,7 +15,7 @@ RUN BIN="/usr/local/bin" && \ chmod +x "${BIN}/${BINARY_NAME}" # Install node -ARG NODE_VERSION=v15.14.0 +ARG NODE_VERSION ENV NODE_URL="https://nodejs.org/dist/${NODE_VERSION}/node-${NODE_VERSION}-linux-${BUILDARCH}.tar.xz" ENV NODE_PATH="/usr/local/lib/node-${NODE_VERSION}-linux-${BUILDARCH}" ENV PATH="$PATH:${NODE_PATH}/bin" diff --git a/build.assets/Makefile b/build.assets/Makefile index 5ce9b0f594b..598e7bd1e3a 100644 --- a/build.assets/Makefile +++ b/build.assets/Makefile @@ -19,6 +19,7 @@ ARCH ?= amd64 BUILDBOX_VERSION ?= teleport10 GOLANG_VERSION ?= go1.18.3 RUST_VERSION ?= 1.61.0 +NODE_VERSION ?= 16.13.2 BORINGCRYPTO_RUNTIME=$(GOLANG_VERSION)b7 LIBBPF_VERSION ?= 0.3.1 @@ -213,6 +214,7 @@ buildbox-teleterm: buildbox @if [[ $${DRONE} == "true" ]] && ! docker inspect --type=image $(BUILDBOX_TELETERM) 2>&1 >/dev/null; then docker pull $(BUILDBOX_TELETERM) || true; fi; docker build \ --build-arg BUILDBOX_VERSION=$(BUILDBOX_VERSION) \ + --build-arg NODE_VERSION=$(NODE_VERSION) \ --build-arg BUILDARCH=$(RUNTIME_ARCH) \ --build-arg GRPC_NODE_PLUGIN_BINARY_TYPE=$(GRPC_NODE_PLUGIN_BINARY_TYPE) \ --cache-from $(BUILDBOX) \ @@ -444,6 +446,13 @@ print-go-version: print-rust-version: @echo $(RUST_VERSION) +# +# Print the Node version used to build Teleport Connect. +# +.PHONY:print-node-version +print-node-version: + @echo $(NODE_VERSION) + # # Print the buildbox version used to build Teleport. # diff --git a/build.assets/tooling/cmd/get-webapps-version/main.go b/build.assets/tooling/cmd/get-webapps-version/main.go new file mode 100644 index 00000000000..189d45fbfed --- /dev/null +++ b/build.assets/tooling/cmd/get-webapps-version/main.go @@ -0,0 +1,48 @@ +// Copyright 2022 Gravitational, Inc +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +// Command get-webapps-version determines the appropriate version +// of webapps to check out for a given version of teleport. +package main + +import ( + "fmt" + "os" + "strings" +) + +func main() { + fmt.Println(webappsVersion( + os.Getenv("DRONE_TAG"), + os.Getenv("DRONE_TARGET_BRANCH"), + )) +} + +func webappsVersion(tag, targetBranch string) string { + // if this build was triggered from a tag on the + // gravitational/teleport repo, assume that same + // tag exists on gravitational/webapps + if tag != "" { + return tag + } + + // if this build is on one of the teleport release branches, + // map to the equivalent release branch in webapps + if strings.HasPrefix(targetBranch, "branch/") { + return "teleport-" + strings.TrimPrefix(targetBranch, "branch/") + } + + // otherwise, this is a build on master, so just use master on webapps + return "master" +} diff --git a/build.assets/tooling/cmd/get-webapps-version/main_test.go b/build.assets/tooling/cmd/get-webapps-version/main_test.go new file mode 100644 index 00000000000..2d7d399f087 --- /dev/null +++ b/build.assets/tooling/cmd/get-webapps-version/main_test.go @@ -0,0 +1,39 @@ +// Copyright 2022 Gravitational, Inc +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package main + +import ( + "testing" + + "github.com/stretchr/testify/require" +) + +func TestWebappsVersion(t *testing.T) { + for _, test := range []struct { + desc string + droneTag string + targetBranch string + want string + }{ + {desc: "prefer tag", droneTag: "v9.2.0", want: "v9.2.0"}, + {desc: "maps branches", targetBranch: "branch/v9", want: "teleport-v9"}, + {desc: "fallback master", targetBranch: "foobar", want: "master"}, + } { + t.Run(test.desc, func(t *testing.T) { + require.Equal(t, test.want, + webappsVersion(test.droneTag, test.targetBranch)) + }) + } +} diff --git a/dronegen/common.go b/dronegen/common.go index 9e04e3d8e37..9be6ea574cf 100644 --- a/dronegen/common.go +++ b/dronegen/common.go @@ -162,6 +162,10 @@ func (b *buildType) Description(packageType string, extraQualifications ...strin return result } +func (b *buildType) hasTeleportConnect() bool { + return b.os == "darwin" && b.arch == "amd64" +} + // dockerService generates a docker:dind service // It includes the Docker socket volume by default, plus any extra volumes passed in func dockerService(v ...volumeRef) service { diff --git a/dronegen/mac.go b/dronegen/mac.go index 1b7293ec1a1..9b159482377 100644 --- a/dronegen/mac.go +++ b/dronegen/mac.go @@ -19,6 +19,13 @@ import ( "path" ) +const ( + perBuildDir = "/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED" + perBuildToolchainsDir = perBuildDir + "/toolchains" + perBuildCargoDir = perBuildToolchainsDir + "/cargo" + perBuildRustupDir = perBuildToolchainsDir + "/rustup" +) + // escapedPreformatted returns expr wrapped in escaped backticks, // resulting in Slack "preformatted" string, but safe to use in bash // without triggering the command expansion. @@ -37,8 +44,13 @@ func newDarwinPipeline(name string) pipeline { } func darwinPushPipeline() pipeline { + b := buildType{os: "darwin", arch: "amd64"} p := newDarwinPipeline("push-build-darwin-amd64") - p.Trigger = triggerPush + p.Trigger = trigger{ + Event: triggerRef{Include: []string{"push"}, Exclude: []string{"pull_request"}}, + Branch: triggerRef{Include: []string{"master", "branch/*"}}, + Repo: triggerRef{Include: []string{"gravitational/*"}}, + } p.Steps = []step{ setUpExecStorageStep(p.Workspace.Path), { @@ -47,10 +59,11 @@ func darwinPushPipeline() pipeline { "WORKSPACE_DIR": {raw: p.Workspace.Path}, "GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"}, }, - Commands: pushCheckoutCommandsDarwin(), + Commands: pushCheckoutCommandsDarwin(b), }, installGoToolchainStep(), installRustToolchainStep(p.Workspace.Path), + installNodeToolchainStep(p.Workspace.Path), { Name: "Build Mac artifacts", Environment: map[string]value{ @@ -60,7 +73,7 @@ func darwinPushPipeline() pipeline { "ARCH": {raw: "amd64"}, "WORKSPACE_DIR": {raw: p.Workspace.Path}, }, - Commands: darwinTagBuildCommands(), + Commands: darwinTagBuildCommands(b, darwinBuildOptions{unlockKeychain: false}), }, cleanUpToolchainsStep(p.Workspace.Path), cleanUpExecStorageStep(p.Workspace.Path), @@ -101,27 +114,36 @@ func darwinTagPipeline() pipeline { "WORKSPACE_DIR": {raw: p.Workspace.Path}, "GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"}, }, - Commands: darwinTagCheckoutCommands(), + Commands: darwinTagCheckoutCommands(b), }, installGoToolchainStep(), installRustToolchainStep(p.Workspace.Path), + installNodeToolchainStep(p.Workspace.Path), { Name: "Build Mac release artifacts", Environment: map[string]value{ - "GOPATH": {raw: path.Join(p.Workspace.Path, "/go")}, - "GOCACHE": {raw: path.Join(p.Workspace.Path, "/go/cache")}, - "OS": {raw: b.os}, - "ARCH": {raw: b.arch}, - "WORKSPACE_DIR": {raw: p.Workspace.Path}, + "GOPATH": {raw: path.Join(p.Workspace.Path, "/go")}, + "GOCACHE": {raw: path.Join(p.Workspace.Path, "/go/cache")}, + "OS": {raw: b.os}, + "ARCH": {raw: b.arch}, + "WORKSPACE_DIR": {raw: p.Workspace.Path}, + "BUILDBOX_PASSWORD": {fromSecret: "BUILDBOX_PASSWORD"}, + + // These credentials are necessary for the signing and notarization of + // Teleport Connect, which is built in to the Electron tooling. + // The rest of the mac artifacts are signed and notarized with gon + // in the darwin pkg pipeline. + "APPLE_USERNAME": {fromSecret: "APPLE_USERNAME"}, + "APPLE_PASSWORD": {fromSecret: "APPLE_PASSWORD"}, }, - Commands: darwinTagBuildCommands(), + Commands: darwinTagBuildCommands(b, darwinBuildOptions{unlockKeychain: true}), }, { Name: "Copy Mac artifacts", Environment: map[string]value{ "WORKSPACE_DIR": {raw: p.Workspace.Path}, }, - Commands: darwinTagCopyPackageArtifactCommands(), + Commands: darwinTagCopyPackageArtifactCommands(b), }, { Name: "Upload to S3", @@ -140,8 +162,8 @@ func darwinTagPipeline() pipeline { Failure: "ignore", Environment: map[string]value{ "WORKSPACE_DIR": {raw: p.Workspace.Path}, - "RELEASES_CERT": value{fromSecret: "RELEASES_CERT_STAGING"}, - "RELEASES_KEY": value{fromSecret: "RELEASES_KEY_STAGING"}, + "RELEASES_CERT": {fromSecret: "RELEASES_CERT_STAGING"}, + "RELEASES_KEY": {fromSecret: "RELEASES_KEY_STAGING"}, }, }, cleanUpToolchainsStep(p.Workspace.Path), @@ -150,13 +172,27 @@ func darwinTagPipeline() pipeline { return p } -func pushCheckoutCommandsDarwin() []string { - return []string{ +func pushCheckoutCommandsDarwin(b buildType) []string { + commands := []string{ `set -u`, `mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, `git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .`, `git checkout ${DRONE_TAG:-$DRONE_COMMIT}`, + } + + // clone github.com/gravitational/webapps for the Teleport Connect source code + if b.hasTeleportConnect() { + commands = append(commands, + `mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`, + `git clone https://github.com/gravitational/webapps.git .`, + `git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)`, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, + ) + } + + commands = append(commands, // fetch enterprise submodules // suppressing the newline on the end of the private key makes git operations fail on MacOS // with an error like 'Load key "/path/.ssh/id_rsa": invalid format' @@ -168,7 +204,9 @@ func pushCheckoutCommandsDarwin() []string { `GIT_SSH_COMMAND='ssh -i $WORKSPACE_DIR/.ssh/id_rsa -o UserKnownHostsFile=$WORKSPACE_DIR/.ssh/known_hosts -F /dev/null' git submodule update --init --recursive webassets || true`, `rm -rf $WORKSPACE_DIR/.ssh`, `mkdir -p $WORKSPACE_DIR/go/cache`, - } + ) + + return commands } func setUpExecStorageStep(path string) step { @@ -192,9 +230,9 @@ func installGoToolchainStep() step { }, Commands: []string{ `set -u`, - `mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `mkdir -p ` + perBuildToolchainsDir, `curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz`, - `tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz`, + `tar -C ` + perBuildToolchainsDir + ` -xzf $RUNTIME.darwin-amd64.tar.gz`, `rm -rf $RUNTIME.darwin-amd64.tar.gz`, }, } @@ -206,16 +244,38 @@ func installRustToolchainStep(path string) step { Environment: map[string]value{"WORKSPACE_DIR": {raw: path}}, Commands: []string{ `set -u`, - `export PATH=/Users/build/.cargo/bin:$PATH`, - `mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export PATH=/Users/$(whoami)/.cargo/bin:$PATH`, // use the system-installed rustup to install our custom Rust version + `mkdir -p ` + perBuildToolchainsDir, `export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`, - `export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export CARGO_HOME=` + perBuildCargoDir, `export RUST_HOME=$CARGO_HOME`, + `export RUSTUP_HOME=` + perBuildRustupDir, `rustup toolchain install $RUST_VERSION`, }, } } +func installNodeToolchainStep(workspacePath string) step { + return step{ + Name: "Install Node Toolchain", + Environment: map[string]value{"WORKSPACE_DIR": {raw: workspacePath}}, + Commands: []string{ + `set -u`, + `export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-node-version)`, + `export TOOLCHAIN_DIR=` + perBuildToolchainsDir, + `export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64`, + `mkdir -p $TOOLCHAIN_DIR`, + `curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz`, + `tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz`, + `rm -f node-v$NODE_VERSION-darwin-x64.tar.gz`, + `export PATH=$NODE_DIR/bin:$PATH`, + `corepack enable yarn`, + `echo Node reporting version $(node --version)`, + `echo Yarn reporting version $(yarn --version)`, + }, + } +} + func cleanUpToolchainsStep(path string) step { return step{ Name: "Clean up toolchains (post)", @@ -225,16 +285,17 @@ func cleanUpToolchainsStep(path string) step { }, Commands: []string{ `set -u`, - `export PATH=/Users/build/.cargo/bin:$PATH`, - `export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export PATH=/Users/$(whoami)/.cargo/bin:$PATH`, + `export CARGO_HOME=` + perBuildCargoDir, `export RUST_HOME=$CARGO_HOME`, + `export RUSTUP_HOME=` + perBuildRustupDir, `export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, // clean up the rust toolchain even though we're about to delete the directory // this ensures we don't leave behind a broken link `rustup override unset`, `rustup toolchain uninstall $RUST_VERSION`, - `rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `rm -rf ` + perBuildDir, }, } } @@ -251,39 +312,87 @@ func cleanUpExecStorageStep(path string) step { } } -func darwinTagCheckoutCommands() []string { - return append(pushCheckoutCommandsDarwin(), +func darwinTagCheckoutCommands(b buildType) []string { + return append( + pushCheckoutCommandsDarwin(b), `mkdir -p $WORKSPACE_DIR/go/artifacts`, `echo "${DRONE_TAG##v}" > $WORKSPACE_DIR/go/.version.txt`, `cat $WORKSPACE_DIR/go/.version.txt`, ) } -func darwinTagBuildCommands() []string { - return []string{ +type darwinBuildOptions struct { + unlockKeychain bool +} + +func darwinTagBuildCommands(b buildType, opts darwinBuildOptions) []string { + commands := []string{ `set -u`, + `echo HOME=$${HOME}`, + `export HOME=/Users/$(whoami)`, + `export TOOLCHAIN_DIR=` + perBuildToolchainsDir, + `export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-node-version)`, `export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`, - `export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`, + `export CARGO_HOME=` + perBuildCargoDir, `export RUST_HOME=$CARGO_HOME`, - `export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH`, + `export RUSTUP_HOME=` + perBuildRustupDir, + `export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64`, + `export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, `build.assets/build-fido2-macos.sh build`, `export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)"`, `rustup override set $RUST_VERSION`, - `make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes`, } + + if opts.unlockKeychain { + commands = append(commands, + `security unlock-keychain -p $${BUILDBOX_PASSWORD} login.keychain`, + `security find-identity -v`, + ) + } + + commands = append(commands, + `make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes`, + ) + + if b.hasTeleportConnect() { + commands = append(commands, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`, + `yarn install --frozen-lockfile && yarn build-term && yarn package-term`, + ) + } + + return commands } -func darwinTagCopyPackageArtifactCommands() []string { - return []string{ +func darwinTagCopyPackageArtifactCommands(b buildType) []string { + commands := []string{ `set -u`, `cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`, // copy release archives to artifact directory `cp teleport*.tar.gz $WORKSPACE_DIR/go/artifacts`, `cp e/teleport-ent*.tar.gz $WORKSPACE_DIR/go/artifacts`, - // generate checksums (for mac) - `cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l`, } + + // copy Teleport Connect artifacts + if b.hasTeleportConnect() { + commands = append(commands, + `cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps/packages/teleterm/build/release`, + `cp *.dmg $WORKSPACE_DIR/go/artifacts`, + ) + } + + // generate checksums + commands = append(commands, + `cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l`, + ) + if b.hasTeleportConnect() { + commands = append(commands, + `cd $WORKSPACE_DIR/go/artifacts && for FILE in *.dmg; do shasum -a 256 "$FILE" > "$FILE.sha256"; done && ls -l`, + ) + } + + return commands } func darwinUploadToS3Commands() []string { diff --git a/dronegen/mac_pkg.go b/dronegen/mac_pkg.go index 395ce5bc9f5..77406ddaa2b 100644 --- a/dronegen/mac_pkg.go +++ b/dronegen/mac_pkg.go @@ -36,7 +36,7 @@ func darwinPkgPipeline(name, makeTarget string, pkgGlobs []string, extraQualific "WORKSPACE_DIR": {raw: p.Workspace.Path}, "GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"}, }, - Commands: darwinTagCheckoutCommands(), + Commands: darwinTagCheckoutCommands(b), }, { Name: "Download built tarball artifacts from S3", diff --git a/dronegen/tag.go b/dronegen/tag.go index a2cade6f34b..922fc105f5e 100644 --- a/dronegen/tag.go +++ b/dronegen/tag.go @@ -82,6 +82,16 @@ func tagBuildCommands(b buildType) []string { ), ) + // Build Teleport Connect on suported OS/arch + if b.hasTeleportConnect() { + commands = append(commands, + `cd /go/src/github.com/gravitational/webapps`, + `yarn install --frozen-lockfile && yarn build-term && yarn package-term`, + `cd -`, + ) + + } + if b.os == "windows" { commands = append(commands, `rm -f windows-signing-cert.pfx`,