Skip to content
.gitlab-ci.yml 2.46 KiB
Newer Older
Timo Furrer's avatar
Timo Furrer committed
include: 
Timo Furrer's avatar
Timo Furrer committed
  - local: tests/unit.gitlab-ci.yml
  - local: tests/integration.gitlab-ci.yml
Timo Furrer's avatar
Timo Furrer committed

Timo Furrer's avatar
Timo Furrer committed
  - test
Timo Furrer's avatar
Timo Furrer committed
  - test-integration
Timo Furrer's avatar
Timo Furrer committed
  - deploy
  - release
Timo Furrer's avatar
Timo Furrer committed
.opentofu-versions:
Timo Furrer's avatar
Timo Furrer committed
      - OPENTOFU_VERSION: '1.6.0'
      - OPENTOFU_VERSION: '1.6.0-rc1'

variables:
Timo Furrer's avatar
Timo Furrer committed
  # OpenTofu variables
  STABLE_OPENTOFU_VERSION: '1.6.0'

  # OpenTofu image build variables:
  DOCKER_DIND_IMAGE: "docker:24.0.7-dind"
  PLATFORMS: linux/amd64,linux/arm64
  BASE_IMAGE: "alpine:3.18.4"
  GITLAB_OPENTOFU_IMAGE_NAME: "$CI_REGISTRY_IMAGE/internal/gitlab-opentofu-$OPENTOFU_VERSION:$CI_COMMIT_SHA"

Timo Furrer's avatar
Timo Furrer committed
gitlab-opentofu-image:build:
Timo Furrer's avatar
Timo Furrer committed
  extends: .opentofu-versions
  stage: build
  services:
    - "$DOCKER_DIND_IMAGE"
  image: "$DOCKER_DIND_IMAGE"
  before_script:
    # See note on the `build terraform` job about this image
    - docker run --rm --privileged tonistiigi/binfmt
    # Registry auth
    - docker login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY"
  script:
    - docker buildx create --use
    # NOTE: we disable provenance for now
    # because it causes troubles with the registry and older clients.
    # See
    # - https://gitlab.com/gitlab-org/terraform-images/-/issues/104
    # - https://gitlab.com/gitlab-org/terraform-images/-/merge_requests/184#note_1328485943
    - docker buildx build
      --platform "$PLATFORMS"
      --build-arg BASE_IMAGE=$BASE_IMAGE
      --build-arg OPENTOFU_VERSION=$OPENTOFU_VERSION
      --file Dockerfile
      --tag "$GITLAB_OPENTOFU_IMAGE_NAME"
      --provenance=false
      --push
      .

Timo Furrer's avatar
Timo Furrer committed
gitlab-opentofu-image:deploy:
  extends: .opentofu-versions
  stage: deploy
  image:
    name: gcr.io/go-containerregistry/crane:debug
    entrypoint: [""]
  variables:
    RELEASE_IMAGE_NAME: "$CI_REGISTRY_IMAGE/gitlab-opentofu"
    RELEASE_SEMVER: "${CI_COMMIT_TAG}+opentofu-${OPENTOFU_VERSION}"
  before_script:
    - crane auth login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY"
  script:
    - crane copy "$GITLAB_OPENTOFU_IMAGE_NAME" "$RELEASE_IMAGE_NAME:$RELEASE_SEMVER"
  rules:
    - if: $CI_COMMIT_TAG

# If the pipeline is for a new tag with a semantic version, and all previous jobs succeed,
# create the release.
Timo Furrer's avatar
Timo Furrer committed
create-release:
  stage: release
  image: registry.gitlab.com/gitlab-org/release-cli:latest
  rules:
    - if: $CI_COMMIT_TAG =~ /\d+/
  script: echo "Creating release $CI_COMMIT_TAG"
  release:
    tag_name: $CI_COMMIT_TAG
    description: "Release $CI_COMMIT_TAG of components repository $CI_PROJECT_PATH"