You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

628 lines
18 KiB

7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
  1. stages:
  2. - moderator
  3. - unit-tests
  4. - deploy-gce-part1
  5. - deploy-gce-part2
  6. - deploy-gce-special
  7. variables:
  8. FAILFASTCI_NAMESPACE: 'kargo-ci'
  9. # DOCKER_HOST: tcp://localhost:2375
  10. ANSIBLE_FORCE_COLOR: "true"
  11. # asia-east1-a
  12. # asia-northeast1-a
  13. # europe-west1-b
  14. # us-central1-a
  15. # us-east1-b
  16. # us-west1-a
  17. before_script:
  18. - pip install ansible==2.3.0
  19. - pip install netaddr
  20. - pip install apache-libcloud==0.20.1
  21. - pip install boto==2.9.0
  22. - mkdir -p /.ssh
  23. - cp tests/ansible.cfg .
  24. .job: &job
  25. tags:
  26. - kubernetes
  27. - docker
  28. image: quay.io/ant31/kargo:master
  29. .docker_service: &docker_service
  30. services:
  31. - docker:dind
  32. .create_cluster: &create_cluster
  33. <<: *job
  34. <<: *docker_service
  35. .gce_variables: &gce_variables
  36. GCE_USER: travis
  37. SSH_USER: $GCE_USER
  38. TEST_ID: "$CI_PIPELINE_ID-$CI_BUILD_ID"
  39. CONTAINER_ENGINE: docker
  40. PRIVATE_KEY: $GCE_PRIVATE_KEY
  41. GS_ACCESS_KEY_ID: $GS_KEY
  42. GS_SECRET_ACCESS_KEY: $GS_SECRET
  43. CLOUD_MACHINE_TYPE: "g1-small"
  44. ANSIBLE_KEEP_REMOTE_FILES: "1"
  45. ANSIBLE_CONFIG: ./tests/ansible.cfg
  46. BOOTSTRAP_OS: none
  47. DOWNLOAD_LOCALHOST: "false"
  48. DOWNLOAD_RUN_ONCE: "false"
  49. IDEMPOT_CHECK: "false"
  50. RESET_CHECK: "false"
  51. UPGRADE_TEST: "false"
  52. RESOLVCONF_MODE: docker_dns
  53. LOG_LEVEL: "-vv"
  54. ETCD_DEPLOYMENT: "docker"
  55. KUBELET_DEPLOYMENT: "docker"
  56. VAULT_DEPLOYMENT: "docker"
  57. WEAVE_CPU_LIMIT: "100m"
  58. MAGIC: "ci check this"
  59. .gce: &gce
  60. <<: *job
  61. <<: *docker_service
  62. cache:
  63. key: "$CI_BUILD_REF_NAME"
  64. paths:
  65. - downloads/
  66. - $HOME/.cache
  67. before_script:
  68. - docker info
  69. - pip install ansible==2.3.0
  70. - pip install netaddr
  71. - pip install apache-libcloud==0.20.1
  72. - pip install boto==2.9.0
  73. - mkdir -p /.ssh
  74. - mkdir -p $HOME/.ssh
  75. - echo $PRIVATE_KEY | base64 -d > $HOME/.ssh/id_rsa
  76. - echo $GCE_PEM_FILE | base64 -d > $HOME/.ssh/gce
  77. - echo $GCE_CREDENTIALS > $HOME/.ssh/gce.json
  78. - chmod 400 $HOME/.ssh/id_rsa
  79. - ansible-playbook --version
  80. - export PYPATH=$([ $BOOTSTRAP_OS = none ] && echo /usr/bin/python || echo /opt/bin/python)
  81. script:
  82. - pwd
  83. - ls
  84. - echo ${PWD}
  85. - echo "${STARTUP_SCRIPT}"
  86. - >
  87. ansible-playbook tests/cloud_playbooks/create-gce.yml -i tests/local_inventory/hosts.cfg -c local
  88. ${LOG_LEVEL}
  89. -e cloud_image=${CLOUD_IMAGE}
  90. -e cloud_region=${CLOUD_REGION}
  91. -e gce_credentials_file=${HOME}/.ssh/gce.json
  92. -e gce_project_id=${GCE_PROJECT_ID}
  93. -e gce_service_account_email=${GCE_ACCOUNT}
  94. -e cloud_machine_type=${CLOUD_MACHINE_TYPE}
  95. -e inventory_path=${PWD}/inventory/inventory.ini
  96. -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  97. -e mode=${CLUSTER_MODE}
  98. -e test_id=${TEST_ID}
  99. -e startup_script="'${STARTUP_SCRIPT}'"
  100. # Check out latest tag if testing upgrade
  101. # Uncomment when gitlab kargo repo has tags
  102. #- test "${UPGRADE_TEST}" != "false" && git fetch --all && git checkout $(git describe --tags $(git rev-list --tags --max-count=1))
  103. - test "${UPGRADE_TEST}" != "false" && git checkout 031cf565ec3ccd3ebbe80eeef3454c3780e5c598 && pip install ansible==2.2.0
  104. # Create cluster
  105. - >
  106. ansible-playbook -i inventory/inventory.ini -b --become-user=root --private-key=${HOME}/.ssh/id_rsa -u $SSH_USER
  107. ${SSH_ARGS}
  108. ${LOG_LEVEL}
  109. -e ansible_python_interpreter=${PYPATH}
  110. -e ansible_ssh_user=${SSH_USER}
  111. -e bootstrap_os=${BOOTSTRAP_OS}
  112. -e cert_management=${CERT_MGMT:-script}
  113. -e cloud_provider=gce
  114. -e deploy_netchecker=true
  115. -e download_localhost=${DOWNLOAD_LOCALHOST}
  116. -e download_run_once=${DOWNLOAD_RUN_ONCE}
  117. -e etcd_deployment_type=${ETCD_DEPLOYMENT}
  118. -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  119. -e kubedns_min_replicas=1
  120. -e kubelet_deployment_type=${KUBELET_DEPLOYMENT}
  121. -e local_release_dir=${PWD}/downloads
  122. -e resolvconf_mode=${RESOLVCONF_MODE}
  123. -e vault_deployment_type=${VAULT_DEPLOYMENT}
  124. --limit "all:!fake_hosts"
  125. cluster.yml
  126. # Repeat deployment if testing upgrade
  127. - >
  128. if [ "${UPGRADE_TEST}" != "false" ]; then
  129. test "${UPGRADE_TEST}" == "basic" && PLAYBOOK="cluster.yml";
  130. test "${UPGRADE_TEST}" == "graceful" && PLAYBOOK="upgrade-cluster.yml";
  131. pip install ansible==2.3.0;
  132. git checkout "${CI_BUILD_REF}";
  133. ansible-playbook -i inventory/inventory.ini -b --become-user=root --private-key=${HOME}/.ssh/id_rsa -u $SSH_USER
  134. ${SSH_ARGS}
  135. ${LOG_LEVEL}
  136. -e ansible_python_interpreter=${PYPATH}
  137. -e ansible_ssh_user=${SSH_USER}
  138. -e bootstrap_os=${BOOTSTRAP_OS}
  139. -e cloud_provider=gce
  140. -e deploy_netchecker=true
  141. -e download_localhost=${DOWNLOAD_LOCALHOST}
  142. -e download_run_once=${DOWNLOAD_RUN_ONCE}
  143. -e etcd_deployment_type=${ETCD_DEPLOYMENT}
  144. -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  145. -e kubedns_min_replicas=1
  146. -e kubelet_deployment_type=${KUBELET_DEPLOYMENT}
  147. -e local_release_dir=${PWD}/downloads
  148. -e resolvconf_mode=${RESOLVCONF_MODE}
  149. -e weave_cpu_requests=${WEAVE_CPU_LIMIT}
  150. -e weave_cpu_limit=${WEAVE_CPU_LIMIT}
  151. --limit "all:!fake_hosts"
  152. $PLAYBOOK;
  153. fi
  154. # Tests Cases
  155. ## Test Master API
  156. - ansible-playbook -i inventory/inventory.ini -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/010_check-apiserver.yml $LOG_LEVEL
  157. ## Ping the between 2 pod
  158. - ansible-playbook -i inventory/inventory.ini -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/030_check-network.yml $LOG_LEVEL
  159. ## Advanced DNS checks
  160. - ansible-playbook -i inventory/inventory.ini -e ansible_python_interpreter=${PYPATH} -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root --limit "all:!fake_hosts" tests/testcases/040_check-network-adv.yml $LOG_LEVEL
  161. ## Idempotency checks 1/5 (repeat deployment)
  162. - >
  163. if [ "${IDEMPOT_CHECK}" = "true" ]; then
  164. ansible-playbook -i inventory/inventory.ini -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS
  165. -b --become-user=root -e cloud_provider=gce $LOG_LEVEL -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  166. --private-key=${HOME}/.ssh/id_rsa
  167. -e bootstrap_os=${BOOTSTRAP_OS}
  168. -e ansible_python_interpreter=${PYPATH}
  169. -e download_localhost=${DOWNLOAD_LOCALHOST}
  170. -e download_run_once=${DOWNLOAD_RUN_ONCE}
  171. -e deploy_netchecker=true
  172. -e resolvconf_mode=${RESOLVCONF_MODE}
  173. -e local_release_dir=${PWD}/downloads
  174. -e etcd_deployment_type=${ETCD_DEPLOYMENT}
  175. -e kubedns_min_replicas=1
  176. -e kubelet_deployment_type=${KUBELET_DEPLOYMENT}
  177. --limit "all:!fake_hosts"
  178. cluster.yml;
  179. fi
  180. ## Idempotency checks 2/5 (Advanced DNS checks)
  181. - >
  182. if [ "${IDEMPOT_CHECK}" = "true" ]; then
  183. ansible-playbook -i inventory/inventory.ini -e ansible_python_interpreter=${PYPATH}
  184. -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root
  185. --limit "all:!fake_hosts"
  186. tests/testcases/040_check-network-adv.yml $LOG_LEVEL;
  187. fi
  188. ## Idempotency checks 3/5 (reset deployment)
  189. - >
  190. if [ "${IDEMPOT_CHECK}" = "true" AND "${RESET_CHECK}" = "true" ]; then
  191. ansible-playbook -i inventory/inventory.ini -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS
  192. -b --become-user=root -e cloud_provider=gce $LOG_LEVEL -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  193. --private-key=${HOME}/.ssh/id_rsa
  194. -e bootstrap_os=${BOOTSTRAP_OS}
  195. -e ansible_python_interpreter=${PYPATH}
  196. -e reset_confirmation=yes
  197. --limit "all:!fake_hosts"
  198. reset.yml;
  199. fi
  200. ## Idempotency checks 4/5 (redeploy after reset)
  201. - >
  202. if [ "${IDEMPOT_CHECK}" = "true" AND "${RESET_CHECK}" = "true" ]; then
  203. ansible-playbook -i inventory/inventory.ini -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS
  204. -b --become-user=root -e cloud_provider=gce $LOG_LEVEL -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  205. --private-key=${HOME}/.ssh/id_rsa
  206. -e bootstrap_os=${BOOTSTRAP_OS}
  207. -e ansible_python_interpreter=${PYPATH}
  208. -e download_localhost=${DOWNLOAD_LOCALHOST}
  209. -e download_run_once=${DOWNLOAD_RUN_ONCE}
  210. -e deploy_netchecker=true
  211. -e resolvconf_mode=${RESOLVCONF_MODE}
  212. -e local_release_dir=${PWD}/downloads
  213. -e etcd_deployment_type=${ETCD_DEPLOYMENT}
  214. -e kubedns_min_replicas=1
  215. -e kubelet_deployment_type=${KUBELET_DEPLOYMENT}
  216. --limit "all:!fake_hosts"
  217. cluster.yml;
  218. fi
  219. ## Idempotency checks 5/5 (Advanced DNS checks)
  220. - >
  221. if [ "${IDEMPOT_CHECK}" = "true" AND "${RESET_CHECK}" = "true" ]; then
  222. ansible-playbook -i inventory/inventory.ini -e ansible_python_interpreter=${PYPATH}
  223. -u $SSH_USER -e ansible_ssh_user=$SSH_USER $SSH_ARGS -b --become-user=root
  224. --limit "all:!fake_hosts"
  225. tests/testcases/040_check-network-adv.yml $LOG_LEVEL;
  226. fi
  227. after_script:
  228. - >
  229. ansible-playbook -i inventory/inventory.ini tests/cloud_playbooks/delete-gce.yml -c local $LOG_LEVEL
  230. -e mode=${CLUSTER_MODE}
  231. -e test_id=${TEST_ID}
  232. -e kube_network_plugin=${KUBE_NETWORK_PLUGIN}
  233. -e gce_project_id=${GCE_PROJECT_ID}
  234. -e gce_service_account_email=${GCE_ACCOUNT}
  235. -e gce_credentials_file=${HOME}/.ssh/gce.json
  236. -e cloud_image=${CLOUD_IMAGE}
  237. -e inventory_path=${PWD}/inventory/inventory.ini
  238. -e cloud_region=${CLOUD_REGION}
  239. # Test matrix. Leave the comments for markup scripts.
  240. .coreos_calico_sep_variables: &coreos_calico_sep_variables
  241. # stage: deploy-gce-part1
  242. KUBE_NETWORK_PLUGIN: calico
  243. CLOUD_IMAGE: coreos-stable
  244. CLOUD_REGION: us-west1-b
  245. CLUSTER_MODE: separate
  246. BOOTSTRAP_OS: coreos
  247. RESOLVCONF_MODE: host_resolvconf # This is required as long as the CoreOS stable channel uses docker < 1.12
  248. ##User-data to simply turn off coreos upgrades
  249. STARTUP_SCRIPT: 'systemctl disable locksmithd && systemctl stop locksmithd'
  250. .ubuntu_canal_ha_variables: &ubuntu_canal_ha_variables
  251. # stage: deploy-gce-part1
  252. KUBE_NETWORK_PLUGIN: canal
  253. CLOUD_IMAGE: ubuntu-1604-xenial
  254. CLOUD_REGION: europe-west1-b
  255. CLOUD_MACHINE_TYPE: "n1-standard-2"
  256. UPGRADE_TEST: "basic"
  257. CLUSTER_MODE: ha
  258. UPGRADE_TEST: "graceful"
  259. STARTUP_SCRIPT: ""
  260. .rhel7_weave_variables: &rhel7_weave_variables
  261. # stage: deploy-gce-part1
  262. KUBE_NETWORK_PLUGIN: weave
  263. CLOUD_IMAGE: rhel-7
  264. CLOUD_REGION: europe-west1-b
  265. CLUSTER_MODE: default
  266. STARTUP_SCRIPT: ""
  267. .centos7_flannel_variables: &centos7_flannel_variables
  268. # stage: deploy-gce-part2
  269. KUBE_NETWORK_PLUGIN: flannel
  270. CLOUD_IMAGE: centos-7
  271. CLOUD_REGION: us-west1-a
  272. CLUSTER_MODE: default
  273. STARTUP_SCRIPT: ""
  274. .debian8_calico_variables: &debian8_calico_variables
  275. # stage: deploy-gce-part2
  276. KUBE_NETWORK_PLUGIN: calico
  277. CLOUD_IMAGE: debian-8-kubespray
  278. CLOUD_REGION: us-central1-b
  279. CLUSTER_MODE: default
  280. STARTUP_SCRIPT: ""
  281. .coreos_canal_variables: &coreos_canal_variables
  282. # stage: deploy-gce-part2
  283. KUBE_NETWORK_PLUGIN: canal
  284. CLOUD_IMAGE: coreos-stable
  285. CLOUD_REGION: us-east1-b
  286. CLUSTER_MODE: default
  287. BOOTSTRAP_OS: coreos
  288. IDEMPOT_CHECK: "true"
  289. RESOLVCONF_MODE: host_resolvconf # This is required as long as the CoreOS stable channel uses docker < 1.12
  290. STARTUP_SCRIPT: 'systemctl disable locksmithd && systemctl stop locksmithd'
  291. .rhel7_canal_sep_variables: &rhel7_canal_sep_variables
  292. # stage: deploy-gce-special
  293. KUBE_NETWORK_PLUGIN: canal
  294. CLOUD_IMAGE: rhel-7
  295. CLOUD_REGION: us-east1-b
  296. CLUSTER_MODE: separate
  297. STARTUP_SCRIPT: ""
  298. .ubuntu_weave_sep_variables: &ubuntu_weave_sep_variables
  299. # stage: deploy-gce-special
  300. KUBE_NETWORK_PLUGIN: weave
  301. CLOUD_IMAGE: ubuntu-1604-xenial
  302. CLOUD_REGION: us-central1-b
  303. CLUSTER_MODE: separate
  304. IDEMPOT_CHECK: "false"
  305. STARTUP_SCRIPT: ""
  306. .centos7_calico_ha_variables: &centos7_calico_ha_variables
  307. # stage: deploy-gce-special
  308. KUBE_NETWORK_PLUGIN: calico
  309. DOWNLOAD_LOCALHOST: "true"
  310. DOWNLOAD_RUN_ONCE: "true"
  311. CLOUD_IMAGE: centos-7
  312. CLOUD_REGION: europe-west1-b
  313. CLUSTER_MODE: ha-scale
  314. IDEMPOT_CHECK: "true"
  315. STARTUP_SCRIPT: ""
  316. .coreos_alpha_weave_ha_variables: &coreos_alpha_weave_ha_variables
  317. # stage: deploy-gce-special
  318. KUBE_NETWORK_PLUGIN: weave
  319. CLOUD_IMAGE: coreos-alpha-1325-0-0-v20170216
  320. CLOUD_REGION: us-west1-a
  321. CLUSTER_MODE: ha-scale
  322. BOOTSTRAP_OS: coreos
  323. RESOLVCONF_MODE: host_resolvconf # This is required as long as the CoreOS stable channel uses docker < 1.12
  324. STARTUP_SCRIPT: 'systemctl disable locksmithd && systemctl stop locksmithd'
  325. .ubuntu_rkt_sep_variables: &ubuntu_rkt_sep_variables
  326. # stage: deploy-gce-part1
  327. KUBE_NETWORK_PLUGIN: flannel
  328. CLOUD_IMAGE: ubuntu-1604-xenial
  329. CLOUD_REGION: us-central1-b
  330. CLUSTER_MODE: separate
  331. ETCD_DEPLOYMENT: rkt
  332. KUBELET_DEPLOYMENT: rkt
  333. STARTUP_SCRIPT: ""
  334. .ubuntu_vault_sep_variables: &ubuntu_vault_sep_variables
  335. # stage: deploy-gce-part1
  336. KUBE_NETWORK_PLUGIN: canal
  337. CERT_MGMT: vault
  338. CLOUD_IMAGE: ubuntu-1604-xenial
  339. CLOUD_REGION: us-central1-b
  340. CLUSTER_MODE: separate
  341. STARTUP_SCRIPT: ""
  342. # Builds for PRs only (premoderated by unit-tests step) and triggers (auto)
  343. coreos-calico-sep:
  344. stage: deploy-gce-part1
  345. <<: *job
  346. <<: *gce
  347. variables:
  348. <<: *gce_variables
  349. <<: *coreos_calico_sep_variables
  350. when: on_success
  351. except: ['triggers']
  352. only: [/^pr-.*$/]
  353. coreos-calico-sep-triggers:
  354. stage: deploy-gce-part1
  355. <<: *job
  356. <<: *gce
  357. variables:
  358. <<: *gce_variables
  359. <<: *coreos_calico_sep_variables
  360. when: on_success
  361. only: ['triggers']
  362. centos7-flannel:
  363. stage: deploy-gce-part2
  364. <<: *job
  365. <<: *gce
  366. variables:
  367. <<: *gce_variables
  368. <<: *centos7_flannel_variables
  369. when: on_success
  370. except: ['triggers']
  371. only: [/^pr-.*$/]
  372. centos7-flannel-triggers:
  373. stage: deploy-gce-part1
  374. <<: *job
  375. <<: *gce
  376. variables:
  377. <<: *gce_variables
  378. <<: *centos7_flannel_variables
  379. when: on_success
  380. only: ['triggers']
  381. ubuntu-weave-sep:
  382. stage: deploy-gce-special
  383. <<: *job
  384. <<: *gce
  385. variables:
  386. <<: *gce_variables
  387. <<: *ubuntu_weave_sep_variables
  388. when: on_success
  389. except: ['triggers']
  390. only: [/^pr-.*$/]
  391. ubuntu-weave-sep-triggers:
  392. stage: deploy-gce-part1
  393. <<: *job
  394. <<: *gce
  395. variables:
  396. <<: *gce_variables
  397. <<: *ubuntu_weave_sep_variables
  398. when: on_success
  399. only: ['triggers']
  400. # More builds for PRs/merges (manual) and triggers (auto)
  401. ubuntu-canal-ha:
  402. stage: deploy-gce-part1
  403. <<: *job
  404. <<: *gce
  405. variables:
  406. <<: *gce_variables
  407. <<: *ubuntu_canal_ha_variables
  408. when: manual
  409. except: ['triggers']
  410. only: ['master', /^pr-.*$/]
  411. ubuntu-canal-ha-triggers:
  412. stage: deploy-gce-part1
  413. <<: *job
  414. <<: *gce
  415. variables:
  416. <<: *gce_variables
  417. <<: *ubuntu_canal_ha_variables
  418. when: on_success
  419. only: ['triggers']
  420. rhel7-weave:
  421. stage: deploy-gce-part1
  422. <<: *job
  423. <<: *gce
  424. variables:
  425. <<: *gce_variables
  426. <<: *rhel7_weave_variables
  427. when: manual
  428. except: ['triggers']
  429. only: ['master', /^pr-.*$/]
  430. rhel7-weave-triggers:
  431. stage: deploy-gce-part1
  432. <<: *job
  433. <<: *gce
  434. variables:
  435. <<: *gce_variables
  436. <<: *rhel7_weave_variables
  437. when: on_success
  438. only: ['triggers']
  439. debian8-calico-upgrade:
  440. stage: deploy-gce-part2
  441. <<: *job
  442. <<: *gce
  443. variables:
  444. <<: *gce_variables
  445. <<: *debian8_calico_variables
  446. when: manual
  447. except: ['triggers']
  448. only: ['master', /^pr-.*$/]
  449. debian8-calico-triggers:
  450. stage: deploy-gce-part1
  451. <<: *job
  452. <<: *gce
  453. variables:
  454. <<: *gce_variables
  455. <<: *debian8_calico_variables
  456. when: on_success
  457. only: ['triggers']
  458. coreos-canal:
  459. stage: deploy-gce-part2
  460. <<: *job
  461. <<: *gce
  462. variables:
  463. <<: *gce_variables
  464. <<: *coreos_canal_variables
  465. when: manual
  466. except: ['triggers']
  467. only: ['master', /^pr-.*$/]
  468. coreos-canal-triggers:
  469. stage: deploy-gce-part1
  470. <<: *job
  471. <<: *gce
  472. variables:
  473. <<: *gce_variables
  474. <<: *coreos_canal_variables
  475. when: on_success
  476. only: ['triggers']
  477. rhel7-canal-sep:
  478. stage: deploy-gce-special
  479. <<: *job
  480. <<: *gce
  481. variables:
  482. <<: *gce_variables
  483. <<: *rhel7_canal_sep_variables
  484. when: manual
  485. except: ['triggers']
  486. only: ['master', /^pr-.*$/,]
  487. rhel7-canal-sep-triggers:
  488. stage: deploy-gce-part1
  489. <<: *job
  490. <<: *gce
  491. variables:
  492. <<: *gce_variables
  493. <<: *rhel7_canal_sep_variables
  494. when: on_success
  495. only: ['triggers']
  496. centos7-calico-ha:
  497. stage: deploy-gce-special
  498. <<: *job
  499. <<: *gce
  500. variables:
  501. <<: *gce_variables
  502. <<: *centos7_calico_ha_variables
  503. when: manual
  504. except: ['triggers']
  505. only: ['master', /^pr-.*$/]
  506. centos7-calico-ha-triggers:
  507. stage: deploy-gce-part1
  508. <<: *job
  509. <<: *gce
  510. variables:
  511. <<: *gce_variables
  512. <<: *centos7_calico_ha_variables
  513. when: on_success
  514. only: ['triggers']
  515. # no triggers yet https://github.com/kubernetes-incubator/kargo/issues/613
  516. coreos-alpha-weave-ha:
  517. stage: deploy-gce-special
  518. <<: *job
  519. <<: *gce
  520. variables:
  521. <<: *gce_variables
  522. <<: *coreos_alpha_weave_ha_variables
  523. when: manual
  524. except: ['triggers']
  525. only: ['master', /^pr-.*$/]
  526. ubuntu-rkt-sep:
  527. stage: deploy-gce-part1
  528. <<: *job
  529. <<: *gce
  530. variables:
  531. <<: *gce_variables
  532. <<: *ubuntu_rkt_sep_variables
  533. when: manual
  534. except: ['triggers']
  535. only: ['master', /^pr-.*$/]
  536. ubuntu-vault-sep:
  537. stage: deploy-gce-part1
  538. <<: *job
  539. <<: *gce
  540. variables:
  541. <<: *gce_variables
  542. <<: *ubuntu_vault_sep_variables
  543. when: manual
  544. except: ['triggers']
  545. only: ['master', /^pr-.*$/]
  546. # Premoderated with manual actions
  547. ci-authorized:
  548. <<: *job
  549. stage: moderator
  550. before_script:
  551. - apt-get -y install jq
  552. script:
  553. - /bin/sh scripts/premoderator.sh
  554. except: ['triggers', 'master']
  555. syntax-check:
  556. <<: *job
  557. stage: unit-tests
  558. script:
  559. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root cluster.yml -vvv --syntax-check
  560. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root upgrade-cluster.yml -vvv --syntax-check
  561. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root reset.yml -vvv --syntax-check
  562. - ansible-playbook -i inventory/local-tests.cfg -u root -e ansible_ssh_user=root -b --become-user=root extra_playbooks/upgrade-only-k8s.yml -vvv --syntax-check
  563. except: ['triggers', 'master']
  564. tox-inventory-builder:
  565. stage: unit-tests
  566. <<: *job
  567. script:
  568. - pip install tox
  569. - cd contrib/inventory_builder && tox
  570. when: manual
  571. except: ['triggers', 'master']