From e8814fccc0579a660b56c929407418007ec8ce4a Mon Sep 17 00:00:00 2001 From: yh-noh Date: Wed, 30 Sep 2026 16:59:45 +0900 Subject: [PATCH 1/4] =?UTF-8?q?fix(install):=20=EB=A1=9C=EA=B7=B8=20?= =?UTF-8?q?=EB=AA=A8=EB=93=9C=EC=97=90=EC=84=9C=20Wave=202=20=EC=9D=B4?= =?UTF-8?q?=ED=9B=84=EA=B0=80=20=EC=8B=A4=ED=96=89=EB=90=98=EC=A7=80=20?= =?UTF-8?q?=EC=95=8A=EB=8A=94=20=EB=AC=B8=EC=A0=9C=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - 로그 모드가 각 Wave를 attached(compose up)로 실행해 Wave 1에서 멈추고 이후 Wave(web-console 등)가 영영 기동되지 않던 문제 - 모든 Wave를 detached로 실행하는 run_startup_waves()로 통합, 로그 모드는 전체 기동 후 마지막에만 로그에 attach - Wave 진입점에서 닿지 않는 서비스(cost-optimizer collector/rightsizer, cb-mapui 등)를 위해 Wave 후 전체 run -d 단계 추가 --- bin/installAll.sh | 62 ++++++++++++++++++++++++++++------------------- 1 file changed, 37 insertions(+), 25 deletions(-) diff --git a/bin/installAll.sh b/bin/installAll.sh index 5691113..6dc96eb 100755 --- a/bin/installAll.sh +++ b/bin/installAll.sh @@ -168,6 +168,35 @@ STARTUP_WAVES=( "mc-application-manager mc-workflow-manager mc-cost-optimizer-fe" ) +# Starts every wave detached (-d), then one final full-stack `run -d` for the +# services no wave entry point reaches (cost-optimizer collectors/rightsizers, +# cb-mapui, ...). Waves must always be detached: an attached `compose up` never +# returns, so later waves would never start. +run_startup_waves() { + local wave_num=0 + local run_exit + for wave_services in "${STARTUP_WAVES[@]}"; do + wave_num=$((wave_num + 1)) + echo "" + echo "---- Wave $wave_num/${#STARTUP_WAVES[@]}: $wave_services ----" + ./mcc infra run -d -s "$wave_services" + run_exit=$? + if [ $run_exit -ne 0 ]; then + report_run_failure "$run_exit" "Wave $wave_num ($wave_services)" + exit 1 + fi + done + + echo "" + echo "---- Remaining services (not reached by any wave) ----" + ./mcc infra run -d + run_exit=$? + if [ $run_exit -ne 0 ]; then + report_run_failure "$run_exit" "remaining services" + exit 1 + fi +} + # Prints a consistent failure banner for a failed `./mcc infra run` invocation. report_run_failure() { local exit_code="$1" @@ -543,20 +572,14 @@ case $RUN_MODE in exit 1 fi - wave_num=0 - for wave_services in "${STARTUP_WAVES[@]}"; do - wave_num=$((wave_num + 1)) - echo "" - echo "---- Wave $wave_num/${#STARTUP_WAVES[@]}: $wave_services ----" - ./mcc infra run -s "$wave_services" - run_exit=$? - if [ $run_exit -ne 0 ]; then - report_run_failure "$run_exit" "Wave $wave_num ($wave_services)" - exit 1 - fi - done - + run_startup_waves check_post_initial + + # Attach to the whole stack only after every wave is up (Ctrl+C to detach; + # containers keep running) + echo "" + echo "All services started. Attaching to logs (Ctrl+C to stop following)..." + ./mcc infra run ;; background) echo "" @@ -579,18 +602,7 @@ case $RUN_MODE in echo "Image download and initial setup in progress..." echo "" - wave_num=0 - for wave_services in "${STARTUP_WAVES[@]}"; do - wave_num=$((wave_num + 1)) - echo "" - echo "---- Wave $wave_num/${#STARTUP_WAVES[@]}: $wave_services ----" - ./mcc infra run -d -s "$wave_services" - run_exit=$? - if [ $run_exit -ne 0 ]; then - report_run_failure "$run_exit" "Wave $wave_num ($wave_services)" - exit 1 - fi - done + run_startup_waves echo "" echo "Image download and initial setup completed." From e2b99e3aac748af007eb0814b8ee98e99d49a933 Mon Sep 17 00:00:00 2001 From: yh-noh Date: Wed, 30 Sep 2026 16:59:45 +0900 Subject: [PATCH 2/4] =?UTF-8?q?fix(workflow):=20Jenkins=20=ED=94=8C?= =?UTF-8?q?=EB=9F=AC=EA=B7=B8=EC=9D=B8=20=EB=8B=A4=EC=9A=B4=EB=A1=9C?= =?UTF-8?q?=EB=93=9C=20=EC=8B=A4=ED=8C=A8=20=EC=9E=AC=EC=8B=9C=EB=8F=84=20?= =?UTF-8?q?=EB=B0=8F=20healthcheck=20=EC=9C=A0=EC=98=88=20=ED=99=95?= =?UTF-8?q?=EB=8C=80?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - update site 다운로드 실패(Connection reset/timeout)는 예외 없이 설치 작업만 Failure로 남아, 누락된 의존 플러그인(joda-time-api 등) 때문에 재시작 후 로드 실패와 재시작 루프가 반복됨 - 플러그인별 마지막 InstallationJob이 Failure면 최대 5회 재시도, 끝내 실패하면 명시적으로 예외 발생 - 클린 설치 초기화가 약 9.5분 소요되어 기존 start_period(6m)+재시도 3회를 넘겨 unhealthy 판정 → mc-workflow-manager depends_on 실패. start_period 15m로 확대 --- conf/docker/docker-compose.yaml | 5 ++- .../tool/init.groovy.d/basic-security.groovy | 31 +++++++++++++++++++ 2 files changed, 35 insertions(+), 1 deletion(-) diff --git a/conf/docker/docker-compose.yaml b/conf/docker/docker-compose.yaml index a898ece..3f4fac0 100644 --- a/conf/docker/docker-compose.yaml +++ b/conf/docker/docker-compose.yaml @@ -1042,7 +1042,10 @@ services: curl -fsS -u "$${JENKINS_USERNAME}:$${JENKINS_PASSWORD}" http://localhost:8080/api/json > /dev/null <<: *default-health-check - start_period: 6m + # First boot downloads ~100 plugins and restarts Jenkins; a clean install + # was observed taking ~9.5 min. start_period only suppresses failures, so a + # generous value costs nothing once Jenkins is actually ready. + start_period: 15m mc-workflow-manager: diff --git a/conf/docker/tool/init.groovy.d/basic-security.groovy b/conf/docker/tool/init.groovy.d/basic-security.groovy index 2c8560e..cb6523a 100644 --- a/conf/docker/tool/init.groovy.d/basic-security.groovy +++ b/conf/docker/tool/init.groovy.d/basic-security.groovy @@ -97,6 +97,37 @@ plugins.each { pluginName -> } } +// deploy() also queues each dependency as its own InstallationJob, and a failed +// download (e.g. "Connection reset" from the update site) does not throw -- it +// only leaves that job in Failure state. Without a retry the missing dependency +// (e.g. joda-time-api) makes dependents fail to load after restart, and Jenkins +// only converges after several restart cycles. +def failedInstalls = { + def latestJobs = [:] + uc.getJobs().findAll { it instanceof UpdateCenter.InstallationJob }.each { job -> + latestJobs[job.plugin.name] = job + } + latestJobs.findAll { name, job -> job.status instanceof UpdateCenter.DownloadJob.Failure }.keySet() +} + +def maxInstallRetries = 5 +for (int attempt = 1; attempt <= maxInstallRetries; attempt++) { + def failed = failedInstalls() + if (failed.isEmpty()) { + break + } + println "--> Retrying failed plugin downloads (${attempt}/${maxInstallRetries}): ${failed.join(', ')}" + sleep(5000L * attempt) + failed.each { pluginName -> + uc.getPlugin(pluginName)?.deploy()?.get() + } +} + +def stillFailed = failedInstalls() +if (!stillFailed.isEmpty()) { + throw new IllegalStateException("Jenkins plugin download failed after ${maxInstallRetries} retries: ${stillFailed.join(', ')}") +} + println "--> Saving Jenkins state..." instance.save() From 6f3f9bdfa34424be0e41061c719af3624f1b5f35 Mon Sep 17 00:00:00 2001 From: yh-noh Date: Thu, 1 Oct 2026 13:17:13 +0900 Subject: [PATCH 3/4] =?UTF-8?q?fix(env):=20AWS=5FIDENTITY=5FROLE=5FARN=20?= =?UTF-8?q?=EA=B3=84=EC=A0=95=20=EC=9E=90=EB=A6=AC=EC=97=90=20AWS=5FACCOUN?= =?UTF-8?q?T=5FID=20=EC=82=AC=EC=9A=A9?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - 루트 .env.setup의 MC_IAM_MANAGER_AWS_IDENTITY_ROLE_ARN이 계정 ID 자리에 MC_IAM_MANAGER_KEYCLOAK_DOMAIN을 참조하던 오류 수정 - mc-iam-manager/.env.setup과 동일하게 MC_IAM_MANAGER_AWS_ACCOUNT_ID 사용 --- conf/docker/.env.setup | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/conf/docker/.env.setup b/conf/docker/.env.setup index 9166e21..434c5b3 100644 --- a/conf/docker/.env.setup +++ b/conf/docker/.env.setup @@ -159,7 +159,7 @@ MC_IAM_MANAGER_DEFAULT_WORKSPACE_NAME=ws01 MC_IAM_MANAGER_AWS_STS_ENDPOINT=https://sts.amazonaws.com MC_IAM_MANAGER_AWS_ACCOUNT_ID=notyet MC_IAM_MANAGER_AWS_IDENTITY_PROVIDER_ARN=arn:aws:iam::${MC_IAM_MANAGER_AWS_ACCOUNT_ID}:oidc-provider/${MC_IAM_MANAGER_KEYCLOAK_DOMAIN}/realms/${MC_IAM_MANAGER_KEYCLOAK_OIDC_CLIENT_NAME} -MC_IAM_MANAGER_AWS_IDENTITY_ROLE_ARN=arn:aws:iam::${MC_IAM_MANAGER_KEYCLOAK_DOMAIN}:role/mciam-platformadmin +MC_IAM_MANAGER_AWS_IDENTITY_ROLE_ARN=arn:aws:iam::${MC_IAM_MANAGER_AWS_ACCOUNT_ID}:role/mciam-platformadmin MC_IAM_MANAGER_CSP_ROLE_PREFIX=mciam From 740e0abaff5575763c56411e033a65947f2005a9 Mon Sep 17 00:00:00 2001 From: yh-noh Date: Tue, 6 Oct 2026 11:25:40 +0900 Subject: [PATCH 4/4] =?UTF-8?q?chore:=20mc-iam-manager=200.6.4,=20mc-web-c?= =?UTF-8?q?onsole=200.6.6=20=EC=9D=B4=EB=AF=B8=EC=A7=80=C2=B7=EB=B2=84?= =?UTF-8?q?=EC=A0=84=EC=9C=BC=EB=A1=9C=20=EA=B3=A0=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - docker-compose.yaml / docker-compose.mini.yaml: mc-iam-manager 0.6.3 → 0.6.4, mc-web-console-api·front 0.6.5 → 0.6.6 - docker-compose.mini.yaml의 web 이미지를 개인 레지스트리 csescsta/*:edge에서 릴리즈 태그 cloudbaristaorg/*:0.6.6으로 통일 - web 컨테이너에 마운트되는 conf/mc-web-console/api/conf/api.yaml과 conf/api.yaml, conf/docker/api.yaml의 mc-iam-manager·mc-web-console version을 0.6.4·0.6.6으로 갱신 --- conf/api.yaml | 4 ++-- conf/docker/api.yaml | 4 ++-- conf/docker/conf/mc-web-console/api/conf/api.yaml | 4 ++-- conf/docker/docker-compose.mini.yaml | 6 +++--- conf/docker/docker-compose.yaml | 6 +++--- 5 files changed, 12 insertions(+), 12 deletions(-) diff --git a/conf/api.yaml b/conf/api.yaml index db48e4a..109a0d4 100644 --- a/conf/api.yaml +++ b/conf/api.yaml @@ -11,7 +11,7 @@ services: password: mc-iam-manager: - version: 0.5.2 + version: 0.6.4 baseurl: http://mc-iam-manager:5000 auth: type: bearer @@ -25,7 +25,7 @@ services: password: spider mc-web-console: - version: 0.5.2 + version: 0.6.6 baseurl: http://mc-web-console:3000 auth: type: bearer diff --git a/conf/docker/api.yaml b/conf/docker/api.yaml index db48e4a..109a0d4 100644 --- a/conf/docker/api.yaml +++ b/conf/docker/api.yaml @@ -11,7 +11,7 @@ services: password: mc-iam-manager: - version: 0.5.2 + version: 0.6.4 baseurl: http://mc-iam-manager:5000 auth: type: bearer @@ -25,7 +25,7 @@ services: password: spider mc-web-console: - version: 0.5.2 + version: 0.6.6 baseurl: http://mc-web-console:3000 auth: type: bearer diff --git a/conf/docker/conf/mc-web-console/api/conf/api.yaml b/conf/docker/conf/mc-web-console/api/conf/api.yaml index 853a4b0..e557d94 100644 --- a/conf/docker/conf/mc-web-console/api/conf/api.yaml +++ b/conf/docker/conf/mc-web-console/api/conf/api.yaml @@ -11,7 +11,7 @@ services: password: mc-iam-manager: - version: 0.5.1 + version: 0.6.4 baseurl: http://mc-iam-manager:5000 auth: type: bearer @@ -25,7 +25,7 @@ services: password: default mc-web-console: - version: 0.5.2 + version: 0.6.6 baseurl: http://mc-web-console-api:3000 auth: type: bearer diff --git a/conf/docker/docker-compose.mini.yaml b/conf/docker/docker-compose.mini.yaml index b7cba4f..70e7947 100644 --- a/conf/docker/docker-compose.mini.yaml +++ b/conf/docker/docker-compose.mini.yaml @@ -219,7 +219,7 @@ services: mc-iam-manager: container_name: mc-iam-manager - image: cloudbaristaorg/mc-iam-manager:0.6.3 + image: cloudbaristaorg/mc-iam-manager:0.6.4 restart: unless-stopped networks: - mc-iam-manager-network @@ -387,7 +387,7 @@ services: exec docker-entrypoint.sh postgres" mc-web-console-api: - image: csescsta/mc-web-console-api:edge + image: cloudbaristaorg/mc-web-console-api:0.6.6 pull_policy: always container_name: mc-web-console-api platform: linux/amd64 @@ -436,7 +436,7 @@ services: <<: *default-health-check mc-web-console-front: - image: csescsta/mc-web-console-front:edge + image: cloudbaristaorg/mc-web-console-front:0.6.6 pull_policy: always container_name: mc-web-console-front platform: linux/amd64 diff --git a/conf/docker/docker-compose.yaml b/conf/docker/docker-compose.yaml index a898ece..3c1a2e2 100644 --- a/conf/docker/docker-compose.yaml +++ b/conf/docker/docker-compose.yaml @@ -277,7 +277,7 @@ services: mc-iam-manager: container_name: mc-iam-manager - image: cloudbaristaorg/mc-iam-manager:0.6.3 + image: cloudbaristaorg/mc-iam-manager:0.6.4 restart: unless-stopped networks: - mc-iam-manager-network @@ -1176,7 +1176,7 @@ services: exec docker-entrypoint.sh postgres" mc-web-console-api: - image: cloudbaristaorg/mc-web-console-api:0.6.5 + image: cloudbaristaorg/mc-web-console-api:0.6.6 pull_policy: always container_name: mc-web-console-api platform: linux/amd64 @@ -1220,7 +1220,7 @@ services: <<: *default-health-check mc-web-console-front: - image: cloudbaristaorg/mc-web-console-front:0.6.5 + image: cloudbaristaorg/mc-web-console-front:0.6.6 pull_policy: always container_name: mc-web-console-front platform: linux/amd64