Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 37 additions & 25 deletions bin/installAll.sh
Original file line number Diff line number Diff line change
Expand Up @@ -168,6 +168,35 @@ STARTUP_WAVES=(
"mc-application-manager mc-workflow-manager mc-cost-optimizer-fe"
)

# Starts every wave detached (-d), then one final full-stack `run -d` for the
# services no wave entry point reaches (cost-optimizer collectors/rightsizers,
# cb-mapui, ...). Waves must always be detached: an attached `compose up` never
# returns, so later waves would never start.
run_startup_waves() {
local wave_num=0
local run_exit
for wave_services in "${STARTUP_WAVES[@]}"; do
wave_num=$((wave_num + 1))
echo ""
echo "---- Wave $wave_num/${#STARTUP_WAVES[@]}: $wave_services ----"
./mcc infra run -d -s "$wave_services"
run_exit=$?
if [ $run_exit -ne 0 ]; then
report_run_failure "$run_exit" "Wave $wave_num ($wave_services)"
exit 1
fi
done

echo ""
echo "---- Remaining services (not reached by any wave) ----"
./mcc infra run -d
run_exit=$?
if [ $run_exit -ne 0 ]; then
report_run_failure "$run_exit" "remaining services"
exit 1
fi
}

# Prints a consistent failure banner for a failed `./mcc infra run` invocation.
report_run_failure() {
local exit_code="$1"
Expand Down Expand Up @@ -543,20 +572,14 @@ case $RUN_MODE in
exit 1
fi

wave_num=0
for wave_services in "${STARTUP_WAVES[@]}"; do
wave_num=$((wave_num + 1))
echo ""
echo "---- Wave $wave_num/${#STARTUP_WAVES[@]}: $wave_services ----"
./mcc infra run -s "$wave_services"
run_exit=$?
if [ $run_exit -ne 0 ]; then
report_run_failure "$run_exit" "Wave $wave_num ($wave_services)"
exit 1
fi
done

run_startup_waves
check_post_initial

# Attach to the whole stack only after every wave is up (Ctrl+C to detach;
# containers keep running)
echo ""
echo "All services started. Attaching to logs (Ctrl+C to stop following)..."
./mcc infra run
;;
background)
echo ""
Expand All @@ -579,18 +602,7 @@ case $RUN_MODE in
echo "Image download and initial setup in progress..."
echo ""

wave_num=0
for wave_services in "${STARTUP_WAVES[@]}"; do
wave_num=$((wave_num + 1))
echo ""
echo "---- Wave $wave_num/${#STARTUP_WAVES[@]}: $wave_services ----"
./mcc infra run -d -s "$wave_services"
run_exit=$?
if [ $run_exit -ne 0 ]; then
report_run_failure "$run_exit" "Wave $wave_num ($wave_services)"
exit 1
fi
done
run_startup_waves

echo ""
echo "Image download and initial setup completed."
Expand Down
4 changes: 2 additions & 2 deletions conf/api.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ services:
password:

mc-iam-manager:
version: 0.5.2
version: 0.6.4
baseurl: http://mc-iam-manager:5000
auth:
type: bearer
Expand All @@ -25,7 +25,7 @@ services:
password: spider

mc-web-console:
version: 0.5.2
version: 0.6.6
baseurl: http://mc-web-console:3000
auth:
type: bearer
Expand Down
2 changes: 1 addition & 1 deletion conf/docker/.env.setup
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,7 @@ MC_IAM_MANAGER_DEFAULT_WORKSPACE_NAME=ws01
MC_IAM_MANAGER_AWS_STS_ENDPOINT=https://sts.amazonaws.com
MC_IAM_MANAGER_AWS_ACCOUNT_ID=notyet
MC_IAM_MANAGER_AWS_IDENTITY_PROVIDER_ARN=arn:aws:iam::${MC_IAM_MANAGER_AWS_ACCOUNT_ID}:oidc-provider/${MC_IAM_MANAGER_KEYCLOAK_DOMAIN}/realms/${MC_IAM_MANAGER_KEYCLOAK_OIDC_CLIENT_NAME}
MC_IAM_MANAGER_AWS_IDENTITY_ROLE_ARN=arn:aws:iam::${MC_IAM_MANAGER_KEYCLOAK_DOMAIN}:role/mciam-platformadmin
MC_IAM_MANAGER_AWS_IDENTITY_ROLE_ARN=arn:aws:iam::${MC_IAM_MANAGER_AWS_ACCOUNT_ID}:role/mciam-platformadmin


MC_IAM_MANAGER_CSP_ROLE_PREFIX=mciam
Expand Down
4 changes: 2 additions & 2 deletions conf/docker/api.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ services:
password:

mc-iam-manager:
version: 0.5.2
version: 0.6.4
baseurl: http://mc-iam-manager:5000
auth:
type: bearer
Expand All @@ -25,7 +25,7 @@ services:
password: spider

mc-web-console:
version: 0.5.2
version: 0.6.6
baseurl: http://mc-web-console:3000
auth:
type: bearer
Expand Down
4 changes: 2 additions & 2 deletions conf/docker/conf/mc-web-console/api/conf/api.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ services:
password:

mc-iam-manager:
version: 0.5.1
version: 0.6.4
baseurl: http://mc-iam-manager:5000
auth:
type: bearer
Expand All @@ -25,7 +25,7 @@ services:
password: default

mc-web-console:
version: 0.5.2
version: 0.6.6
baseurl: http://mc-web-console-api:3000
auth:
type: bearer
Expand Down
6 changes: 3 additions & 3 deletions conf/docker/docker-compose.mini.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -219,7 +219,7 @@ services:

mc-iam-manager:
container_name: mc-iam-manager
image: cloudbaristaorg/mc-iam-manager:0.6.3
image: cloudbaristaorg/mc-iam-manager:0.6.4
restart: unless-stopped
networks:
- mc-iam-manager-network
Expand Down Expand Up @@ -387,7 +387,7 @@ services:
exec docker-entrypoint.sh postgres"

mc-web-console-api:
image: csescsta/mc-web-console-api:edge
image: cloudbaristaorg/mc-web-console-api:0.6.6
pull_policy: always
container_name: mc-web-console-api
platform: linux/amd64
Expand Down Expand Up @@ -436,7 +436,7 @@ services:
<<: *default-health-check

mc-web-console-front:
image: csescsta/mc-web-console-front:edge
image: cloudbaristaorg/mc-web-console-front:0.6.6
pull_policy: always
container_name: mc-web-console-front
platform: linux/amd64
Expand Down
11 changes: 7 additions & 4 deletions conf/docker/docker-compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -277,7 +277,7 @@ services:

mc-iam-manager:
container_name: mc-iam-manager
image: cloudbaristaorg/mc-iam-manager:0.6.3
image: cloudbaristaorg/mc-iam-manager:0.6.4
restart: unless-stopped
networks:
- mc-iam-manager-network
Expand Down Expand Up @@ -1042,7 +1042,10 @@ services:
curl -fsS -u "$${JENKINS_USERNAME}:$${JENKINS_PASSWORD}"
http://localhost:8080/api/json > /dev/null
<<: *default-health-check
start_period: 6m
# First boot downloads ~100 plugins and restarts Jenkins; a clean install
# was observed taking ~9.5 min. start_period only suppresses failures, so a
# generous value costs nothing once Jenkins is actually ready.
start_period: 15m


mc-workflow-manager:
Expand Down Expand Up @@ -1176,7 +1179,7 @@ services:
exec docker-entrypoint.sh postgres"

mc-web-console-api:
image: cloudbaristaorg/mc-web-console-api:0.6.5
image: cloudbaristaorg/mc-web-console-api:0.6.6
pull_policy: always
container_name: mc-web-console-api
platform: linux/amd64
Expand Down Expand Up @@ -1220,7 +1223,7 @@ services:
<<: *default-health-check

mc-web-console-front:
image: cloudbaristaorg/mc-web-console-front:0.6.5
image: cloudbaristaorg/mc-web-console-front:0.6.6
pull_policy: always
container_name: mc-web-console-front
platform: linux/amd64
Expand Down
31 changes: 31 additions & 0 deletions conf/docker/tool/init.groovy.d/basic-security.groovy
Original file line number Diff line number Diff line change
Expand Up @@ -97,6 +97,37 @@ plugins.each { pluginName ->
}
}

// deploy() also queues each dependency as its own InstallationJob, and a failed
// download (e.g. "Connection reset" from the update site) does not throw -- it
// only leaves that job in Failure state. Without a retry the missing dependency
// (e.g. joda-time-api) makes dependents fail to load after restart, and Jenkins
// only converges after several restart cycles.
def failedInstalls = {
def latestJobs = [:]
uc.getJobs().findAll { it instanceof UpdateCenter.InstallationJob }.each { job ->
latestJobs[job.plugin.name] = job
}
latestJobs.findAll { name, job -> job.status instanceof UpdateCenter.DownloadJob.Failure }.keySet()
}

def maxInstallRetries = 5
for (int attempt = 1; attempt <= maxInstallRetries; attempt++) {
def failed = failedInstalls()
if (failed.isEmpty()) {
break
}
println "--> Retrying failed plugin downloads (${attempt}/${maxInstallRetries}): ${failed.join(', ')}"
sleep(5000L * attempt)
failed.each { pluginName ->
uc.getPlugin(pluginName)?.deploy()?.get()
}
}

def stillFailed = failedInstalls()
if (!stillFailed.isEmpty()) {
throw new IllegalStateException("Jenkins plugin download failed after ${maxInstallRetries} retries: ${stillFailed.join(', ')}")
}

println "--> Saving Jenkins state..."
instance.save()

Expand Down
Loading