consists of ~80 separate github repositories • Built on top of a Web Application Stack (PHP, Apache, Javascript, CSS, HTML) • Over 14000 unit tests and 2200 acceptance ( ui/ api ) tests • Pull request for “core” run 15 hours of test time ( Feedback < 30 mins ) • Every night we run over 180 hours of tests • Various infrastructure components – Relational database (MySQL, MariaDB, PostgreSQL, OracleDB) – Memory Cache (Memcached, Redis) – Storage Providers (FileSystem, NFS, SMB, Swift, S3, OneDrive, Dropbox, etc.) – Identity / Authentication Providers (LDAP, Active Directory, Shibboleth / SAML) – Other Infrastructure Components (ClamAV, Elasticsearch, Collabora, etc.)
locally, e.g. “works for me ™” • Test suites encountered regular timeouts • Feedback / Results of test runs sometimes only after days • No real plugin system, not extensible • Travis wasn‘t able to provide extended build power on our open-source repositories (only possible on private repositories)* *) changed in Summer 2018
to date – Plugin updates result in changes to config format – Only managed via web UI • Secrets are managed via web UI or hacky API scripts • Frequently ran out of disk space • Wasn‘t cleaning up containers properly • Containers (services) required a lot of bash magic • Test results took hours to complete – very slow Feedback cycle • Static number of executors
& drone-agents via ansible • Provide Docker containers for infrastructure components (PHP / databases / storages) • Gradual migration of “owncloud/core” from Jenkins / Travis to Drone – Basic linting and unit testing – Gradually migrated integration / acceptance tests and UI tests • Expand drone to app repositories – Required “plugin” to install and configure ownCloud => https://github.com/owncloud-ci – Built further custom plugins, e.g. recorder
• Too many systems to maintain • Secrets management • Frequently ran out of disk space • Static number of executors / timeouts • Containers required a lot of bash magic • CI environment not reproducible locally • No plugin system / limited extensibility Need to maintain 3 systems: Jenkins, Drone, Travis Drone provided us with API & UI Docker isn’t great at cleaning up after itself No time restriction, but amount of parallel jobs limited Container native Containers & drone exec Any container can be a plugin
entirely • Scaling Drone agents on demand • Number of test suites still increasing • Entirely version controlled and easily manageable infrastructure – Terraform – Ansible – Hetzner Cloud – Autoscaler Final infrastructure
Providers ( AWS, Azure, Packet. Openstack, hetznercloud …) • Simple service connected to drone server • Hooked into Drone CLI, e.g. “drone server create” • Checks the Drone queue in a loop • Launch servers based on a cloud-init config • Start Drone agent via remote Docker connection (secured by TLS) • Unregister Drone agent if not needed anymore • Destroy server instance after a minimal amount of time Welcome to “Autoscaler”
scheduling in yaml configuration • Split feedback on pull requests per test suite • Archiving build data – we got lots of build logs • Downstream cross repository checks • Upstream cross repository checks • Ability to restart one branch of a fan-in/fan-out scenario • Triggers – Invoke builds from different sources – Split pipelines into different configurations What else is missing?
a tool to your company, doesn’t guarantee success – Promote the tool in your team / get the team onboard – Gradual adoption helped to gain traction within teams • Everything works great, until you move to production – Load can will kill your application at some point … and also your CI system... • Smaller Infrastructure components vs. Monolithic Infrastructure – Docker default network limitations – General resource limits, e.g. Disks, IOPS, CPU, Memory • Technical fallacies – Everything that can be unreachable, will be unreachable ( this is also true for your SaaS repository provider) – Database compression is really not a good idea for write heavy loads Lessons Learned