• Jenkins • Bamboo • GitlabCI • Concourse CI • Rationale • Architecture • Yandex Cloud to the rescue • Quick start • How to speed-up almost any CI • Modern CI Rationale • CI with MSA • Metadata first approach • How to build products with MSA with infinite teams and so on
• Easy to make mess in Jenkins, yet works • High availability? Master-Slave/Master-Master? • Think I’m wrong? Imaging managing 50 instances of Jenkins simultaneously? How about 500? 5000?
проектик, надо ребятам сделать быстрее CI/CD(?) • ME: Окай, давайте там посмотрим, что там и как, прежде чем • MGMT: Не нас не пустят на нормальный аудит, там всё “нормас”, Jenkins, ты же знаешь Jenkins? Ну вот, “давай давай делай” • ME:…
надо ребятам сделать быстрее CI/CD(?) • Окай, давайте там посмотрим, что там и как, прежде чем • Не нас не пустят на нормальный аудит, там всё “нормас”, Jenkins, ты же знаешь Jenkins? Ну вот, “давай давай делай” • …
8 мегабайтный bat файл • Который работает 5 дней • А потом может быть у тебя получится какой-то результат • Но обычно нет, поэтому нас и позвали, потому что последние 180+ дней не было удачных билдов
“батничка”, около 150 тасочек, все на груви, добавляются в Jenkins через API, запускаются параллельно на всех воркерах что можем использовать • Теперь это 7 часов а не 5 дней, ура?
“батничка”, около 150 тасочек, все на груви, добавляются в Jenkins через API, запускаются параллельно на всех воркерах что можем использовать • Теперь это 7 часов а не 5 дней, ура? • Ускорить больше не можем
версии Jenkins не добавляют функционал(обычно) • Но из-за того что вы обновились, некоторые плагины перестали работать так как работали на версии ранее • Пришёл из отпуска, весь Дженкинс в баше, в эти текстовые амбразуры понапихали всяких кастомов • Через месяц никто не знает как это работает • Не доверяем тулу, которым пользуемся
done by any shortcut and not through pipeline as code, some from your team will go for it eventually. And you can’t trace it(kinda), and can’t forbid(sorta), and can’t update(sometimes).
~10 Deploy projects to multiple variables • Unable to upgrade at all pipelines something inside • We have some scripts to patch database on fly • Barely solves problem, due to stateful workers
model based on agents, not on working users • Beta-like PaC, fails a lot, you either need to learn Java, because yaml definitions aren’t covered in docs any good, and Java is more powerful • Doesn’t share bitbucket pipelines syntax(YARLY!)
and deploy process, stored and versioned in Git • Code review • Able to template builds(team A, Appname, git, docker repo) • Able to parametrise builds(deploy to (dev, preprod, prod) • Same process for everyone, because same reusable parts used • DRY? SOLID? KISS? YAGNI? • Be simple/Flat learning curve • API First • Maybe nice GUI? • But restrict user to not change anything via GUI? • Auto register build agents • Build should be repeatable • Consistency through stateless, container-based builds • Integrate with external systems without plug-in hell • Able to extend with minimum efforts • Minimising efforts to maintain CI/CD (no more Jenkins Janitors) • OpenSource • Not Cryptic code from 1999, be able to contribute
NINJAS in • All in one • Yet all tools are at-least “meh” state • Cannot be split off your repository • Building with triggers on external repos like github/bitbucket — known trickstery • Intermediate artifacts have to be defined and uploaded/downloaded for every job • Gitlab GOLD $99 per one user • Yeah that one witch have K8s support • At scale of 15k developers its $1 500 000
• All in one • Yet all tools are atleast “meh” state • Non reproducible builds • Cannot be split off your repository • Building with triggers on external repos like github/bitbucket — known trickstery • Intermediate artifacts have to be defined and uploaded/downloaded for every job • Gitlab GOLD $99 per one user • Yeah that one witch have K8s support • At scale of 15k developerrs its $1 500 000
integration with, SELF • Pipeline as Code • Yet unable to take care of external repos • You can, but this is bash-snippet hell • But there gitlab have snippets for that
integration with, SELF • Pipeline as Code • Yet unable to take care of external repos • You can, but this is bash-snippet hell • But there gitlab have snippets for that
and deploy process, stored and versioned in Git • Code review • Able to template builds(team A, Appname, git, docker repo) • Able to parametrise builds(deploy to (dev, preprod, prod) • Same process for everyone, because same reusable parts used • DRY? SOLID? KISS? YAGNI? • Be simple/Flat learning curve • API First • Maybe nice GUI? • But restrict user to not change anything via GUI? • Auto register build agents • Build should be repeatable • Consistency through stateless, container-based builds • Integrate with external systems without plug-in hell • Able to extend with minimum efforts • Minimising efforts to maintain CI/CD (no more Jenkins Janitors) • OpenSource • Not Cryptic code from 1999, be able to contribute
Forward-worker used to reverse-tunnel a worker's addresses through the TSA and register the forwarded connections with the ATC. This allows workers running in arbitrary networks to register securely, so long as they can reach the TSA. This is much safer than opening the worker up to the outside world.
, igi / a e , igi /HEAD) 10161a6ef3b1cfef89b61e94f048863b46b29b0b af791274aef9dc9afacf7fc759cd0f444999d5ea a e Ma e b a ch deadbeefdeadbeefdeadbeefdeadbeefdeadbeef e67f848abc35c5cf11861cf8be3b2c0c12ceace4 Microservices Development: Commit stages
, igi / a e , igi /HEAD) 10161a6ef3b1cfef89b61e94f048863b46b29b0b af791274aef9dc9afacf7fc759cd0f444999d5ea a e Ma e b a ch deadbeefdeadbeefdeadbeefdeadbeefdeadbeef e67f848abc35c5cf11861cf8be3b2c0c12ceace4 Microservices Development: Commit stages
, igi / a e , igi /HEAD) 10161a6ef3b1cfef89b61e94f048863b46b29b0b af791274aef9dc9afacf7fc759cd0f444999d5ea a e Ma e b a ch deadbeefdeadbeefdeadbeefdeadbeefdeadbeef e67f848abc35c5cf11861cf8be3b2c0c12ceace4 Microservices Development: Commit stages
Ma e b a ch deadbeefdeadbeefdeadbeefdeadbeefdeadbeef d5c0829d613ef45dab1846e4e1a259908ee269fd (HEAD -> a e , igi / a e , igi /HEAD) e67f848abc35c5cf11861cf8be3b2c0c12ceace4 Microservices Development: Commit stages
Ma e b a ch deadbeefdeadbeefdeadbeefdeadbeefdeadbeef d5c0829d613ef45dab1846e4e1a259908ee269fd (HEAD -> a e , igi / a e , igi /HEAD) e67f848abc35c5cf11861cf8be3b2c0c12ceace4 Microservices Development: Commit stages • We checking any our commit against other stable versions
tests • Build • SonarQube Stage • Sonar code check • Code Smells • Potential bugs • Unit test run time (Y U COMMIT SKIP TESTS?) • Skip unit tests • Unit test failures • Maintainability of new code lower than B • Tech debt of new code • Security rating on new code • Uncovered conditions on new code • Code coverage • Security • Aquasecurity/Microscanner • Aquasecurity/Trivy(after push to Artifactory actually)
tests • Build • SonarQube Stage • Code Smells • Potential bugs • Unit test run time (The junior cut off all unit tests?) • Skip unit tests • Unit test failures • Maintainability of new code lower than B • Tech debt of new code • Security rating on new code • Uncovered conditions on new code • Code coverage • Security • Aquasecurity/Microscanner • Aquasecurity/Trivy(after push to Artifactory actually) • Run integration tests on mockups • Spin DB • Spin nearest services(testcontainers) • Push image to artifactory • Prepare Kubernetes Environment
NS, push secrets to pull images, configure all the things: • Create svc, ingress • Create network policies, pod disruption budget, limits, qos/priority • Deploy everything • Deploy in team-appname-sha1commit-sidecar-ns tools to run • Starts from API tests • Ends with Selenium, running under Aerokube
NS, push secrets to pull images, configure all the things: • Create svc, ingress • Create network policies, pod disruption budget, limits, qos/priority • Deploy everything • Deploy in team-appname-sha1commit-sidecar-ns tools to run • Starts from API tests • Ends with Selenium, running under Aerokube
almost 0 cost • Integration tests running on nearest services with testcontainers • e2e tests, runs from sidecar-NS • Starts from API tests • Ends with Selenium, running under Aerokube