Files
cloud-host/scripts/trigger-platform-build.sh
T
keyhan 58ab81469b
Build and Deploy Platform / build-and-deploy (push) Failing after 3m18s
Stabilize CI Kaniko tag and keep Harbor free of egress proxy.
Use the seeded kaniko v1.27.6-debug image, retry npm ci, and push via harbor-core without HTTP_PROXY so Harbor UI metadata and blob uploads keep working.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-17 16:47:23 +03:30

90 lines
3.3 KiB
Bash
Executable File

#!/usr/bin/env bash
# Trigger in-cluster Kaniko build → Harbor. No local docker build/push.
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
NAMESPACE="${BUILD_NAMESPACE:-cloudhost-builds}"
JOB_NAME="${JOB_NAME:-build-platform-images}"
GIT_REPO="${GIT_REPO:-http://gitea-http.gitea.svc.cluster.local:3000/abrban/cloud-host.git}"
GIT_REF="${GIT_REF:-main}"
IMAGE_TAG="${IMAGE_TAG:-$(date +%Y%m%d-%H%M)}"
echo "==> Applying Kaniko build job (tag=${IMAGE_TAG}, ref=${GIT_REF})"
kubectl -n "${NAMESPACE}" delete job "${JOB_NAME}" --ignore-not-found
kubectl apply -f - <<EOF
apiVersion: batch/v1
kind: Job
metadata:
name: ${JOB_NAME}
namespace: ${NAMESPACE}
spec:
ttlSecondsAfterFinished: 3600
backoffLimit: 1
template:
spec:
restartPolicy: Never
imagePullSecrets:
- name: registry-pull-secret
initContainers:
- name: git-clone
image: registry.abrban.com/proxy-dockerhub/alpine/git:2.43.0
command:
- sh
- -ec
- |
git clone --depth=1 --branch "${GIT_REF}" "${GIT_REPO}" /workspace
ls -la /workspace
volumeMounts:
- name: workspace
mountPath: /workspace
containers:
- name: kaniko
image: registry.abrban.com/abrban/kaniko-executor:v1.27.6-debug
command:
- sh
- -ec
- |
set -eux
# Push via harbor-core so artifacts appear in Harbor UI
REG="harbor-core.cloudhost.svc.cluster.local/abrban"
unset HTTP_PROXY HTTPS_PROXY http_proxy https_proxy || true
export NO_PROXY="harbor-core.cloudhost.svc.cluster.local,harbor-registry.cloudhost.svc.cluster.local,registry.abrban.com,10.43.0.0/16,.svc,.cluster.local"
export no_proxy="$NO_PROXY"
/kaniko/executor \
--dockerfile=/workspace/backend/Dockerfile \
--context=dir:///workspace/backend \
--destination="${REG}/cloudhost-backend:${IMAGE_TAG}" \
--insecure --skip-tls-verify
/kaniko/executor \
--dockerfile=/workspace/frontend/Dockerfile \
--context=dir:///workspace/frontend \
--build-arg=NEXT_PUBLIC_API_URL=https://api.abrban.com \
--destination="${REG}/cloudhost-frontend:${IMAGE_TAG}" \
--insecure --skip-tls-verify
echo "BUILT_TAG=${IMAGE_TAG}"
volumeMounts:
- name: workspace
mountPath: /workspace
- name: docker-config
mountPath: /kaniko/.docker
volumes:
- name: workspace
emptyDir: {}
- name: docker-config
secret:
secretName: kaniko-harbor-auth
items:
- key: .dockerconfigjson
path: config.json
EOF
echo "==> Waiting for build job..."
kubectl -n "${NAMESPACE}" wait --for=condition=complete "job/${JOB_NAME}" --timeout=45m
echo "==> Build complete (tag=${IMAGE_TAG})."
echo "To deploy via GitOps, commit the tag in the cloud-host-gitops repo:"
echo " platform/values-abrban.yaml → images.backend.tag / images.frontend.tag = \"${IMAGE_TAG}\""
echo "Or for a direct Helm deploy (bootstrap only):"
echo " TAG=${IMAGE_TAG} ./scripts/gitops-deploy.sh"