[release-10.4.19] CI: Use docker creds from ci/common (#104875)

* CI: Use docker creds from ci/common (#104827)

Use docker creds from ci/common

(cherry picked from commit fd4afdbd2c)

* CI: move `grafana-delivery-bot` path in Drone (#104886)

* move delivery bot creds to vault

* format-drone

(cherry picked from commit ec35e861e0)
pull/104939/head^2
Kevin Minehart 2 months ago committed by GitHub
parent 56894bf6a1
commit a359ffa756
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
  1. 46
      .drone.yml
  2. 8
      scripts/drone/steps/lib.star
  3. 19
      scripts/drone/vault.star

@ -836,10 +836,8 @@ steps:
from_secret: docker_password from_secret: docker_password
DOCKER_USER: DOCKER_USER:
from_secret: docker_username from_secret: docker_username
GITHUB_APP_ID: GITHUB_APP_ID: "329617"
from_secret: delivery-bot-app-id GITHUB_APP_INSTALLATION_ID: "37346161"
GITHUB_APP_INSTALLATION_ID:
from_secret: delivery-bot-app-installation-id
GITHUB_APP_PRIVATE_KEY: GITHUB_APP_PRIVATE_KEY:
from_secret: delivery-bot-app-private-key from_secret: delivery-bot-app-private-key
failure: ignore failure: ignore
@ -2221,10 +2219,8 @@ steps:
from_secret: docker_username from_secret: docker_username
GCP_KEY: GCP_KEY:
from_secret: gcp_grafanauploads from_secret: gcp_grafanauploads
GITHUB_APP_ID: GITHUB_APP_ID: "329617"
from_secret: delivery-bot-app-id GITHUB_APP_INSTALLATION_ID: "37346161"
GITHUB_APP_INSTALLATION_ID:
from_secret: delivery-bot-app-installation-id
GITHUB_APP_PRIVATE_KEY: GITHUB_APP_PRIVATE_KEY:
from_secret: delivery-bot-app-private-key from_secret: delivery-bot-app-private-key
image: google/cloud-sdk:431.0.0 image: google/cloud-sdk:431.0.0
@ -2246,10 +2242,8 @@ steps:
from_secret: docker_username from_secret: docker_username
GCP_KEY: GCP_KEY:
from_secret: gcp_grafanauploads from_secret: gcp_grafanauploads
GITHUB_APP_ID: GITHUB_APP_ID: "329617"
from_secret: delivery-bot-app-id GITHUB_APP_INSTALLATION_ID: "37346161"
GITHUB_APP_INSTALLATION_ID:
from_secret: delivery-bot-app-installation-id
GITHUB_APP_PRIVATE_KEY: GITHUB_APP_PRIVATE_KEY:
from_secret: delivery-bot-app-private-key from_secret: delivery-bot-app-private-key
image: google/cloud-sdk:431.0.0 image: google/cloud-sdk:431.0.0
@ -2767,10 +2761,8 @@ steps:
from_secret: docker_username from_secret: docker_username
GCP_KEY: GCP_KEY:
from_secret: gcp_grafanauploads from_secret: gcp_grafanauploads
GITHUB_APP_ID: GITHUB_APP_ID: "329617"
from_secret: delivery-bot-app-id GITHUB_APP_INSTALLATION_ID: "37346161"
GITHUB_APP_INSTALLATION_ID:
from_secret: delivery-bot-app-installation-id
GITHUB_APP_PRIVATE_KEY: GITHUB_APP_PRIVATE_KEY:
from_secret: delivery-bot-app-private-key from_secret: delivery-bot-app-private-key
image: google/cloud-sdk:431.0.0 image: google/cloud-sdk:431.0.0
@ -4707,13 +4699,13 @@ name: prerelease_bucket
--- ---
get: get:
name: username name: username
path: infra/data/ci/grafanaci-docker-hub path: ci/data/common/dockerhub
kind: secret kind: secret
name: docker_username name: docker_username
--- ---
get: get:
name: password name: password
path: infra/data/ci/grafanaci-docker-hub path: ci/data/common/dockerhub
kind: secret kind: secret
name: docker_password name: docker_password
--- ---
@ -4832,20 +4824,8 @@ kind: secret
name: dagger_token name: dagger_token
--- ---
get: get:
name: app-id name: PRIVATE_KEY
path: infra/data/ci/grafana-release-eng/grafana-delivery-bot path: ci/data/repo/grafana/grafana/delivery-bot-app
kind: secret
name: delivery-bot-app-id
---
get:
name: app-installation-id
path: infra/data/ci/grafana-release-eng/grafana-delivery-bot
kind: secret
name: delivery-bot-app-installation-id
---
get:
name: app-private-key
path: infra/data/ci/grafana-release-eng/grafana-delivery-bot
kind: secret kind: secret
name: delivery-bot-app-private-key name: delivery-bot-app-private-key
--- ---
@ -4856,6 +4836,6 @@ kind: secret
name: gcr_credentials name: gcr_credentials
--- ---
kind: signature kind: signature
hmac: 5d5a9e9eeedbe77b1f14d6f661dc2724270a8fb28f142f10a47bd556e0b39a14 hmac: 77cf486cba59cee56db9edbbfeee4997cd22bc9060dd854639e2ae44822dc080
... ...

@ -895,8 +895,8 @@ def publish_images_step(ver_mode, docker_repo, trigger = None):
"GCP_KEY": from_secret(gcp_grafanauploads), "GCP_KEY": from_secret(gcp_grafanauploads),
"DOCKER_USER": from_secret("docker_username"), "DOCKER_USER": from_secret("docker_username"),
"DOCKER_PASSWORD": from_secret("docker_password"), "DOCKER_PASSWORD": from_secret("docker_password"),
"GITHUB_APP_ID": from_secret("delivery-bot-app-id"), "GITHUB_APP_ID": "329617",
"GITHUB_APP_INSTALLATION_ID": from_secret("delivery-bot-app-installation-id"), "GITHUB_APP_INSTALLATION_ID": "37346161",
"GITHUB_APP_PRIVATE_KEY": from_secret("delivery-bot-app-private-key"), "GITHUB_APP_PRIVATE_KEY": from_secret("delivery-bot-app-private-key"),
} }
@ -913,8 +913,8 @@ def publish_images_step(ver_mode, docker_repo, trigger = None):
environment = { environment = {
"DOCKER_USER": from_secret("docker_username"), "DOCKER_USER": from_secret("docker_username"),
"DOCKER_PASSWORD": from_secret("docker_password"), "DOCKER_PASSWORD": from_secret("docker_password"),
"GITHUB_APP_ID": from_secret("delivery-bot-app-id"), "GITHUB_APP_ID": "329617",
"GITHUB_APP_INSTALLATION_ID": from_secret("delivery-bot-app-installation-id"), "GITHUB_APP_INSTALLATION_ID": "37346161",
"GITHUB_APP_PRIVATE_KEY": from_secret("delivery-bot-app-private-key"), "GITHUB_APP_PRIVATE_KEY": from_secret("delivery-bot-app-private-key"),
} }

@ -55,8 +55,8 @@ def secrets():
vault_secret(gar_pull_secret, "secret/data/common/gar", ".dockerconfigjson"), vault_secret(gar_pull_secret, "secret/data/common/gar", ".dockerconfigjson"),
vault_secret(drone_token, "infra/data/ci/drone", "machine-user-token"), vault_secret(drone_token, "infra/data/ci/drone", "machine-user-token"),
vault_secret(prerelease_bucket, "infra/data/ci/grafana/prerelease", "bucket"), vault_secret(prerelease_bucket, "infra/data/ci/grafana/prerelease", "bucket"),
vault_secret(docker_username, "infra/data/ci/grafanaci-docker-hub", "username"), vault_secret(docker_username, "ci/data/common/dockerhub", "username"),
vault_secret(docker_password, "infra/data/ci/grafanaci-docker-hub", "password"), vault_secret(docker_password, "ci/data/common/dockerhub", "password"),
vault_secret( vault_secret(
gcp_upload_artifacts_key, gcp_upload_artifacts_key,
"infra/data/ci/grafana/releng/artifacts-uploader-service-account", "infra/data/ci/grafana/releng/artifacts-uploader-service-account",
@ -153,21 +153,10 @@ def secrets():
"infra/data/ci/grafana-release-eng/rgm", "infra/data/ci/grafana-release-eng/rgm",
"dagger_token", "dagger_token",
), ),
# grafana-delivery-bot secrets
vault_secret(
"delivery-bot-app-id",
"infra/data/ci/grafana-release-eng/grafana-delivery-bot",
"app-id",
),
vault_secret(
"delivery-bot-app-installation-id",
"infra/data/ci/grafana-release-eng/grafana-delivery-bot",
"app-installation-id",
),
vault_secret( vault_secret(
"delivery-bot-app-private-key", "delivery-bot-app-private-key",
"infra/data/ci/grafana-release-eng/grafana-delivery-bot", "ci/data/repo/grafana/grafana/delivery-bot-app",
"app-private-key", "PRIVATE_KEY",
), ),
vault_secret( vault_secret(
"gcr_credentials", "gcr_credentials",

Loading…
Cancel
Save