jenkins CI/CD 配置文檔
1.全局工具配置
1.1 maven配置
默認(rèn) settings 提供
? 文件路徑:/usr/local/bin/apache-maven-3.3.9/conf/settings.xml
默認(rèn)全局 settings 提供
? 文件路徑 :/usr/local/bin/apache-maven-3.3.9/conf/settings.xml
1.2 jdk
別名:jdk8
JAVA_HOME :/usr/local/openjdk-8
1.3 git
Name :Default
Path to Git executable :/usr/bin/git
1.4 maven
name :maven
MAVEN_HOME : /usr/local/bin/apache-maven-3.3.9
2.下載kubernetes 插件
2.1 kubernetes plugin 安裝
首先進(jìn)入插件管理頁(yè)面【系統(tǒng)管理】->【管理插件】->【可選插件】剃氧,搜索kubernetes plugin,勾選要安裝的插件辐棒,然后點(diǎn)擊【直接安裝】落恼。
2.2 配置kubernetes
單擊【系統(tǒng)管理】 - >【系統(tǒng)設(shè)置】昙篙,找到【云】盖彭,然后點(diǎn)擊【新增一個(gè)云】
WX20200102-151850.pngname:kubernetes
禁用https證書檢查:false
kubernetes URL:https://kubernetes.default.svc.cluster.local
Kubernetes 服務(wù)證書 key : 為k8s集群生成的ca證書
cat /etc/kubernetes/pki/ca.crt
JenkinsURL:http://jenkins-svc.ci.svc.cluster.local:8077 (服務(wù)名.命名空間.svc.cluster.local:端口)
連接超時(shí):5
讀取超時(shí):15
憑據(jù):根據(jù)下面命令獲取
##1.直接使用二進(jìn)制源碼包安裝cfssl
wget https://pkg.cfssl.org/R1.2/cfssl_linux-amd64
chmod +x cfssl_linux-amd64
mv cfssl_linux-amd64 /usr/local/bin/cfssl
wget https://pkg.cfssl.org/R1.2/cfssljson_linux-amd64
chmod +x cfssljson_linux-amd64
mv cfssljson_linux-amd64 /usr/local/bin/cfssljson
wget https://pkg.cfssl.org/R1.2/cfssl-certinfo_linux-amd64
chmod +x cfssl-certinfo_linux-amd64
mv cfssl-certinfo_linux-amd64 /usr/local/bin/cfssl-certinfo
export PATH=/usr/local/bin:$PATH
#準(zhǔn)備證書簽名請(qǐng)求
mkdir /usr/local/k8s/cfssl
cd /usr/local/k8s/cfssl
vi admin-csr.json
{
"CN": "admin",
"hosts": [],
"key": {
"algo": "rsa",
"size": 2048
},
"names": [
{
"C": "CN",
"ST": "HangZhou",
"L": "XS",
"O": "system:masters",
"OU": "System"
}
]
}
#3.創(chuàng)建證書和私鑰
cd /usr/local/k8s/cfssl
cfssl gencert -ca=/etc/kubernetes/pki/ca.crt -ca-key=/etc/kubernetes/pki/ca.key --profile=kubernetes admin-csr.json | cfssljson -bare admin
# 生成以下三個(gè)文件
ls -l
admin.csr
admin-key.pem
admin.pem
#4.我們可以通過openssl來轉(zhuǎn)換成pkc格式:
openssl pkcs12 -export -out ./jenkins-admin.pfx -inkey ./admin-key.pem -in ./admin.pem -passout pass:secret
#生成jenkins-admin.pfxpfx文件
ls
jenkins-admin.pfx
下載jenkins-admin.pfx到本地保存
將證書內(nèi)容填寫枫振,點(diǎn)擊憑據(jù)后面的添加柑营,點(diǎn)擊Jenkins
得到jenkins-admin.pfk
文件后,點(diǎn)擊Jenkins配置Credentials后面的Add,配置如下
上傳證書
1341090-20190812121333313-1393693991.png選擇文件 jenkins-admin.pfk
22.png輸入密碼 secret伊磺,后面的內(nèi)容可以不填寫宁舰,點(diǎn)擊添加。
33.png選擇 憑據(jù)奢浑,點(diǎn)擊連接測(cè)試。
出現(xiàn) Connection test successful 表示連接成功腋腮。
2.3配置 Pod Template
構(gòu)建slave鏡像
docker pull cnych/jenkins:jnlp6
docker tag cnych/jenkins:jnlp6 harbor.demo.com/private/demo-jenkins:jnlp
docker push harbor.demo.com/private/demo-jenkins:jnlp
設(shè)置Pod Template ( jenkinsfile 中l(wèi)abel標(biāo)簽和標(biāo)簽列表設(shè)置保持一致)
WX20200102-154511.png添加卷
Service Account:jenkins
3.gitlab 設(shè)置
下載gitlab插件
系統(tǒng)管理—系統(tǒng)配置-Gitlab
WX20200102-155116.pngGitLab API token API token 在gitlab-settings-Access Token獲取
WX20200102-155245.png4.新建pipeline任務(wù)
podTemplate(label: '100kip', cloud: 'kubernetes') {
node('100kip') {
environment {
harborHost = ""
harborCertificate = ""
kubeconfigId = ""
privateHarbor = ""
version=""
images=""
yamlPath="";
}
stage('Clone') {
echo "1.Clone Stage"
checkout([$class: 'GitSCM',
branches: [[name: '*/${branch}']],
doGenerateSubmoduleConfigurations: false,
extensions: [[$class: 'CloneOption', depth: 1, honorRefspec: true, noTags: true, reference: '', shallow: true]],
submoduleCfg: [],
userRemoteConfigs: [[credentialsId: 'jenkins_gitlab', url: '${git_url}']]]
)
}
stage('pom version') {
echo "2.pom version"
def pom = readMavenPom file: 'pom.xml'
version = "${pom.version}"
harborHost = "harbor.demo.com"
harborCertificate = "harbor_username_password"
kubeconfigId = "kubernetes_config"
privateHarbor = "${harborHost}\\/kb"
images = "${privateHarbor}\\/${module}:${version}-${BUILD_NUMBER}"
echo "version:${version}-----privateHarbor:${privateHarbor}----images:${images}"
def isCanary="${canary}";
if(isCanary == "true"){
echo "灰度發(fā)布"
yamlPath = "k8s/${profiles}/canary/${module}-canary.yaml";
}else{
yamlPath = "k8s/${profiles}/${module}.yaml";
}
}
stage('Maven bulid') {
echo "2.Maven bulid"
sh "mvn clean package -pl ${module} -P ${profiles} -DskipTests -U "
}
stage('Docker build') {
echo "3.Build Docker Image Stage"
def buildArg = "-f ${module}/Dockerfile --build-arg version=${version} --build-arg module=${module} ."
def customImage = docker.build("${images}", "${buildArg}")
docker.withRegistry("http://${harborHost}", "${harborCertificate}") {
customImage.push()
}
}
stage('K8S Deploy') {
echo "K8S Deploy"
sh "sed -i 's/${module}:lastest/${images}/g' ${yamlPath}"
kubernetesDeploy configs: "${yamlPath}", kubeconfigId: "${kubeconfigId}"
echo "Service deploy successfully! please request http://${domain}"
}
}
}
本文由博客群發(fā)一文多發(fā)等運(yùn)營(yíng)工具平臺(tái) OpenWrite 發(fā)布