deploy: add build_bypass.yaml This works the same as build.yaml, but skips testing and running govulncheck. This is intended to be used manually when the regular build process is stuck due to, for example, having a dependency for which there is no fix yet. Change-Id: I8f71e7008fd1d99d2ab6d777aa8e00f98e171f91 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/817042 Reviewed-by: Roland Shoemaker <roland@golang.org> Auto-Submit: Roland Shoemaker <roland@golang.org> Reviewed-by: Neal Patel <nealpatel@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/deploy/build_bypass.yaml b/deploy/build_bypass.yaml new file mode 100644 index 0000000..e8e1cef --- /dev/null +++ b/deploy/build_bypass.yaml
@@ -0,0 +1,83 @@ +steps: + - id: Lock + name: golang:latest + entrypoint: bash + args: + - -ec + - | + if [[ "$COMMIT_SHA" = '' ]]; then + echo "no COMMIT_SHA, not locking" + exit 0 + fi + go run golang.org/x/website/cmd/locktrigger@latest \ + -project $PROJECT_ID -build $BUILD_ID -repo https://go.googlesource.com/vulndb + + - id: Unshallow + name: gcr.io/cloud-builders/git + entrypoint: bash + args: + - -c + - | + if ! git fetch --unshallow; then + echo "git fetch --unshallow failed, no worries mate" + fi + + - id: CopyExisting + name: gcr.io/cloud-builders/gcloud + entrypoint: bash + args: + - -ec + - gcloud -q storage cp --recursive gs://go-vulndb /workspace + + - id: Generate + name: golang:latest + entrypoint: bash + args: ["-ec", "go run ./cmd/gendb -out /workspace/db -zip /workspace/db/vulndb.zip"] + + - id: PreValidate + name: golang:latest + entrypoint: bash + args: + - -ec + - go run ./cmd/checkdeploy -new /workspace/db -existing /workspace/go-vulndb + + - id: Deploy + name: gcr.io/cloud-builders/gcloud + entrypoint: bash + args: ["./deploy/gcp-deploy.sh"] + + - id: CopyDeployed + name: gcr.io/cloud-builders/gcloud + entrypoint: bash + args: + - -ec + - mkdir /workspace/deployed && gcloud -q storage cp --recursive gs://go-vulndb /workspace/deployed + + - id: PostValidate + name: golang:latest + entrypoint: bash + args: ["-ec", "go run ./cmd/checkdb /workspace/deployed/go-vulndb"] + env: + - 'GOPROXY=https://proxy.golang.org' + + - id: PublishCVEs + name: golang:latest + entrypoint: bash + args: + - -ec + - | + # Ensure we have valid credentials before attempting publish. + go run ./cmd/cve -key $$CVE_API_KEY -user $$CVE_API_USER quota + # Publish or update any CVE records that have changed. + go run ./cmd/cve -key $$CVE_API_KEY -user $$CVE_API_USER publish-all + secretEnv: ['CVE_API_USER', 'CVE_API_KEY'] + +availableSecrets: + secretManager: + - versionName: ${_CVE_API_KEY} + env: 'CVE_API_KEY' + - versionName: ${_CVE_API_USER} + env: 'CVE_API_USER' + +options: + logging: CLOUD_LOGGING_ONLY