Skip to content

CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java - #6257

Open
guillaume-dequenne wants to merge 10 commits into
masterfrom
CLP-918
Open

guillaume-dequenne wants to merge 10 commits into
masterfrom
CLP-918

Conversation

@guillaume-dequenne

@guillaume-dequenne guillaume-dequenne commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Part of CLP-918

Summary

CI resolves Maven dependencies and Orchestrator downloads through the dev JFrog Edge (https://repox-internal.dev.sonar.build) with ci-github-actions 2.2.0. With an Edge repox-url, the reader token is issued by the Edge (development/artifactory-edge-dev on https://vault.dev.sonar.build), so there is no token federation wait.

  • Every build-maven and config-maven step in build.yml and unified-dogfooding.yml is pinned to 2.2.0 and sets repox-url: https://repox-internal.dev.sonar.build. build-maven still deploys to https://repox.jfrog.io with the SaaS qa-deployer token, and promote stays on SaaS.
  • Orchestrator 6.4.3 reads ARTIFACTORY_URL and ARTIFACTORY_ACCESS_TOKEN from config-maven, so the explicit -Dorchestrator.artifactory.* flags and the federation wait steps are removed.

Blocked

The Spring scanner ITs in Build and Unit Test on Windows fail with a 401. sonar-scanner-integration-tester 1.2.0.1354 is a shaded jar that bundles Orchestrator 6.2.0, which reads maven-metadata.xml from the Edge without a token. Its master is on Orchestrator 6.4.3 (#86) but unreleased; this PR needs that release and a bump of sonar-scanner-integration-tester.

Validation

  • PR Build green on the current head, including Build and Unit Test on Windows and the Linux ruling jobs.

@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Migrate Orchestrator downloads to the JFrog Edge node for sonar-java CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java Sep 28, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

CLP-1097

@datadog-sonarsource

This comment has been minimized.

Comment thread .github/actions/wait-for-artifactory-token-federation/action.yml Outdated
Comment thread .github/workflows/build.yml
Comment thread .github/workflows/build.yml
…n tests

sonar-scanner-integration-tester 1.2.0.1354 brings Orchestrator 6.2.0, which
treats an Edge ARTIFACTORY_URL as a plain Maven repository and reads its
maven-metadata.xml without a token. Orchestrator 6.4.3 authenticates on the
Edge. Also resolve the dogfooding build through the Edge with the 2.2.0 pin.
sonar-scanner-integration-tester is a shaded jar that bundles its Orchestrator classes and declares no Orchestrator dependency, so dependencyManagement cannot change the version it runs. The scanner integration tests need a tester release built with Orchestrator 6.4.3.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

❌ Ruling needs updating. A fix PR has been created: #6290

Please review and merge it into your branch.

sonar-scanner-integration-tester 1.3.0.1396 bundles Orchestrator 6.4.3, which authenticates on the JFrog Edge. 1.2.0.1354 bundled Orchestrator 6.2.0, which read maven-metadata.xml from the Edge without a token.
@gitar-bot

gitar-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Code Review ✅ Approved 3 closed / 3 findings

🟡 Medium risk · CI Maven and Orchestrator downloads now resolve through the internal JFrog Edge.

Migrates Orchestrator downloads to JFrog Edge with ci-github-actions 2.2.0, configuring repox-url across build workflows and pinning sonar-orchestrator-locators and sonar-orchestrator-build to 6.4.3.4676 in scanner integration tests. Addressed probe timeout and unified-dogfooding.yml Edge configuration; PR description updated to reflect the Edge-issued-token approach.

✅ 3 closed
✅ Edge Case: Probe curl has no timeout, so the 2-minute bound can be exceeded

📄 .github/actions/wait-for-artifactory-token-federation/action.yml:22-36
The retry loop assumes each attempt is fast: 12 × 10s sleeps, and the failure message says "within 2 minutes". The curl call sets no --connect-timeout or --max-time, though. curl's default connect timeout is 300s and it has no default overall limit, so a slow or unresponsive Edge node can hold one attempt for minutes or indefinitely. The ruling-qa and plugin-qa jobs then stall until the job timeout, and the 2-minute message doesn't match the real behaviour. The 000 retry branch is meant to handle an unreachable Edge, but it only runs after curl returns. Adding per-attempt timeouts fixes this.

✅ Quality: unified-dogfooding.yml still uses build-maven@v2 without the Edge repox-url

📄 .github/workflows/build.yml:37-42
This commit moves every Maven step in build.yml to ci-github-actions@c3a85ac… (v2.2.0) with repox-url: https://repox-internal.dev.sonar.build. .github/workflows/unified-dogfooding.yml:19 still uses the floating build-maven@v2 with the same private-reader/qa-deployer roles and no repox-url, so it keeps resolving through repox.jfrog.io. pr-cleanup.yml also stays on the floating @v2. Nothing in the repo shows this is deliberate. Either apply the same pin and repox-url there, or document why dogfooding should stay on the public Repox.

✅ Quality: PR description no longer matches the code: token-wait and #353 were dropped

📄 .github/workflows/build.yml:95-97 📄 .github/workflows/build.yml:109-123 📄 .github/workflows/build.yml:215-217 📄 .github/workflows/build.yml:229-237
The description says both jobs "wait for token federation", use the shared action from SonarSource/ci-github-actions#353, and that #353 must be merged and repinned before this PR merges. Commit dca4538 removed both wait-for-artifactory-token-federation steps and the explicit -Dorchestrator.artifactory.* flags. Orchestrator now reads ARTIFACTORY_URL/ARTIFACTORY_ACCESS_TOKEN from config-maven@v2.2.0 with repox-url set, and every ci-github-actions step is pinned to v2.2.0. Reviewers and mergers following the description would wait on an unrelated upstream PR, and they would expect a federation wait that the code no longer has. Update the summary, validation and merge-order notes to describe the Edge-issued-token approach.

Review coverage

🧪 Functional validation 1 of 1 objectives covered

📋 Rules No rules evaluated

🤖 Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ CLP-918 - 1 of 1 objectives covered

This PR covers the migration of Orchestrator downloads to the JFrog Edge node.

✅ 1 covered here
  • ✅ Migrate the Orchestrator's SonarQube download source to the JFrog Edge node
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqube-next

sonarqube-next Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants