CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java - #6257
guillaume-dequenne wants to merge 10 commits into
Conversation
This comment has been minimized.
This comment has been minimized.
…n tests sonar-scanner-integration-tester 1.2.0.1354 brings Orchestrator 6.2.0, which treats an Edge ARTIFACTORY_URL as a plain Maven repository and reads its maven-metadata.xml without a token. Orchestrator 6.4.3 authenticates on the Edge. Also resolve the dogfooding build through the Edge with the 2.2.0 pin.
sonar-scanner-integration-tester is a shaded jar that bundles its Orchestrator classes and declares no Orchestrator dependency, so dependencyManagement cannot change the version it runs. The scanner integration tests need a tester release built with Orchestrator 6.4.3.
|
❌ Ruling needs updating. A fix PR has been created: #6290 Please review and merge it into your branch. |
sonar-scanner-integration-tester 1.3.0.1396 bundles Orchestrator 6.4.3, which authenticates on the JFrog Edge. 1.2.0.1354 bundled Orchestrator 6.2.0, which read maven-metadata.xml from the Edge without a token.
Code Review ✅ Approved 3 closed / 3 findings🟡 Medium risk · CI Maven and Orchestrator downloads now resolve through the internal JFrog Edge. Migrates Orchestrator downloads to JFrog Edge with ci-github-actions 2.2.0, configuring ✅ 3 closed✅ Edge Case: Probe curl has no timeout, so the 2-minute bound can be exceeded
✅ Quality: unified-dogfooding.yml still uses build-maven@v2 without the Edge repox-url
✅ Quality: PR description no longer matches the code: token-wait and #353 were dropped
Review coverage🧪 Functional validation 1 of 1 objectives covered 📋 Rules No rules evaluated 🤖 Auto-approval Not enabled · Set up Implementation Status ✅ 1 of 1 objectives covered✅ CLP-918 - 1 of 1 objectives coveredThis PR covers the migration of Orchestrator downloads to the JFrog Edge node. ✅ 1 covered here
OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|





Part of CLP-918
Summary
CI resolves Maven dependencies and Orchestrator downloads through the dev JFrog Edge (
https://repox-internal.dev.sonar.build) with ci-github-actions 2.2.0. With an Edgerepox-url, the reader token is issued by the Edge (development/artifactory-edge-devonhttps://vault.dev.sonar.build), so there is no token federation wait.build-mavenandconfig-mavenstep inbuild.ymlandunified-dogfooding.ymlis pinned to 2.2.0 and setsrepox-url: https://repox-internal.dev.sonar.build.build-mavenstill deploys tohttps://repox.jfrog.iowith the SaaSqa-deployertoken, andpromotestays on SaaS.ARTIFACTORY_URLandARTIFACTORY_ACCESS_TOKENfromconfig-maven, so the explicit-Dorchestrator.artifactory.*flags and the federation wait steps are removed.Blocked
The Spring scanner ITs in
Build and Unit Test on Windowsfail with a 401.sonar-scanner-integration-tester1.2.0.1354 is a shaded jar that bundles Orchestrator 6.2.0, which readsmaven-metadata.xmlfrom the Edge without a token. Its master is on Orchestrator 6.4.3 (#86) but unreleased; this PR needs that release and a bump ofsonar-scanner-integration-tester.Validation
Build and Unit Test on Windowsand the Linux ruling jobs.