Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Campaign] Ensure Github workflow runs on docker image used by Production Distribution Build #1605

Closed
peterzhuamazon opened this issue Oct 6, 2023 · 8 comments
Labels
enhancement New feature or request

Comments

@peterzhuamazon
Copy link
Member

Hi All,

This is coming from the campaign here:

Overview

We would like your CI check (specifically plugin build) in GitHub Repo to run on top of the Build Docker Images from production distribution pipeline.

This is to ensure every plugin repo will use the exact docker images we used in Jenkins build, to check their PRs and run tests before merging the code, so that issues can be detected earlier, and environment can be identical across teams.

Solutions

The Build Team has created a simple script to dynamically retrieve the current docker image name/tag, so everyone can easily pull the images for their CI checks.

We have a trial run of the above with k-NN team. The script retrieves the docker image dynamically, save output, and use it as the docker image to pull for the upcoming run:

Note that GitHub Actions only support LINUX docker container at the time of this writing, so we will add Windows containers later on as well as macOS.

Implementation Notes

We would like you to review above PR and implement similar changes. Note on line 33 of the above k-NN PR, -u and -p parameters needs to assign values accordingly.

  • OpenSearch Plugin:
          CI_IMAGE_VERSION=`opensearch-build/docker/ci/get-ci-images.sh -p centos7 -u opensearch -t build | head -1`
  • OpenSearch-Dashboards Plugin:
          CI_IMAGE_VERSION=`opensearch-build/docker/ci/get-ci-images.sh -p rockylinux8 -u opensearch-dashboards -t build | head -1`

Note that in the above k-NN PR, despite it being OpenSearch plugin, it still uses rockylinux8, as we initially plan to upgrade to rockylinux. We have since revert back to centos7 to support older versions of systems running k-NN lib. As a result, all OpenSearch plugins still uses centos7 for the time being, and all OpenSearch-Dashboards plugins can go to rockylinux8.

Completion Date

The above should be implemented by Nov. 1, 2023 (2023-11-01) by Plugin Owners to their repository.
And backport the changes to 2.x branch after merging in main branch.

Contacts

Please contact @peterzhuamazon for any questions on this campaign.

cc: @bbarani

Thanks.

@peterzhuamazon peterzhuamazon added the enhancement New feature or request label Oct 6, 2023
@stephen-crawford
Copy link
Contributor

[Triage] Hi @peterzhuamazon, thank you for filing this issue. At this time, the Security repos do not have enough context around the purpose of this change... It seems like this is adding responsibility to the Security repo without context for the change. Could you provide a case for this change and why we should address it on such an aggressive time scale (11/1)?

Thank you.

@peterzhuamazon
Copy link
Member Author

We have a new approach established here.
Please see this sample workflow file from Alerting for example:
https://github.com/opensearch-project/alerting/blob/main/.github/workflows/multi-node-test-workflow.yml

Thanks.

@peterzhuamazon
Copy link
Member Author

Hi @scrawfor99 I will work with you on this soon.

Thanks.

@cwperks
Copy link
Member

cwperks commented Oct 23, 2023

[Triage] @peterzhuamazon Will this potentially speed up or make CI checks more stable than the default github runners? The security-dashboards-plugin repo has recently been having issues with running out of space, do these runners have more space than the default github runners?

@peterzhuamazon
Copy link
Member Author

[Triage] @peterzhuamazon Will this potentially speed up or make CI checks more stable than the default github runners? The security-dashboards-plugin repo has recently been having issues with running out of space, do these runners have more space than the default github runners?

Hi @cwperks I dont think it will resolve out of space issues as it is still using github actions runner as host (?), tho the env is in sync with jenkins prod build now so if there is any errors where github actions pass but jenkins doesnt, we can catch them earlier before release cycle starts.

Thanks.

@peterzhuamazon
Copy link
Member Author

Due to the complexity of the workflows, we need to work with security team to understand the process before onboarding the docker images.

@peterzhuamazon peterzhuamazon moved this from Not started to Backlog in OpenSearch Engineering Effectiveness Nov 3, 2023
@stephen-crawford
Copy link
Contributor

[Triage] Hi @peterzhuamazon, is there anything you needed from the Security Plugin or its maintainers at this time? It looks like you marked this as in your Backlog so we wanted to check whether this was still being pursued?

@stephen-crawford
Copy link
Contributor

[Triage] Going to close this. Please reopen if further work continues on this effort.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants