blob: 4b1697e31bb3db213e258c563ac69ffadc514841 [file] [log] [blame]
Samuli Silvius9e9afd72018-12-21 14:23:51 +02001#! /usr/bin/env bash
2
3# COPYRIGHT NOTICE STARTS HERE
4#
Tomáš Levora8d272bd2019-03-12 15:06:35 +01005# Copyright 2018-2019 © Samsung Electronics Co., Ltd.
Samuli Silvius9e9afd72018-12-21 14:23:51 +02006#
7# Licensed under the Apache License, Version 2.0 (the "License");
8# you may not use this file except in compliance with the License.
9# You may obtain a copy of the License at
10#
11# http://www.apache.org/licenses/LICENSE-2.0
12#
13# Unless required by applicable law or agreed to in writing, software
14# distributed under the License is distributed on an "AS IS" BASIS,
15# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16# See the License for the specific language governing permissions and
17# limitations under the License.
18#
19# COPYRIGHT NOTICE ENDS HERE
20
Samuli Silvius9e9afd72018-12-21 14:23:51 +020021### This script prepares Nexus repositories data blobs for ONAP
22
Tomáš Levora8d272bd2019-03-12 15:06:35 +010023## The script requires following dependencies are installed: nodejs, jq, docker
24## All required resources are expected in the upper directory
25## created during download procedure as DATA_DIR
26## All lists used must be in project data_lists directory
Samuli Silvius9e9afd72018-12-21 14:23:51 +020027
28# Fail fast settings
29set -e
30
Tomáš Levora8d272bd2019-03-12 15:06:35 +010031TIMESTAMP="date +'%Y-%m-%d_%H-%M-%S'"
32SCRIPT_LOG="/tmp/$(basename $0)_$(eval ${TIMESTAMP}).log"
33
34# Log everything
35exec &> >(tee -a "${SCRIPT_LOG}")
36
37usage () {
38 echo " This script is preparing Nexus data blob from docker images and npm and pypi packages"
39 echo " Usage:"
40 echo " ./$(basename $0) <project version> [<target>]"
41 echo " "
42 echo " Example: ./$(basename $0) onap_3.0.1 /root/nexus_data"
43 echo " "
44 echo " Dependencies: nodejs, jq, docker"
45 echo " "
46 exit 1
47}
48
Samuli Silvius9e9afd72018-12-21 14:23:51 +020049# Nexus repository location
50NEXUS_DOMAIN="nexus"
Tomáš Levora8d272bd2019-03-12 15:06:35 +010051NEXUS_PORT="8081"
52NEXUS_DOCKER_PORT="8082"
53NPM_REGISTRY="http://${NEXUS_DOMAIN}:${NEXUS_PORT}/repository/npm-private/"
54PYPI_REGISTRY="http://${NEXUS_DOMAIN}:${NEXUS_PORT}/repository/pypi-private/"
55DOCKER_REGISTRY="${NEXUS_DOMAIN}:${NEXUS_DOCKER_PORT}"
56DEFAULT_REGISTRY="docker.io"
Samuli Silvius9e9afd72018-12-21 14:23:51 +020057
58# Nexus repository credentials
59NEXUS_USERNAME=admin
60NEXUS_PASSWORD=admin123
61NEXUS_EMAIL=admin@example.org
62
Tomáš Levora8d272bd2019-03-12 15:06:35 +010063if [ "${1}" == "-h" ] || [ "${1}" == "--help" ] || [ $# -eq 0 ]; then
64 usage
65else
66 TAG="${1}"
67fi
68
69# Setting paths
70LOCAL_PATH="$(readlink -f $(dirname ${0}))"
71DATA_DIR="$(realpath ${LOCAL_PATH}/../../resources)"
72
73if [ -z "${2}" ]; then
74 NEXUS_DATA_DIR="${DATA_DIR}/nexus_data"
75else
76 NEXUS_DATA_DIR="${2}"
77fi
78
79# Setup directory with resources lists
80LISTS_DIR="${LOCAL_PATH}/data_lists"
81
82# Setup directories with resources for docker, npm and pypi
83NXS_SRC_DOCKER_IMG_DIR="${DATA_DIR}/offline_data/docker_images_for_nexus"
84NXS_SRC_NPM_DIR="${DATA_DIR}/offline_data/npm_tar"
85NXS_SRC_PYPI_DIR="${DATA_DIR}/offline_data/pypi"
86
87# Setup specific resources list based on the tag provided
88NXS_DOCKER_IMG_LIST="${LISTS_DIR}/${TAG}-docker_images.list"
89NXS_NPM_LIST="${LISTS_DIR}/$(sed 's/.$/x/' <<< ${TAG})-npm.list"
90NXS_PYPI_LIST="${LISTS_DIR}/$(sed 's/.$/x/' <<< ${TAG})-pip_packages.list"
91
92# Setup Nexus image used for build and install infra
93INFRA_LIST="${LISTS_DIR}/infra_docker_images.list"
94NEXUS_IMAGE="$(grep sonatype/nexus3 ${INFRA_LIST})"
95NEXUS_IMAGE_TAR="${DATA_DIR}/offline_data/docker_images_infra/$(sed 's/\//\_/ ; s/$/\.tar/ ; s/\:/\_/' <<< ${NEXUS_IMAGE})"
96
97# Setup default ports published to host as docker registry
98PUBLISHED_PORTS="-p ${NEXUS_PORT}:${NEXUS_PORT} -p ${NEXUS_DOCKER_PORT}:${NEXUS_DOCKER_PORT}"
99
100# Setup additional ports published to host based on simulated docker registries
101for REGISTRY in $(sed -n '/\.[^/].*\//p' ${NXS_DOCKER_IMG_LIST} | sed -e 's/\/.*$//' | sort -u | grep -v ${DEFAULT_REGISTRY} || true); do
102 if [[ ${REGISTRY} != *":"* ]]; then
103 if [[ ${PUBLISHED_PORTS} != *"80:${NEXUS_DOCKER_PORT}"* ]]; then
104 PUBLISHED_PORTS="${PUBLISHED_PORTS} -p 80:${NEXUS_DOCKER_PORT}"
105 fi
106 else
107 REGISTRY_PORT="$(sed 's/^.*\:\([[:digit:]]*\)$/\1/' <<< ${REGISTRY})"
108 if [[ ${PUBLISHED_PORTS} != *"${REGISTRY_PORT}:${NEXUS_DOCKER_PORT}"* ]]; then
109 PUBLISHED_PORTS="${PUBLISHED_PORTS} -p ${REGISTRY_PORT}:${NEXUS_DOCKER_PORT}"
110 fi
111 fi
112done
113
114# Setup simulated domain names to be able to push all to private Nexus repository
115SIMUL_HOSTS="$(sed -n '/\.[^/].*\//p' ${NXS_DOCKER_IMG_LIST} | sed -e 's/\/.*$// ; s/:.*$//' | sort -u | grep -v ${DEFAULT_REGISTRY} || true) ${NEXUS_DOMAIN}"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200116
117# Nexus repository configuration setup
118NEXUS_CONFIG_GROOVY='import org.sonatype.nexus.security.realm.RealmManager
119import org.sonatype.nexus.repository.attributes.AttributesFacet
120import org.sonatype.nexus.security.user.UserManager
121import org.sonatype.nexus.repository.manager.RepositoryManager
122import org.sonatype.nexus.security.user.UserNotFoundException
123/* Use the container to look up some services. */
124realmManager = container.lookup(RealmManager.class)
125userManager = container.lookup(UserManager.class, "default") //default user manager
126repositoryManager = container.lookup(RepositoryManager.class)
127/* Managers are used when scripting api cannot. Note that scripting api can only create mostly, and that creation methods return objects of created entities. */
128/* Perform cleanup by removing all repos and users. Realms do not need to be re-disabled, admin and anonymous user will not be removed. */
129userManager.listUserIds().each({ id ->
130 if (id != "anonymous" && id != "admin")
131 userManager.deleteUser(id)
132})
133repositoryManager.browse().each {
134 repositoryManager.delete(it.getName())
135}
136/* Add bearer token realms at the end of realm lists... */
137realmManager.enableRealm("NpmToken")
138realmManager.enableRealm("DockerToken")
Tomáš Levora1d902342019-02-05 10:01:43 +0100139realmManager.enableRealm("PypiToken")
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200140/* Create the docker user. */
141security.addUser("docker", "docker", "docker", "docker@example.com", true, "docker", ["nx-anonymous"])
Tomáš Levora1d902342019-02-05 10:01:43 +0100142/* Create docker, npm and pypi repositories. Their default configuration should be compliant with our requirements, except the docker registry creation. */
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200143repository.createNpmHosted("npm-private")
Tomáš Levora1d902342019-02-05 10:01:43 +0100144repository.createPyPiHosted("pypi-private")
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200145def r = repository.createDockerHosted("onap", 8082, 0)
146/* force basic authentication true by default, must set to false for docker repo. */
147conf=r.getConfiguration()
148conf.attributes("docker").set("forceBasicAuth", false)
149repositoryManager.update(conf)'
150
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100151# Prepare the Nexus configuration
152NEXUS_CONFIG=$(echo "${NEXUS_CONFIG_GROOVY}" | jq -Rsc '{"name":"configure", "type":"groovy", "content":.}')
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200153
154#################################
155# Prepare the local environment #
156#################################
157
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200158# Add simulated domain names to /etc/hosts
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100159HOSTS_BACKUP="$(eval ${TIMESTAMP}_hosts.bk)"
160cp /etc/hosts "/etc/${HOSTS_BACKUP}"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200161for DNS in ${SIMUL_HOSTS}; do
162 echo "127.0.0.1 ${DNS}" >> /etc/hosts
163done
164
165# Backup the current docker registry settings
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100166if [ -f ~/.docker/config.json ]; then
167 DOCKER_CONF_BACKUP="$(eval ${TIMESTAMP}_config.json.bk)"
168 mv ~/.docker/config.json "~/.docker/${DOCKER_CONF_BACKUP}"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200169fi
170
171#################################
172# Docker repository preparation #
173#################################
174
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100175# Load predefined Nexus image
176docker load -i ${NEXUS_IMAGE_TAR}
177
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200178# Load all necessary images
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100179for ARCHIVE in $(sed $'s/\r// ; /^#/d ; s/\:/\_/g ; s/\//\_/g ; s/$/\.tar/g' ${NXS_DOCKER_IMG_LIST} | awk '{ print $1 }'); do
180 docker load -i ${NXS_SRC_DOCKER_IMG_DIR}/${ARCHIVE}
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200181done
182
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200183################################
184# Nexus repository preparation #
185################################
186
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200187# Prepare nexus-data directory
188if [ -d ${NEXUS_DATA_DIR} ]; then
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100189 if [ "$(docker ps -q -f name="${NEXUS_DOMAIN}")" ]; then
190 echo "Removing container ${NEXUS_DOMAIN}"
191 docker rm -f $(docker ps -aq -f name="${NEXUS_DOMAIN}")
192 fi
193 pushd ${NEXUS_DATA_DIR}/..
194 NXS_BACKUP="$(eval ${TIMESTAMP})_$(basename ${NEXUS_DATA_DIR})_bk"
195 mv ${NEXUS_DATA_DIR} "${NXS_BACKUP}"
196 echo "${NEXUS_DATA_DIR} already exists - backing up to ${NXS_BACKUP}"
197 popd
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200198fi
199
200mkdir -p ${NEXUS_DATA_DIR}
201chown 200:200 ${NEXUS_DATA_DIR}
202chmod 777 ${NEXUS_DATA_DIR}
203
204# Save Nexus version to prevent/catch data incompatibility
205docker images --no-trunc | grep sonatype/nexus3 | awk '{ print $1":"$2" "$3}' > ${NEXUS_DATA_DIR}/nexus.ver
206
207# Start the Nexus
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100208NEXUS_CONT_ID=$(docker run -d --rm -v ${NEXUS_DATA_DIR}:/nexus-data:rw --name ${NEXUS_DOMAIN} ${PUBLISHED_PORTS} ${NEXUS_IMAGE})
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200209echo "Waiting for Nexus to fully start"
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100210until curl -su ${NEXUS_USERNAME}:${NEXUS_PASSWORD} http://${NEXUS_DOMAIN}:${NEXUS_PORT}/service/metrics/healthcheck | grep '"healthy":true' > /dev/null ; do
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200211 printf "."
212 sleep 3
213done
214echo -e "\nNexus started"
215
216# Configure the nexus repository
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100217curl -sX POST --header 'Content-Type: application/json' --data-binary "${NEXUS_CONFIG}" http://${NEXUS_USERNAME}:${NEXUS_PASSWORD}@${NEXUS_DOMAIN}:${NEXUS_PORT}/service/rest/v1/script
218curl -sX POST --header "Content-Type: text/plain" http://${NEXUS_USERNAME}:${NEXUS_PASSWORD}@${NEXUS_DOMAIN}:${NEXUS_PORT}/service/rest/v1/script/configure/run > /dev/null
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200219
220###########################
221# Populate NPM repository #
222###########################
223
224# Configure NPM registry to our Nexus repository
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100225echo "Configure NPM registry to ${NPM_REGISTRY}"
226npm config set registry "${NPM_REGISTRY}"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200227
228# Login to NPM registry
229/usr/bin/expect <<EOF
230spawn npm login
231expect "Username:"
232send "${NEXUS_USERNAME}\n"
233expect "Password:"
234send "${NEXUS_PASSWORD}\n"
235expect Email:
236send "${NEXUS_EMAIL}\n"
237expect eof
238EOF
239
240# Patch problematic package
Tomáš Levora1d902342019-02-05 10:01:43 +0100241pushd ${NXS_SRC_NPM_DIR}
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100242PATCHED_NPM="$(grep tsscmp ${NXS_NPM_LIST} | sed $'s/\r// ; s/\\@/\-/ ; s/$/\.tgz/')"
243if [[ ! -z "${PATCHED_NPM}" ]] && ! zgrep -aq "${NPM_REGISTRY}" "${PATCHED_NPM}" 2>/dev/null; then
244 tar xzf "${PATCHED_NPM}"
245 rm -f "${PATCHED_NPM}"
246 sed -i 's|\"registry\":\ \".*\"|\"registry\":\ \"'"${NPM_REGISTRY}"'\"|g' package/package.json
247 tar -zcf "${PATCHED_NPM}" package
248 rm -rf package
249fi
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200250
251# Push NPM packages to Nexus repository
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100252for ARCHIVE in $(sed $'s/\r// ; s/\\@/\-/g ; s/$/\.tgz/g' ${NXS_NPM_LIST});do
253 npm publish --access public ${ARCHIVE} > /dev/null
254 echo "NPM ${ARCHIVE} pushed to Nexus"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200255done
Tomáš Levora1d902342019-02-05 10:01:43 +0100256popd
257
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100258###############################
259## Populate PyPi repository #
260###############################
Tomáš Levora1d902342019-02-05 10:01:43 +0100261
262pushd ${NXS_SRC_PYPI_DIR}
263for PACKAGE in $(sed $'s/\r//; s/==/-/' ${NXS_PYPI_LIST}); do
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100264 twine upload -u "${NEXUS_USERNAME}" -p "${NEXUS_PASSWORD}" --repository-url ${PYPI_REGISTRY} ${PACKAGE}*
265 echo "PYPI ${PACKAGE} pushed to Nexus"
Tomáš Levora1d902342019-02-05 10:01:43 +0100266done
267popd
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200268
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100269###############################
270## Populate Docker repository #
271###############################
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200272
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100273# Login to simulated docker registries
274for REGISTRY in $(sed -n '/\.[^/].*\//p' ${NXS_DOCKER_IMG_LIST} | sed -e 's/\/.*$//' | sort -u | grep -v ${DEFAULT_REGISTRY}) ${DOCKER_REGISTRY}; do
275 echo "Docker login to ${REGISTRY}"
276 docker login -u "${NEXUS_USERNAME}" -p "${NEXUS_PASSWORD}" ${REGISTRY} > /dev/null
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200277done
278
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100279# Push images to private nexus based on the list
280# Images from default registry need to be tagged to private registry
281# and those without defined repository in tag uses default repository 'library'
282for IMAGE in $(sed $'s/\r// ; /^#/d' ${NXS_DOCKER_IMG_LIST} | awk '{ print $1 }'); do
283 PUSH=""
284 if [[ ${IMAGE} != *"/"* ]]; then
285 PUSH="${DOCKER_REGISTRY}/library/${IMAGE}"
286 elif [[ ${IMAGE} == *"${DEFAULT_REGISTRY}"* ]]; then
287 if [[ ${IMAGE} == *"/"*"/"* ]]; then
288 PUSH="$(sed 's/'"${DEFAULT_REGISTRY}"'/'"${DOCKER_REGISTRY}"'/' <<< ${IMAGE})"
289 else
290 PUSH="$(sed 's/'"${DEFAULT_REGISTRY}"'/'"${DOCKER_REGISTRY}"'\/library/' <<< ${IMAGE})"
291 fi
292 elif [[ -z $(sed -n '/\.[^/].*\//p' <<< ${IMAGE}) ]]; then
293 PUSH="${DOCKER_REGISTRY}/${IMAGE}"
294 fi
295 if [[ ! -z ${PUSH} ]]; then
296 docker tag ${IMAGE} ${PUSH}
297 else
298 PUSH="${IMAGE}"
299 fi
300 docker push ${PUSH}
301 echo "${IMAGE} pushed as ${PUSH} to Nexus"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200302done
303
304##############################
305# Stop the Nexus and cleanup #
306##############################
307
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100308echo "Stopping Nexus and returning backups"
309
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200310# Stop the Nexus
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100311docker stop ${NEXUS_CONT_ID} > /dev/null
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200312
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100313# Return backed up configuration files
314mv -f "${HOSTS_BACKUP}" /etc/hosts
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200315
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100316if [ -f "~/.docker/${DOCKER_CONF_BACKUP}" ]; then
317 mv -f "${DOCKER_CONF_BACKUP}" ~/.docker/config.json
318fi
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200319
Tomáš Levora8d272bd2019-03-12 15:06:35 +0100320# Return default settings
321npm config set registry "https://registry.npmjs.org"
322
323echo "Nexus blob is built"
Samuli Silvius9e9afd72018-12-21 14:23:51 +0200324exit 0