From 61a9e6dbb41551d74a41e6ca961e9acc123f1492 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Mon, 27 Jul 2026 11:50:03 +0200 Subject: [PATCH 01/17] STAC-25420 Upgrade OTel and refresh BCI packages --- BCI.dockerfile | 3 ++- go.mod | 24 ++++++++++++------------ go.sum | 50 ++++++++++++++++++++++++++------------------------ 3 files changed, 40 insertions(+), 37 deletions(-) diff --git a/BCI.dockerfile b/BCI.dockerfile index adedb474..c242e41c 100644 --- a/BCI.dockerfile +++ b/BCI.dockerfile @@ -22,7 +22,8 @@ ENV DOCKER_STS_AGENT=true \ SHORT_ARCH=${SHORT_ARCH} \ EBPF_SUBFOLDER=${EBPF_SUBFOLDER} -RUN zypper -n --no-gpg-checks --installroot /chroot refresh && \ +RUN zypper -n --gpg-auto-import-keys --installroot /chroot refresh && \ + zypper -n --gpg-auto-import-keys --installroot /chroot update && \ zypper -n --installroot /chroot install util-linux libudev1 ca-certificates curl wget xz iproute2 conntrack-tools && \ zypper -n --root /chroot clean --all diff --git a/go.mod b/go.mod index 0ab76e61..0b465950 100644 --- a/go.mod +++ b/go.mod @@ -180,12 +180,12 @@ require ( github.com/hashicorp/golang-lru/v2 v2.0.7 github.com/shirou/gopsutil/v4 v4.26.4 go.opentelemetry.io/obi v0.9.0 - go.opentelemetry.io/otel v1.43.0 - go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.43.0 - go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.37.0 - go.opentelemetry.io/otel/metric v1.43.0 - go.opentelemetry.io/otel/sdk v1.43.0 - go.opentelemetry.io/otel/sdk/metric v1.43.0 + go.opentelemetry.io/otel v1.44.0 + go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.44.0 + go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.44.0 + go.opentelemetry.io/otel/metric v1.44.0 + go.opentelemetry.io/otel/sdk v1.44.0 + go.opentelemetry.io/otel/sdk/metric v1.44.0 k8s.io/kubelet v0.31.2 ) @@ -388,7 +388,7 @@ require ( github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect github.com/grpc-ecosystem/go-grpc-middleware v1.4.0 // indirect github.com/grpc-ecosystem/grpc-gateway v1.16.0 // indirect - github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect + github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 // indirect github.com/h2non/filetype v1.1.3 // indirect github.com/hashicorp/errwrap v1.1.0 // indirect github.com/hashicorp/go-multierror v1.1.1 // indirect @@ -514,9 +514,9 @@ require ( go.mongodb.org/mongo-driver v1.17.7 // indirect go.opentelemetry.io/auto/sdk v1.2.1 // indirect go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 // indirect - go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 // indirect - go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 // indirect - go.opentelemetry.io/otel/trace v1.43.0 // indirect + go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 // indirect + go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0 // indirect + go.opentelemetry.io/otel/trace v1.44.0 // indirect go.opentelemetry.io/proto/otlp v1.10.0 // indirect go.uber.org/atomic v1.11.0 // indirect go.uber.org/dig v1.18.0 // indirect @@ -534,8 +534,8 @@ require ( golang.org/x/lint v0.0.0-20241112194109-818c5a804067 // indirect golang.org/x/term v0.44.0 // indirect golang.org/x/tools/go/expect v0.1.1-deprecated // indirect - google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478 // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 // indirect + google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa // indirect gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect gopkg.in/go-jose/go-jose.v2 v2.6.3 // indirect diff --git a/go.sum b/go.sum index c369be79..2e946d98 100644 --- a/go.sum +++ b/go.sum @@ -932,8 +932,8 @@ github.com/grpc-ecosystem/go-grpc-middleware v1.4.0/go.mod h1:g5qyo/la0ALbONm6Vb github.com/grpc-ecosystem/grpc-gateway v1.13.0/go.mod h1:8XEsbTttt/W+VvjtQhLACqCisSPWTxCZ7sBRjU6iH9c= github.com/grpc-ecosystem/grpc-gateway v1.16.0 h1:gmcG1KaJ57LophUzW0Hy8NmPhnMZb4M0+kPpLofRdBo= github.com/grpc-ecosystem/grpc-gateway v1.16.0/go.mod h1:BDjrQk3hbvj6Nolgz8mAMFbcEtjT1g+wF4CSlocrBnw= -github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 h1:HWRh5R2+9EifMyIHV7ZV+MIZqgz+PMpZ14Jynv3O2Zs= -github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0/go.mod h1:JfhWUomR1baixubs02l85lZYYOm7LV6om4ceouMv45c= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 h1:5VipnvEpbqr2gA2VbM+nYVbkIF28c5ZQfqCBQ5g2xfk= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0/go.mod h1:Hyl3n6Twe1hvtd9XUXDec4pTvgMSEixRuQKPTMH2bNs= github.com/h2non/filetype v1.0.5/go.mod h1:isekKqOuhMj+s/7r3rIeTErIRy4Rub5uBWHfvMusLMU= github.com/h2non/filetype v1.1.3 h1:FKkx9QbD7HR/zjK1Ia5XiBsq9zdLi5Kf3zGyFTAFkGg= github.com/h2non/filetype v1.1.3/go.mod h1:319b3zT68BvV+WRj7cwy856M2ehB3HqNOt6sy1HndBY= @@ -1603,26 +1603,28 @@ go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 h1:CqXxU8V go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0/go.mod h1:BuhAPThV8PBHBvg8ZzZ/Ok3idOdhWIodywz2xEcRbJo= go.opentelemetry.io/obi v0.9.0 h1:kJ8fNEtnpAZQ6KuJ8DePRSR/Xdv9NSwfMdIkurTk3w0= go.opentelemetry.io/obi v0.9.0/go.mod h1:PNuZ5ddXMJdxApl5gXV7hs/rr34cZ+b4NTkU6qXeIUs= -go.opentelemetry.io/otel v1.43.0 h1:mYIM03dnh5zfN7HautFE4ieIig9amkNANT+xcVxAj9I= -go.opentelemetry.io/otel v1.43.0/go.mod h1:JuG+u74mvjvcm8vj8pI5XiHy1zDeoCS2LB1spIq7Ay0= -go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.43.0 h1:8UQVDcZxOJLtX6gxtDt3vY2WTgvZqMQRzjsqiIHQdkc= -go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.43.0/go.mod h1:2lmweYCiHYpEjQ/lSJBYhj9jP1zvCvQW4BqL9dnT7FQ= -go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 h1:88Y4s2C8oTui1LGM6bTWkw0ICGcOLCAI5l6zsD1j20k= -go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0/go.mod h1:Vl1/iaggsuRlrHf/hfPJPvVag77kKyvrLeD10kpMl+A= -go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 h1:RAE+JPfvEmvy+0LzyUA25/SGawPwIUbZ6u0Wug54sLc= -go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0/go.mod h1:AGmbycVGEsRx9mXMZ75CsOyhSP6MFIcj/6dnG+vhVjk= +go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= +go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= +go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.44.0 h1:SUplec5dp06reu1zaXmOXdvqH398taqrDXqUl99jxSc= +go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.44.0/go.mod h1:ho2g4N+ane+swq5I/VBkKWnRDY4kUINH3FuqyZqX/Ug= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 h1:4YsVu3B8+3qtWYYrsUYgn0OG78pN0rnNPRGX4SbokQI= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0/go.mod h1:+wnlSn0mD1ADVMe3v9Z/WIaiz6q6gL2J/ejaAmdmv80= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0 h1:qazEJlUOQzhCpzQpFETGby7EdqjI1wsd0W+6Gg1SCTU= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0/go.mod h1:fOD2Yefuxixkx3ahVNf0O/PERb6r4OlbxfATVnYvzCo= go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 h1:3iZJKlCZufyRzPzlQhUIWVmfltrXuGyfjREgGP3UUjc= go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0/go.mod h1:/G+nUPfhq2e+qiXMGxMwumDrP5jtzU+mWN7/sjT2rak= -go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.37.0 h1:6VjV6Et+1Hd2iLZEPtdV7vie80Yyqf7oikJLjQ/myi0= -go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.37.0/go.mod h1:u8hcp8ji5gaM/RfcOo8z9NMnf1pVLfVY7lBY2VOGuUU= -go.opentelemetry.io/otel/metric v1.43.0 h1:d7638QeInOnuwOONPp4JAOGfbCEpYb+K6DVWvdxGzgM= -go.opentelemetry.io/otel/metric v1.43.0/go.mod h1:RDnPtIxvqlgO8GRW18W6Z/4P462ldprJtfxHxyKd2PY= -go.opentelemetry.io/otel/sdk v1.43.0 h1:pi5mE86i5rTeLXqoF/hhiBtUNcrAGHLKQdhg4h4V9Dg= -go.opentelemetry.io/otel/sdk v1.43.0/go.mod h1:P+IkVU3iWukmiit/Yf9AWvpyRDlUeBaRg6Y+C58QHzg= -go.opentelemetry.io/otel/sdk/metric v1.43.0 h1:S88dyqXjJkuBNLeMcVPRFXpRw2fuwdvfCGLEo89fDkw= -go.opentelemetry.io/otel/sdk/metric v1.43.0/go.mod h1:C/RJtwSEJ5hzTiUz5pXF1kILHStzb9zFlIEe85bhj6A= -go.opentelemetry.io/otel/trace v1.43.0 h1:BkNrHpup+4k4w+ZZ86CZoHHEkohws8AY+WTX09nk+3A= -go.opentelemetry.io/otel/trace v1.43.0/go.mod h1:/QJhyVBUUswCphDVxq+8mld+AvhXZLhe+8WVFxiFff0= +go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.44.0 h1:hqxVTu/GtBF+vJ8d1fzW7fRxZFvgoDjWcxwwCaFDYpU= +go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.44.0/go.mod h1:z5fVEF4X5v0ESvlJqBrrFlBVoj5EQuefZpzsu7R+x5Q= +go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= +go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo= +go.opentelemetry.io/otel/metric/x v0.66.0 h1:YkCrx1zLOChi9ZcZ6euupOcsgzbVlec7D/xoEU1+cTA= +go.opentelemetry.io/otel/metric/x v0.66.0/go.mod h1:d1+BDj9t96do0/1LoU1ayfCv79ZgNE41qbhBvnMOBZk= +go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58= +go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0= +go.opentelemetry.io/otel/sdk/metric v1.44.0 h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI= +go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA= +go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= +go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= go.opentelemetry.io/proto/otlp v1.10.0 h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g= go.opentelemetry.io/proto/otlp v1.10.0/go.mod h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk= go.step.sm/crypto v0.44.2 h1:t3p3uQ7raP2jp2ha9P6xkQF85TJZh+87xmjSLaib+jk= @@ -2038,10 +2040,10 @@ google.golang.org/genproto v0.0.0-20200804131852-c06518451d9c/go.mod h1:FWY/as6D google.golang.org/genproto v0.0.0-20200825200019-8632dd797987/go.mod h1:FWY/as6DDZQgahTzZj3fqbO1CbirC29ZNUFHwi0/+no= google.golang.org/genproto v0.0.0-20240903143218-8af14fe29dc1 h1:BulPr26Jqjnd4eYDVe+YvyR7Yc2vJGkO5/0UxD0/jZU= google.golang.org/genproto v0.0.0-20240903143218-8af14fe29dc1/go.mod h1:hL97c3SYopEHblzpxRL4lSs523++l8DYxGM1FQiYmb4= -google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478 h1:yQugLulqltosq0B/f8l4w9VryjV+N/5gcW0jQ3N8Qec= -google.golang.org/genproto/googleapis/api v0.0.0-20260414002931-afd174a4e478/go.mod h1:C6ADNqOxbgdUUeRTU+LCHDPB9ttAMCTff6auwCVa4uc= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478 h1:RmoJA1ujG+/lRGNfUnOMfhCy5EipVMyvUE+KNbPbTlw= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260414002931-afd174a4e478/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa h1:Kjn0N0tCrDgiAFW+lGO4JZ3ck44CehvJQMAwj9QF0G8= +google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:q4lMZS6kskjT5HvCPrnnypcDPVJqT/f4nfxmkE7gryY= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa h1:mZHHdPZl0dbGHCflZgAq/Q468DWVFcU2whhB2KAo8fk= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= google.golang.org/grpc v1.19.0/go.mod h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c= google.golang.org/grpc v1.20.1/go.mod h1:10oTOabMzJvdu6/UiuZezV6QK5dSlG84ov/aaiqXj38= google.golang.org/grpc v1.21.1/go.mod h1:oYelfM1adQP15Ek0mdvEgi9Df8B9CZIaU1084ijfRaM= From ef90d4698b815a61ff0de696aa210afa974c8516 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:11:39 +0200 Subject: [PATCH 02/17] STAC-25420 Migrate process-agent CI to GitHub --- .github/workflows/ci.yml | 375 +++++++++++++++++++++++++++++++++++++++ packaging/oci-labels.sh | 4 +- 2 files changed, 377 insertions(+), 2 deletions(-) create mode 100644 .github/workflows/ci.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 00000000..4e702298 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,375 @@ +name: Process-agent CI + +on: + pull_request: + push: + branches: + - master + workflow_dispatch: + +permissions: {} + +concurrency: + group: process-agent-ci-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +env: + IMAGE: quay.io/stackstate/stackstate-k8s-process-agent + +jobs: + prebuild-datadog-agent: + name: Prebuild DataDog eBPF dependencies (${{ matrix.arch }}) + runs-on: ${{ matrix.runner }} + permissions: + contents: read + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + runner: ubuntu-24.04 + prebuild-image: quay.io/stackstate/datadog_build_system-probe_x64:61b4ad67 + - arch: arm64 + runner: ubuntu-24.04-arm + prebuild-image: quay.io/stackstate/datadog_build_system-probe_arm64:61b4ad67 + steps: + - name: Check out source commit + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: ${{ github.event.pull_request.head.sha || github.sha }} + persist-credentials: false + + # A general-purpose BCI builder cannot generate DataDog's eBPF artifacts. + # This repository-owned, architecture-specific builder is the existing + # supported toolchain and is also used to build the upstream agent fork. + - name: Generate DataDog eBPF and Go artifacts + env: + PREBUILD_IMAGE: ${{ matrix.prebuild-image }} + run: | + set -euo pipefail + docker run --rm \ + --volume "${GITHUB_WORKSPACE}:/workspace" \ + --workdir /workspace \ + "${PREBUILD_IMAGE}" \ + bash -lc './prebuild-datadog-agent.sh --generate-no-docker' + + - name: Upload prebuild artifacts + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: prebuild-${{ matrix.arch }} + path: prebuild_artifacts/artifacts + if-no-files-found: error + retention-days: 1 + + build-and-test: + name: Build, generated-code check, and unit tests (${{ matrix.arch }}) + needs: prebuild-datadog-agent + runs-on: ${{ matrix.runner }} + permissions: + contents: read + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + runner: ubuntu-24.04 + builder-image: quay.io/stackstate/datadog_build_deb_x64:61b4ad67 + - arch: arm64 + runner: ubuntu-24.04-arm + builder-image: quay.io/stackstate/datadog_build_deb_arm64:61b4ad67 + steps: + - name: Check out source commit + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: ${{ github.event.pull_request.head.sha || github.sha }} + fetch-depth: 0 + persist-credentials: false + + - name: Download prebuild artifacts + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: prebuild-${{ matrix.arch }} + path: prebuild_artifacts/artifacts + + # The DataDog builder carries the matching compiler, Ruby, conda, LLVM, + # and native libraries needed by the fork. There is no equivalent BCI + # image that can compile this legacy eBPF dependency graph. + - name: Verify generated code, build, and test + env: + BUILDER_IMAGE: ${{ matrix.builder-image }} + SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} + run: | + set -euo pipefail + short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" + + docker run --rm \ + --volume "${GITHUB_WORKSPACE}:/workspace" \ + --workdir /workspace \ + --env CI=true \ + --env GO111MODULE=on \ + --env GOPATH=/workspace/.go \ + --env PROCESS_AGENT_VERSION="${short_sha}" \ + "${BUILDER_IMAGE}" \ + bash -lc ' + eval "$(gimme)" + source /root/.bashrc + source /etc/profile + conda activate ddpy3 + set -euo pipefail + export PATH="${GOPATH}/bin:${PATH}" + + go mod verify + (cd "$(go list -f "{{ .Dir }}" -m github.com/gogo/protobuf)" && make install) + rake protobuf + git diff --exit-code -- model + rake ci + ./prebuild-datadog-agent.sh --install-ebpf + git diff --exit-code + ' + + - name: Upload process-agent image inputs + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: process-agent-${{ matrix.arch }} + path: | + process-agent + ebpf-object-files + if-no-files-found: error + retention-days: 1 + + image-smoke-and-scan: + name: BCI image smoke test, Trivy secrets/CVEs, and Grype (${{ matrix.arch }}) + needs: build-and-test + runs-on: ${{ matrix.runner }} + permissions: + contents: read + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + runner: ubuntu-24.04 + long-arch: x86_64 + llvm-arch: x86_64 + - arch: arm64 + runner: ubuntu-24.04-arm + long-arch: aarch64 + llvm-arch: arm64 + steps: + - name: Check out source commit + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: ${{ github.event.pull_request.head.sha || github.sha }} + persist-credentials: false + + - name: Download process-agent image inputs + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: process-agent-${{ matrix.arch }} + path: . + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 + + - name: Resolve image metadata + id: image + env: + SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} + run: | + set -euo pipefail + short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" + echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" + + - name: Resolve canonical OCI labels + id: oci + uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + with: + image-name: stackstate-k8s-process-agent + tag: ${{ steps.image.outputs.tag }} + title: SUSE Observability Process Agent + description: Process agent collecting per-process and per-container telemetry for SUSE Observability. + component: stackstate-k8s-process-agent + dockerfile: BCI.dockerfile + base-name: registry.suse.com/bci/bci-micro:15.7 + + - name: Build local BCI runtime image + uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0 + with: + context: . + file: BCI.dockerfile + platforms: linux/${{ matrix.arch }} + load: true + push: false + provenance: false + sbom: false + build-args: | + EBPF_SUBFOLDER=${{ matrix.llvm-arch }} + LONG_ARCH=${{ matrix.long-arch }} + SHORT_ARCH=${{ matrix.arch }} + labels: | + ${{ steps.oci.outputs.labels }} + org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} + tags: local/stackstate-k8s-process-agent:${{ steps.image.outputs.tag }}-${{ matrix.arch }} + + - name: Smoke test packaged process-agent binary + env: + ARCH: ${{ matrix.arch }} + TAG: ${{ steps.image.outputs.tag }} + run: | + set -euo pipefail + image="local/stackstate-k8s-process-agent:${TAG}-${ARCH}" + output="$(docker run --rm \ + --entrypoint /opt/stackstate-agent/bin/agent/process-agent \ + "${image}" -version)" + printf '%s\n' "${output}" + grep -F "Version: ${TAG}" <<< "${output}" + + healthcheck="$(docker image inspect --format '{{json .Config.Healthcheck.Test}}' "${image}")" + grep -F '/probe.sh' <<< "${healthcheck}" + + - name: Scan image with VEX-aware Trivy and Grype + uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + with: + image: local/stackstate-k8s-process-agent:${{ steps.image.outputs.tag }}-${{ matrix.arch }} + mode: gate + severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL + with-grype: true + upload-sarif: false + sarif-category: process-agent-${{ matrix.arch }} + + publish-image: + name: Publish and sign commit image (${{ matrix.arch }}) + needs: image-smoke-and-scan + if: >- + github.event_name == 'push' || + github.event_name == 'workflow_dispatch' || + github.event.pull_request.head.repo.full_name == github.repository + runs-on: ${{ matrix.runner }} + permissions: + contents: read + id-token: write + strategy: + fail-fast: false + matrix: + include: + - arch: amd64 + runner: ubuntu-24.04 + long-arch: x86_64 + llvm-arch: x86_64 + - arch: arm64 + runner: ubuntu-24.04-arm + long-arch: aarch64 + llvm-arch: arm64 + steps: + - name: Check out source commit + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: ${{ github.event.pull_request.head.sha || github.sha }} + persist-credentials: false + + - name: Download process-agent image inputs + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: process-agent-${{ matrix.arch }} + path: . + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd # v4.0.0 + + - name: Resolve image tag + id: image + env: + SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} + run: | + set -euo pipefail + short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" + echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" + + - name: Resolve canonical OCI labels + id: oci + uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + with: + image-name: stackstate-k8s-process-agent + tag: ${{ steps.image.outputs.tag }} + title: SUSE Observability Process Agent + description: Process agent collecting per-process and per-container telemetry for SUSE Observability. + component: stackstate-k8s-process-agent + dockerfile: BCI.dockerfile + base-name: registry.suse.com/bci/bci-micro:15.7 + + - name: Build, publish, and sign architecture image + uses: StackVista/image-pipeline/.github/actions/push-single-arch@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + with: + image: ${{ env.IMAGE }} + tag: ${{ steps.image.outputs.tag }} + arch: ${{ matrix.arch }} + dockerfile: BCI.dockerfile + labels: | + ${{ steps.oci.outputs.labels }} + org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} + build-args: | + EBPF_SUBFOLDER=${{ matrix.llvm-arch }} + LONG_ARCH=${{ matrix.long-arch }} + SHORT_ARCH=${{ matrix.arch }} + target-registry: quay.io + target-registry-user: ${{ vars.QUAY_USER }} + target-registry-password: ${{ secrets.QUAY_PASSWORD }} + + merge-multiarch-manifest: + name: Publish and sign multi-architecture commit image + needs: publish-image + if: >- + github.event_name == 'push' || + github.event_name == 'workflow_dispatch' || + github.event.pull_request.head.repo.full_name == github.repository + runs-on: ubuntu-24.04 + permissions: + contents: read + id-token: write + steps: + - name: Resolve image tag + id: image + env: + SOURCE_SHA: ${{ github.event.pull_request.head.sha || github.sha }} + run: | + set -euo pipefail + short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" + echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" + + - name: Merge and sign multi-architecture manifest + uses: StackVista/image-pipeline/.github/actions/merge-multiarch@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + with: + image: ${{ env.IMAGE }} + tag: ${{ steps.image.outputs.tag }} + target-registry: quay.io + target-registry-user: ${{ vars.QUAY_USER }} + target-registry-password: ${{ secrets.QUAY_PASSWORD }} + + ci-success: + name: Process-agent CI + needs: + - prebuild-datadog-agent + - build-and-test + - image-smoke-and-scan + - publish-image + - merge-multiarch-manifest + if: always() + runs-on: ubuntu-24.04 + permissions: {} + steps: + - name: Verify all required jobs succeeded + env: + NEEDS: ${{ toJSON(needs) }} + run: | + set -euo pipefail + failed="$(jq -r ' + to_entries[] | + select(.value.result != "success" and .value.result != "skipped") | + .key + ' <<< "${NEEDS}")" + if [ -n "${failed}" ]; then + echo "Required process-agent jobs failed:" + printf '%s\n' "${failed}" + exit 1 + fi + echo "All required process-agent jobs passed." diff --git a/packaging/oci-labels.sh b/packaging/oci-labels.sh index 78ca1869..7a835533 100755 --- a/packaging/oci-labels.sh +++ b/packaging/oci-labels.sh @@ -9,7 +9,7 @@ set -euo pipefail product="suse-observability" -source_url="https://gitlab.com/stackvista/agent/stackstate-process-agent" +source_url="https://github.com/StackVista/stackstate-process-agent" documentation_url="https://documentation.suse.com/cloudnative/suse-observability/latest/en/classic.html" readme_url="" image_name="" @@ -108,7 +108,7 @@ fi # is actually pushed to quay.io. Matches apply-oci-labels and OciLabels.compute. ref_name="registry.rancher.com/suse-observability/${image_name}:${tag}" if [[ -z "$readme_url" ]]; then - readme_url="${source_url%/}/-/blob/master/README.md" + readme_url="${source_url%/}/blob/master/README.md" fi revision="${CI_COMMIT_SHA:-$(git rev-parse HEAD)}" source="${CI_PROJECT_URL:-$source_url}" From e9f7548562635eb7c91abaa115e2a1cc46c59769 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:14:48 +0200 Subject: [PATCH 03/17] STAC-25420 Remove invalid process-agent gitlink --- .gitignore | 1 + datadog-agent-workdir | 1 - 2 files changed, 1 insertion(+), 1 deletion(-) delete mode 160000 datadog-agent-workdir diff --git a/.gitignore b/.gitignore index 7151b109..c7ef167b 100644 --- a/.gitignore +++ b/.gitignore @@ -37,5 +37,6 @@ derived.gen.go # Prebuild prebuild_artifacts +datadog-agent-workdir/ ebpf-object-files/ ebpf-object-files-root/ diff --git a/datadog-agent-workdir b/datadog-agent-workdir deleted file mode 160000 index e9f6857a..00000000 --- a/datadog-agent-workdir +++ /dev/null @@ -1 +0,0 @@ -Subproject commit e9f6857a70e633791e5c579c459ae2aaed51619d From 86dc419306f1dfc477204bdb14b98d82f0cb6c87 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:18:53 +0200 Subject: [PATCH 04/17] STAC-25420 Initialize Go in prebuild jobs --- .github/workflows/ci.yml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4e702298..2af5afff 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -51,7 +51,14 @@ jobs: --volume "${GITHUB_WORKSPACE}:/workspace" \ --workdir /workspace \ "${PREBUILD_IMAGE}" \ - bash -lc './prebuild-datadog-agent.sh --generate-no-docker' + bash -lc ' + eval "$(gimme)" + source /root/.bashrc + source /etc/profile + conda activate ddpy3 + set -euo pipefail + ./prebuild-datadog-agent.sh --generate-no-docker + ' - name: Upload prebuild artifacts uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 From d17f3c4eb0539c72f844648ae14cfdba6ccfd74d Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:22:24 +0200 Subject: [PATCH 05/17] STAC-25420 Preserve prebuild image toolchain path --- .github/workflows/ci.yml | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2af5afff..a57a3a57 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -51,11 +51,7 @@ jobs: --volume "${GITHUB_WORKSPACE}:/workspace" \ --workdir /workspace \ "${PREBUILD_IMAGE}" \ - bash -lc ' - eval "$(gimme)" - source /root/.bashrc - source /etc/profile - conda activate ddpy3 + bash -c ' set -euo pipefail ./prebuild-datadog-agent.sh --generate-no-docker ' From 63614e918138f0556dd237d0e2054c7163fa60e0 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:26:35 +0200 Subject: [PATCH 06/17] STAC-25420 Preserve build image toolchain path --- .github/workflows/ci.yml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a57a3a57..69dc4bc5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -113,10 +113,8 @@ jobs: --env GOPATH=/workspace/.go \ --env PROCESS_AGENT_VERSION="${short_sha}" \ "${BUILDER_IMAGE}" \ - bash -lc ' - eval "$(gimme)" + bash -c ' source /root/.bashrc - source /etc/profile conda activate ddpy3 set -euo pipefail export PATH="${GOPATH}/bin:${PATH}" From 698f0a8464e2ac92b0c78d0f37d013ad4a2f8411 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:27:46 +0200 Subject: [PATCH 07/17] STAC-25420 Make prebuild inputs explicit --- .github/workflows/ci.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 69dc4bc5..9029fe7b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -28,9 +28,11 @@ jobs: include: - arch: amd64 runner: ubuntu-24.04 + llvm-arch: x86_64 prebuild-image: quay.io/stackstate/datadog_build_system-probe_x64:61b4ad67 - arch: arm64 runner: ubuntu-24.04-arm + llvm-arch: arm64 prebuild-image: quay.io/stackstate/datadog_build_system-probe_arm64:61b4ad67 steps: - name: Check out source commit @@ -44,12 +46,16 @@ jobs: # supported toolchain and is also used to build the upstream agent fork. - name: Generate DataDog eBPF and Go artifacts env: + LLVM_ARCH: ${{ matrix.llvm-arch }} PREBUILD_IMAGE: ${{ matrix.prebuild-image }} run: | set -euo pipefail docker run --rm \ --volume "${GITHUB_WORKSPACE}:/workspace" \ --workdir /workspace \ + --env LLVM_ARCH="${LLVM_ARCH}" \ + --env OUTPUT_USER_ID="$(id -u)" \ + --env OUTPUT_GROUP_ID="$(id -g)" \ "${PREBUILD_IMAGE}" \ bash -c ' set -euo pipefail From bd64f11ca38305be35547ea7bba7a49cf32f396b Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:40:22 +0200 Subject: [PATCH 08/17] STAC-25420 Accommodate legacy RVM build hooks --- .github/workflows/ci.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9029fe7b..9ba95050 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -122,7 +122,9 @@ jobs: bash -c ' source /root/.bashrc conda activate ddpy3 - set -euo pipefail + # RVM's directory hook reads an unset rvm_saved_env variable. + # Keep fail-fast/pipefail without nounset in this legacy builder. + set -eo pipefail export PATH="${GOPATH}/bin:${PATH}" go mod verify From 3cbf9695fe55b3b90929a95f6ddedc0fb490bdf8 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 07:52:05 +0200 Subject: [PATCH 09/17] STAC-25420 Preserve legacy builder shell quoting --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9ba95050..271e256c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -122,7 +122,7 @@ jobs: bash -c ' source /root/.bashrc conda activate ddpy3 - # RVM's directory hook reads an unset rvm_saved_env variable. + # The RVM directory hook reads an unset rvm_saved_env variable. # Keep fail-fast/pipefail without nounset in this legacy builder. set -eo pipefail export PATH="${GOPATH}/bin:${PATH}" From 7e96bb67636898b973c3a6956fccf5723ca0ca24 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 08:04:54 +0200 Subject: [PATCH 10/17] STAC-25420 Install pinned protobuf generator directly --- .github/workflows/ci.yml | 3 ++- README.md | 6 +++--- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 271e256c..bf2752e3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -128,7 +128,8 @@ jobs: export PATH="${GOPATH}/bin:${PATH}" go mod verify - (cd "$(go list -f "{{ .Dir }}" -m github.com/gogo/protobuf)" && make install) + gogo_version="$(go list -m -f "{{.Version}}" github.com/gogo/protobuf)" + go install "github.com/gogo/protobuf/protoc-gen-gogofaster@${gogo_version}" rake protobuf git diff --exit-code -- model rake ci diff --git a/README.md b/README.md index 939e801f..9f49e7b5 100644 --- a/README.md +++ b/README.md @@ -66,11 +66,11 @@ If you modify any of the `.proto` files you _must_ rebuild the `*.pb.go` files. Make sure protobuf 3.6.1.3 is installed, typically has to be built from source: `https://github.com/protocolbuffers/protobuf/tree/v3.6.1.3` -Make sure you install the gogo-proto binaries from the go mod directory: +Install the gogo-proto generator at the version pinned in `go.mod`: ```bash -cd $GO_PATH/pkg/github.com/gogo/protobuf@1.3.2 -make install +GOGO_PROTOBUF_VERSION="$(go list -m -f '{{.Version}}' github.com/gogo/protobuf)" +go install "github.com/gogo/protobuf/protoc-gen-gogofaster@${GOGO_PROTOBUF_VERSION}" ``` Make sure `$GO_PATH/bin` is in the `PATH`. From 42a7cb226643fdab6bce86976abf6ce62a113730 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 08:17:28 +0200 Subject: [PATCH 11/17] STAC-25420 Download protobuf inputs before generation --- Rakefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Rakefile b/Rakefile index d7d7ba78..77ebe40c 100644 --- a/Rakefile +++ b/Rakefile @@ -131,7 +131,7 @@ task :lint do end desc "Compile the protobuf files for the Process Agent" -task :protobuf do +task :protobuf => [:deps] do protocv = `bash -c "protoc --version"`.strip if protocv != 'libprotoc 3.6.1' fail "Requires protoc version 3.6.1" From 464045ac95f7f081804c10b7d5b9ea42437dc4b0 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 08:58:08 +0200 Subject: [PATCH 12/17] STAC-25420 Set packaged binary executable --- BCI.dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/BCI.dockerfile b/BCI.dockerfile index c242e41c..981f8abd 100644 --- a/BCI.dockerfile +++ b/BCI.dockerfile @@ -37,7 +37,7 @@ COPY process-agent /chroot/opt/stackstate-agent/bin/agent COPY DockerFiles/agent/probe.sh /chroot/ COPY DockerFiles/agent/entrypoint/init-process.sh /chroot/ -RUN chmod 755 /chroot/probe.sh /chroot/init-process.sh && \ +RUN chmod 755 /chroot/probe.sh /chroot/init-process.sh /chroot/opt/stackstate-agent/bin/agent/process-agent && \ chroot /chroot useradd -r -s /sbin/nologin -g root stackstate-agent && \ chroot /chroot chown -R stackstate-agent:root /etc/stackstate-agent /var/log/stackstate-agent && \ rm -rf /chroot/var/cache/zypp /chroot/tmp/* /chroot/var/tmp/* From 39508fc797699867e36414c33a6a28efd13f4748 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 09:32:52 +0200 Subject: [PATCH 13/17] STAC-25420 preserve canonical image identity in scans --- .github/workflows/ci.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index bf2752e3..5ac91f17 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -219,7 +219,7 @@ jobs: labels: | ${{ steps.oci.outputs.labels }} org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} - tags: local/stackstate-k8s-process-agent:${{ steps.image.outputs.tag }}-${{ matrix.arch }} + tags: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} - name: Smoke test packaged process-agent binary env: @@ -227,7 +227,7 @@ jobs: TAG: ${{ steps.image.outputs.tag }} run: | set -euo pipefail - image="local/stackstate-k8s-process-agent:${TAG}-${ARCH}" + image="${IMAGE}:${TAG}-${ARCH}" output="$(docker run --rm \ --entrypoint /opt/stackstate-agent/bin/agent/process-agent \ "${image}" -version)" @@ -240,7 +240,7 @@ jobs: - name: Scan image with VEX-aware Trivy and Grype uses: StackVista/image-pipeline/.github/actions/scan-image@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 with: - image: local/stackstate-k8s-process-agent:${{ steps.image.outputs.tag }}-${{ matrix.arch }} + image: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} mode: gate severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with-grype: true From ceab1459310cf732fb10377397e1d6ada1e0330b Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 10:05:31 +0200 Subject: [PATCH 14/17] STAC-25420 upgrade klauspost compress --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 0b465950..0b35a6b2 100644 --- a/go.mod +++ b/go.mod @@ -407,7 +407,7 @@ require ( github.com/justincormack/go-memfd v0.0.0-20170219213707-6e4af0518993 // indirect github.com/karrick/godirwalk v1.17.0 // indirect github.com/kevinburke/ssh_config v1.2.0 // indirect - github.com/klauspost/compress v1.18.6 // indirect + github.com/klauspost/compress v1.18.7 // indirect github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f // indirect github.com/knqyf263/go-deb-version v0.0.0-20230223133812-3ed183d23422 // indirect github.com/knqyf263/go-rpm-version v0.0.0-20220614171824-631e686d1075 // indirect diff --git a/go.sum b/go.sum index 2e946d98..8889ce54 100644 --- a/go.sum +++ b/go.sum @@ -1049,8 +1049,8 @@ github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+o github.com/kjk/lzma v0.0.0-20161016003348-3fd93898850d h1:RnWZeH8N8KXfbwMTex/KKMYMj0FJRCF6tQubUuQ02GM= github.com/kjk/lzma v0.0.0-20161016003348-3fd93898850d/go.mod h1:phT/jsRPBAEqjAibu1BurrabCBNTYiVI+zbmyCZJY6Q= github.com/klauspost/compress v1.13.6/go.mod h1:/3/Vjq9QcHkK5uEr5lBEmyoZ1iFhe47etQ6QUkpK6sk= -github.com/klauspost/compress v1.18.6 h1:2jupLlAwFm95+YDR+NwD2MEfFO9d4z4Prjl1XXDjuao= -github.com/klauspost/compress v1.18.6/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= +github.com/klauspost/compress v1.18.7 h1:aUyZsS4kH3QTKurYhAOwAHxllVPnOthb3vPfnF1Ehjw= +github.com/klauspost/compress v1.18.7/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= github.com/klauspost/pgzip v1.2.5/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs= github.com/klauspost/pgzip v1.2.6 h1:8RXeL5crjEUFnR2/Sn6GJNWtSQ3Dk8pq4CL3jvdDyjU= github.com/klauspost/pgzip v1.2.6/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs= From 47efb12b72e5861d54876c8335c993ee23e41ab7 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 12:20:24 +0200 Subject: [PATCH 15/17] STAC-25420 address GitHub CI review feedback --- .cerberus/cerberus_block_merges.sh | 26 ---- .cerberus/cerberus_notify_failure.sh | 26 ---- .github/workflows/ci.yml | 61 +--------- .gitlab-ci-arm.yml | 174 --------------------------- .gitlab-ci-docker.yml | 23 ---- .gitlab-ci-x64.yml | 172 -------------------------- .gitlab-ci.yml | 129 -------------------- .gitlab-scripts/set_environment.sh | 19 --- DEVELOPMENT.md | 2 +- packaging/build-and-label.sh | 6 +- scripts/set_environment.sh | 18 +++ 11 files changed, 27 insertions(+), 629 deletions(-) delete mode 100755 .cerberus/cerberus_block_merges.sh delete mode 100755 .cerberus/cerberus_notify_failure.sh delete mode 100644 .gitlab-ci-arm.yml delete mode 100644 .gitlab-ci-docker.yml delete mode 100644 .gitlab-ci-x64.yml delete mode 100644 .gitlab-ci.yml delete mode 100644 .gitlab-scripts/set_environment.sh create mode 100755 scripts/set_environment.sh diff --git a/.cerberus/cerberus_block_merges.sh b/.cerberus/cerberus_block_merges.sh deleted file mode 100755 index 501b4302..00000000 --- a/.cerberus/cerberus_block_merges.sh +++ /dev/null @@ -1,26 +0,0 @@ -#!/usr/bin/env bash - -# This script does a call out to the Cerberus Lambda running in AWS -# The Cerberus code can be found at: https://gitlab.com/stackvista/devops/cerberus - -set -exuo pipefail - -PAYLOAD=$(cat << END_OF_PAYLOAD -{ - "action": "block", - "context": { - "project.id": "$CI_PROJECT_ID", - "project.name": "$CI_PROJECT_TITLE", - "project.slug": "$CI_PROJECT_PATH", - "commit.sha": "$CI_COMMIT_SHA", - "commit.title": "$CI_COMMIT_TITLE", - "branch": "$CI_COMMIT_REF_NAME", - "pipeline": "$CI_PIPELINE_ID", - "suite": "$SUITE", - "channel": "$SLACK_CI_REPORT_CHANNEL" - } -} -END_OF_PAYLOAD -) - -curl --verbose --fail --data "${PAYLOAD?Payload is empty}" "${CERBERUS_LAMBDA_URL?No URL Provided}" diff --git a/.cerberus/cerberus_notify_failure.sh b/.cerberus/cerberus_notify_failure.sh deleted file mode 100755 index 6e363d4b..00000000 --- a/.cerberus/cerberus_notify_failure.sh +++ /dev/null @@ -1,26 +0,0 @@ -#!/usr/bin/env bash - -# This script does a call out to the Cerberus Lambda running in AWS -# The Cerberus code can be found at: https://gitlab.com/stackvista/devops/cerberus - -set -exuo pipefail - -PAYLOAD=$(cat << END_OF_PAYLOAD -{ - "action": "notify", - "context": { - "project.id": "$CI_PROJECT_ID", - "project.name": "$CI_PROJECT_TITLE", - "project.slug": "$CI_PROJECT_PATH", - "commit.sha": "$CI_COMMIT_SHA", - "commit.title": "$CI_COMMIT_TITLE", - "branch": "$CI_COMMIT_REF_NAME", - "pipeline": "$CI_PIPELINE_ID", - "suite": "$SUITE", - "channel": "$SLACK_CI_REPORT_CHANNEL" - } -} -END_OF_PAYLOAD -) - -curl --verbose --fail --data "${PAYLOAD?Payload is empty}" "${CERBERUS_LAMBDA_URL?No URL Provided}" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5ac91f17..f2a0a11e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,8 +17,8 @@ env: IMAGE: quay.io/stackstate/stackstate-k8s-process-agent jobs: - prebuild-datadog-agent: - name: Prebuild DataDog eBPF dependencies (${{ matrix.arch }}) + build-and-test: + name: Prebuild, generated-code check, build, and unit tests (${{ matrix.arch }}) runs-on: ${{ matrix.runner }} permissions: contents: read @@ -30,15 +30,18 @@ jobs: runner: ubuntu-24.04 llvm-arch: x86_64 prebuild-image: quay.io/stackstate/datadog_build_system-probe_x64:61b4ad67 + builder-image: quay.io/stackstate/datadog_build_deb_x64:61b4ad67 - arch: arm64 runner: ubuntu-24.04-arm llvm-arch: arm64 prebuild-image: quay.io/stackstate/datadog_build_system-probe_arm64:61b4ad67 + builder-image: quay.io/stackstate/datadog_build_deb_arm64:61b4ad67 steps: - name: Check out source commit uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: ref: ${{ github.event.pull_request.head.sha || github.sha }} + fetch-depth: 0 persist-credentials: false # A general-purpose BCI builder cannot generate DataDog's eBPF artifacts. @@ -62,44 +65,6 @@ jobs: ./prebuild-datadog-agent.sh --generate-no-docker ' - - name: Upload prebuild artifacts - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: prebuild-${{ matrix.arch }} - path: prebuild_artifacts/artifacts - if-no-files-found: error - retention-days: 1 - - build-and-test: - name: Build, generated-code check, and unit tests (${{ matrix.arch }}) - needs: prebuild-datadog-agent - runs-on: ${{ matrix.runner }} - permissions: - contents: read - strategy: - fail-fast: false - matrix: - include: - - arch: amd64 - runner: ubuntu-24.04 - builder-image: quay.io/stackstate/datadog_build_deb_x64:61b4ad67 - - arch: arm64 - runner: ubuntu-24.04-arm - builder-image: quay.io/stackstate/datadog_build_deb_arm64:61b4ad67 - steps: - - name: Check out source commit - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - with: - ref: ${{ github.event.pull_request.head.sha || github.sha }} - fetch-depth: 0 - persist-credentials: false - - - name: Download prebuild artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 - with: - name: prebuild-${{ matrix.arch }} - path: prebuild_artifacts/artifacts - # The DataDog builder carries the matching compiler, Ruby, conda, LLVM, # and native libraries needed by the fork. There is no equivalent BCI # image that can compile this legacy eBPF dependency graph. @@ -190,18 +155,6 @@ jobs: short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" - - name: Resolve canonical OCI labels - id: oci - uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 - with: - image-name: stackstate-k8s-process-agent - tag: ${{ steps.image.outputs.tag }} - title: SUSE Observability Process Agent - description: Process agent collecting per-process and per-container telemetry for SUSE Observability. - component: stackstate-k8s-process-agent - dockerfile: BCI.dockerfile - base-name: registry.suse.com/bci/bci-micro:15.7 - - name: Build local BCI runtime image uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0 with: @@ -216,9 +169,6 @@ jobs: EBPF_SUBFOLDER=${{ matrix.llvm-arch }} LONG_ARCH=${{ matrix.long-arch }} SHORT_ARCH=${{ matrix.arch }} - labels: | - ${{ steps.oci.outputs.labels }} - org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} tags: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} - name: Smoke test packaged process-agent binary @@ -358,7 +308,6 @@ jobs: ci-success: name: Process-agent CI needs: - - prebuild-datadog-agent - build-and-test - image-smoke-and-scan - publish-image diff --git a/.gitlab-ci-arm.yml b/.gitlab-ci-arm.yml deleted file mode 100644 index 025ae6d8..00000000 --- a/.gitlab-ci-arm.yml +++ /dev/null @@ -1,174 +0,0 @@ -stages: - - prebuild - - build - - test - - publish - -variables: - SRC_PATH: /src/github.com/StackVista/stackstate-process-agent - STS_AWS_BUCKET: stackstate-process-agent-2-test - STS_REPO_BRANCH_NAME: $CI_COMMIT_REF_NAME - PACKAGING_BRANCH: $CI_COMMIT_REF_NAME - STS_DOCKER_REPO: stackstate-k8s-process-agent - GO111MODULE: "on" - QUAY_REGISTRY: quay.io - DOCKER_REGISTRY: docker.io - VERSION_LOGIC: '(if [ "$${CI_COMMIT_TAG}" == "" ]; then echo "$${CI_COMMIT_SHORT_SHA}"; else echo "$${CI_COMMIT_TAG}"; fi);' - LINUX_BUILDER: ${REGISTRY_QUAY_URL}/stackstate/datadog_build_deb_arm64:61b4ad67 - GOPATH: "$CI_PROJECT_DIR/.go" - -.go_process_agent_cache: - cache: &go_cache - key: - files: - - go.mod - - go.sum - prefix: process_agent_${SHORT_ARCH} - paths: - - .go/ - -.go_process_pull_agent_cache: - cache: - <<: *go_cache - # override the policy - policy: pull - -.linux_builder: - image: ${LINUX_BUILDER} - before_script: - - eval "$(gimme)" - - source /root/.bashrc - - source /etc/profile - - conda activate ddpy3 - - export PATH="${GOPATH}/bin:${PATH}" - -dependencies: - extends: [ .linux_builder, .go_process_agent_cache ] - stage: prebuild - needs: [] - tags: - - sts-k8s-xl-arm64-runner - script: - - mkdir -p .go - - go mod download - -prebuild_agent: - cache: - - <<: *go_cache - # override the policy - policy: pull - - key: - files: - - go.mod - - go.sum - prefix: prebuild_datadog_agent_${SHORT_ARCH} - paths: - - prebuild_artifacts/artifacts/* - stage: prebuild - needs: [ dependencies ] - image: ${REGISTRY_QUAY_URL}/stackstate/datadog_build_system-probe_arm64:61b4ad67 - tags: - - sts-k8s-xl-arm64-runner - script: - - ./prebuild-datadog-agent.sh --generate-no-docker - artifacts: - paths: - - prebuild_artifacts/artifacts/* - -test_protobuf_updated: - extends: [ .linux_builder, .go_process_pull_agent_cache ] - stage: test - needs: [ dependencies ] - tags: - - sts-k8s-m-arm64-runner - script: - - (cd $(go list -f '{{ .Dir }}' -m github.com/gogo/protobuf); make install) - - rake protobuf - - '[[ ! `git status --porcelain` ]] || (echo "ERROR: protobuf should be regenerated and committed" && git diff && false)' - -build_linux: - extends: [ .linux_builder, .go_process_pull_agent_cache ] - stage: build - needs: [ dependencies, prebuild_agent ] - script: - - export PROCESS_AGENT_VERSION=$(eval $VERSION_LOGIC) - - printenv - - rake build - - ./prebuild-datadog-agent.sh --install-ebpf - artifacts: - paths: - - $CI_PROJECT_DIR/process-agent - - $CI_PROJECT_DIR/ebpf-object-files - expire_in: 2 week - tags: - - sts-k8s-xl-arm64-runner - retry: - max: 2 - when: - - always - -test: - extends: [ .linux_builder, .go_process_pull_agent_cache ] - stage: test - needs: [ dependencies, prebuild_agent ] - script: - - printenv - - rake ci - tags: - - sts-k8s-xl-arm64-runner - retry: - max: 2 - when: - - always - -publish_binaries: - stage: publish - tags: - - sts-k8s-m-arm64-runner - extends: [ .linux_builder, .go_process_pull_agent_cache ] - needs: - - build_linux - script: - - export PROCESS_AGENT_VERSION=$(eval $VERSION_LOGIC) - - ls -la $CI_PROJECT_DIR - - ls -la $CI_PROJECT_DIR/packaging - - cd $CI_PROJECT_DIR/packaging && ./publish_staging_package.sh - -.docker_build: - image: ${REGISTRY_DOCKER_URL}/library/docker:20 - services: - - name: ${REGISTRY_DOCKER_URL}/library/docker:20-dind - alias: docker - variables: - DOCKER_DRIVER: overlay - DOCKER_HOST: tcp://docker:2375 - DOCKER_TLS_CERTDIR: "" - before_script: - - docker login -u "${docker_user}" -p "${docker_password}" "${DOCKER_REGISTRY}" - - docker login -u "${quay_user}" -p "${quay_password}" "${QUAY_REGISTRY}" - # bash + mapfile is required by packaging/build-and-label.sh; the docker:20 - # image is Alpine and only ships ash by default. - - apk add --no-cache bash - -.publish_linux_docker: - extends: [ .docker_build ] - stage: publish - needs: - - build_linux - - prebuild_agent - script: - - export BUILD_TAG="${REPO}:${TAG}" - - export EBPF_SUBFOLDER="$LLVM_ARCH" - - bash ./packaging/build-and-label.sh - - ./packaging/publish_image.sh $BUILD_TAG $REPO $TAG $EXTRA_TAG - -publish_k8s_docker: - extends: [ .publish_linux_docker ] - # Arm builders are spot nodes, so we add retries - retry: 2 - tags: - - sts-k8s-xl-arm64-runner - variables: - REPO: $STS_DOCKER_REPO - TAG: "$CI_COMMIT_REF_SLUG-$SHORT_ARCH" - EXTRA_TAG: $CI_COMMIT_SHORT_SHA-$SHORT_ARCH diff --git a/.gitlab-ci-docker.yml b/.gitlab-ci-docker.yml deleted file mode 100644 index acf8824d..00000000 --- a/.gitlab-ci-docker.yml +++ /dev/null @@ -1,23 +0,0 @@ -variables: - DOCKER_DRIVER: overlay2 - DOCKER_HOST: tcp://docker:2375 - DOCKER_TLS_CERTDIR: "" - -services: - - alias: docker - command: - - --experimental - - --tls=false - name: ${REGISTRY_DOCKER_URL}/library/docker:20-dind - -stages: - - merge-manifest - - acceptance - -merge-manifest: - stage: merge-manifest - image: ${REGISTRY_DOCKER_URL}/library/docker:20-git - script: - - echo "${quay_password}" | docker login --username=${quay_user} --password-stdin quay.io - - docker manifest create "${DST_REPOSITORY}:${DST_TAG}" --amend "${DST_REPOSITORY}:${DST_TAG}-amd64" --amend "${DST_REPOSITORY}:${DST_TAG}-arm64" - - docker manifest push "${DST_REPOSITORY}:${DST_TAG}" diff --git a/.gitlab-ci-x64.yml b/.gitlab-ci-x64.yml deleted file mode 100644 index eb4ad773..00000000 --- a/.gitlab-ci-x64.yml +++ /dev/null @@ -1,172 +0,0 @@ -stages: - - prebuild - - build - - test - - publish - -variables: - SRC_PATH: /src/github.com/StackVista/stackstate-process-agent - STS_AWS_BUCKET: stackstate-process-agent-2-test - STS_REPO_BRANCH_NAME: $CI_COMMIT_REF_NAME - PACKAGING_BRANCH: $CI_COMMIT_REF_NAME - STS_DOCKER_REPO: stackstate-k8s-process-agent - GO111MODULE: "on" - QUAY_REGISTRY: quay.io - DOCKER_REGISTRY: docker.io - VERSION_LOGIC: '(if [ "$${CI_COMMIT_TAG}" == "" ]; then echo "$${CI_COMMIT_SHORT_SHA}"; else echo "$${CI_COMMIT_TAG}"; fi);' - LINUX_BUILDER: ${REGISTRY_QUAY_URL}/stackstate/datadog_build_deb_x64:61b4ad67 - GOPATH: "$CI_PROJECT_DIR/.go" - -.go_process_agent_cache: - cache: &go_cache - key: - files: - - go.mod - - go.sum - prefix: process_agent_${SHORT_ARCH} - paths: - - .go/ - -.go_process_pull_agent_cache: - cache: - <<: *go_cache - # override the policy - policy: pull - -.linux_builder: - image: ${LINUX_BUILDER} - before_script: - - eval "$(gimme)" - - source /root/.bashrc - - source /etc/profile - - conda activate ddpy3 - - export PATH="${GOPATH}/bin:${PATH}" - -dependencies: - extends: [ .linux_builder, .go_process_agent_cache ] - stage: prebuild - needs: [] - tags: - - sts-k8s-xl-runner - script: - - mkdir -p .go - - go mod download - -prebuild_agent: - cache: - - <<: *go_cache - # override the policy - policy: pull - - key: - files: - - go.mod - - go.sum - prefix: prebuild_datadog_agent_${SHORT_ARCH} - paths: - - prebuild_artifacts/artifacts/* - stage: prebuild - needs: [ dependencies ] - image: ${REGISTRY_QUAY_URL}/stackstate/datadog_build_system-probe_x64:61b4ad67 - tags: - - sts-k8s-xl-runner - script: - - ./prebuild-datadog-agent.sh --generate-no-docker - artifacts: - paths: - - prebuild_artifacts/artifacts/* - -test_protobuf_updated: - extends: [ .linux_builder, .go_process_pull_agent_cache ] - stage: test - needs: [ dependencies ] - tags: - - sts-k8s-m-runner - script: - - (cd $(go list -f '{{ .Dir }}' -m github.com/gogo/protobuf); make install) - - rake protobuf - - '[[ ! `git status --porcelain` ]] || (echo "ERROR: protobuf should be regenerated and committed" && git diff && false)' - -build_linux: - extends: [ .linux_builder, .go_process_pull_agent_cache ] - stage: build - needs: [ dependencies, prebuild_agent ] - script: - - export PROCESS_AGENT_VERSION=$(eval $VERSION_LOGIC) - - printenv - - rake build - - ./prebuild-datadog-agent.sh --install-ebpf - artifacts: - paths: - - $CI_PROJECT_DIR/process-agent - - $CI_PROJECT_DIR/ebpf-object-files - expire_in: 2 week - tags: - - sts-k8s-xl-runner - retry: - max: 2 - when: - - always - -test: - extends: [ .linux_builder, .go_process_pull_agent_cache ] - stage: test - needs: [ dependencies, prebuild_agent ] - script: - - printenv - - rake ci - tags: - - sts-k8s-xl-runner - retry: - max: 2 - when: - - always - -publish_binaries: - stage: publish - tags: - - sts-k8s-m-runner - extends: [ .linux_builder, .go_process_pull_agent_cache ] - needs: - - build_linux - script: - - export PROCESS_AGENT_VERSION=$(eval $VERSION_LOGIC) - - ls -la $CI_PROJECT_DIR - - ls -la $CI_PROJECT_DIR/packaging - - cd $CI_PROJECT_DIR/packaging && ./publish_staging_package.sh - -.docker_build: - image: ${REGISTRY_DOCKER_URL}/library/docker:20 - services: - - name: ${REGISTRY_DOCKER_URL}/library/docker:20-dind - alias: docker - variables: - DOCKER_DRIVER: overlay - DOCKER_HOST: tcp://docker:2375 - DOCKER_TLS_CERTDIR: "" - before_script: - - docker login -u "${docker_user}" -p "${docker_password}" "${DOCKER_REGISTRY}" - - docker login -u "${quay_user}" -p "${quay_password}" "${QUAY_REGISTRY}" - # bash + mapfile is required by packaging/build-and-label.sh; the docker:20 - # image is Alpine and only ships ash by default. - - apk add --no-cache bash - -.publish_linux_docker: - extends: [ .docker_build ] - stage: publish - needs: - - build_linux - - prebuild_agent - script: - - export BUILD_TAG="${REPO}:${TAG}" - - export EBPF_SUBFOLDER="$LLVM_ARCH" - - bash ./packaging/build-and-label.sh - - ./packaging/publish_image.sh $BUILD_TAG $REPO $TAG $EXTRA_TAG - -publish_k8s_docker: - extends: [ .publish_linux_docker ] - tags: - - sts-k8s-m-runner - variables: - REPO: $STS_DOCKER_REPO - TAG: "$CI_COMMIT_REF_SLUG-$SHORT_ARCH" - EXTRA_TAG: $CI_COMMIT_SHORT_SHA-$SHORT_ARCH diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml deleted file mode 100644 index 91ed9a05..00000000 --- a/.gitlab-ci.yml +++ /dev/null @@ -1,129 +0,0 @@ -stages: - - triggers - - postbuild - - report - -agent_x86_64: - stage: triggers - variables: - LONG_ARCH: x86_64 - SHORT_ARCH: amd64 - LLVM_ARCH: x86_64 - trigger: - include: .gitlab-ci-x64.yml - strategy: depend - rules: - - when: always - - -agent_arm64: - stage: triggers - variables: - LONG_ARCH: aarch64 - SHORT_ARCH: arm64 - LLVM_ARCH: arm64 - trigger: - include: .gitlab-ci-arm.yml - strategy: depend - rules: - - when: always - -.merge_docker_manifest: &merge_docker_manifest - stage: postbuild - needs: [ agent_x86_64, agent_arm64 ] - trigger: - include: .gitlab-ci-docker.yml - strategy: depend - rules: - - when: on_success - -merge_k8s_docker_manifest: - <<: *merge_docker_manifest - variables: - DST_REPOSITORY: quay.io/stackstate/stackstate-k8s-process-agent - DST_TAG: "$CI_COMMIT_REF_SLUG" - -merge_extra_k8s_docker_manifest: - <<: *merge_docker_manifest - variables: - DST_REPOSITORY: quay.io/stackstate/stackstate-k8s-process-agent - DST_TAG: "$CI_COMMIT_SHORT_SHA" - -beest_k8s_1_33_containerd_trigger_verification: - stage: postbuild - needs: [ merge_extra_k8s_docker_manifest ] - variables: - PROCESS_AGENT_BRANCH_UNDER_TEST: "$CI_COMMIT_REF_NAME" - PROCESS_AGENT_HASH_UNDER_TEST: "$CI_COMMIT_SHORT_SHA" - TRIGGER_AGENT_X86_TESTS: "true" - rules: - - if: $CI_COMMIT_REF_NAME == "master" - when: manual - allow_failure: true - - if: $CI_COMMIT_BRANCH - when: manual - allow_failure: true - trigger: - project: stackvista/integrations/beest - -notify-on-master-fail: - before_script: - - apk add --no-cache bash curl - image: ${REGISTRY_DOCKER_URL}/library/alpine:latest - only: - - master - script: - - SUITE=build ./.cerberus/cerberus_notify_failure.sh - stage: report - tags: - - sts-k8s-m-runner - when: on_failure - -########################### -# Job to manage pushing images to Quay -########################## -# To run this job you need to specify 2 variables: -# SOURCE_IMAGE: the full URL of the image you want to push to Quay `(e.g. docker.io/stackstate/stackstate-k8s-process-agent:latest-amd64)` -# QUAY_IMAGE: the full URL of the destination image on Quay `(e.g. quay.io/stackstate/stackstate-k8s-process-agent:latest-amd64)` -push_image_to_quay: - stage: postbuild - image: ${REGISTRY_DOCKER_URL}/library/docker:20 - services: - - alias: docker - command: - - --experimental - - --tls=false - name: ${REGISTRY_DOCKER_URL}/library/docker:20-dind - variables: - # We cannot access the host docker socket in GitLab CI, so we need to use the Docker-in-Docker service - DOCKER_DRIVER: overlay2 - DOCKER_HOST: tcp://docker:2375 - DOCKER_TLS_CERTDIR: "" - script: - - | - if [ ! -f remote-kube-cache-push.env ]; then - echo "remote-kube-cache-push.env file not found!"; exit 1; - fi - set -o allexport - source remote-kube-cache-push.env - set +o allexport - if [ -z "$SOURCE_IMAGE" ]; then - echo "SOURCE_IMAGE not set" - exit 1 - fi - if [ -z "$QUAY_IMAGE" ]; then - echo "QUAY_IMAGE not set" - exit 1 - fi - echo "Login to Quay.io..." - echo "${quay_password}" | docker login --username=${quay_user} --password-stdin quay.io - echo "Pull source image: $SOURCE_IMAGE" - docker pull "$SOURCE_IMAGE" - echo "Tag image for Quay: $QUAY_IMAGE" - docker tag "$SOURCE_IMAGE" "$QUAY_IMAGE" - echo "Push to Quay: $QUAY_IMAGE" - docker push "$QUAY_IMAGE" - rules: - - if: $CI_COMMIT_BRANCH == "master" - when: manual - allow_failure: true diff --git a/.gitlab-scripts/set_environment.sh b/.gitlab-scripts/set_environment.sh deleted file mode 100644 index 66c5bc4a..00000000 --- a/.gitlab-scripts/set_environment.sh +++ /dev/null @@ -1,19 +0,0 @@ -#! /bin/bash - -export COMPOSE_INTERACTIVE_NO_CLI=1 - -# -export CURRENT_BRANCH=${CI_COMMIT_REF_NAME:-$(git rev-parse --abbrev-ref HEAD)} -echo "CURRENT_BRANCH set to: $CURRENT_BRANCH" -# Docker host can be retrieved by inspecting the routing table and getting the default gateway (i.e. for route -# destination 0.0.0.0). - -# /proc/net/route contains this in hex format, so extract this first with awk and then convert that to an actual ip-address - -hexaddr=$(awk '$2 == "00000000" {print $3}' /proc/net/route | head -n 1) -ipaddr=$(printf "%d." $( - echo $hexaddr | sed 's/../0x& /g' | tr ' ' '\n' | tac - ) | sed 's/\.$/\n/') - -export DOCKER_HOST_IP=$ipaddr -echo "DOCKER_HOST_IP set to: ${DOCKER_HOST_IP}" \ No newline at end of file diff --git a/DEVELOPMENT.md b/DEVELOPMENT.md index 364cb2c4..17c4582d 100644 --- a/DEVELOPMENT.md +++ b/DEVELOPMENT.md @@ -2,7 +2,7 @@ ### Setup an environment ```bash -source ./.gitlab-scripts/set_environment.sh +source ./scripts/set_environment.sh export DOCKER_HOST_IP=localhost && echo "DOCKER_HOST_IP overriden to: ${DOCKER_HOST_IP}" PROJECT_DIR=`pwd` ``` diff --git a/packaging/build-and-label.sh b/packaging/build-and-label.sh index 7f4f7ec0..110e45e1 100755 --- a/packaging/build-and-label.sh +++ b/packaging/build-and-label.sh @@ -2,9 +2,9 @@ # Wrapper around `docker build` for stackstate-k8s-process-agent that splices # canonical SUSE Observability OCI labels via packaging/oci-labels.sh. # -# Replaces the previous inline docker build line in .gitlab-ci-x64.yml and -# .gitlab-ci-arm.yml so the same recipe runs identically on both arches. The -# base image label is derived from BCI.dockerfile by oci-labels.sh itself. +# Keeps the architecture-specific image build recipe available to local and +# legacy automation. The base image label is derived from BCI.dockerfile by +# oci-labels.sh itself. # # Required env (exported by the CI job): # BUILD_TAG — full repo:tag for the local build (e.g. stackstate-k8s-process-agent:foo-amd64) diff --git a/scripts/set_environment.sh b/scripts/set_environment.sh new file mode 100755 index 00000000..7d9f8e39 --- /dev/null +++ b/scripts/set_environment.sh @@ -0,0 +1,18 @@ +#!/usr/bin/env bash + +export COMPOSE_INTERACTIVE_NO_CLI=1 + +export CURRENT_BRANCH=${GITHUB_HEAD_REF:-${GITHUB_REF_NAME:-${CI_COMMIT_REF_NAME:-$(git rev-parse --abbrev-ref HEAD)}}} +echo "CURRENT_BRANCH set to: $CURRENT_BRANCH" + +# /proc/net/route contains the default gateway in little-endian hexadecimal. +hexaddr=$(awk '$2 == "00000000" {print $3}' /proc/net/route | head -n 1) +gateway_octets=() +for ((i = ${#hexaddr}; i > 0; i -= 2)); do + gateway_octets+=("0x${hexaddr:i-2:2}") +done +printf -v ipaddr "%d." "${gateway_octets[@]}" +ipaddr=${ipaddr%.} + +export DOCKER_HOST_IP=$ipaddr +echo "DOCKER_HOST_IP set to: ${DOCKER_HOST_IP}" From 6b1848a587fd4eb3bbbd51442ba7c9f5fcb2a095 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 12:40:13 +0200 Subject: [PATCH 16/17] STAC-25420 preserve VEX product identity in local scans --- .github/workflows/ci.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f2a0a11e..98e7a8a0 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -155,6 +155,20 @@ jobs: short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" + # Image-scoped OpenVEX statements match the canonical OCI product + # identity, even though this architecture image remains local. + - name: Resolve canonical OCI labels + id: oci + uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 + with: + image-name: stackstate-k8s-process-agent + tag: ${{ steps.image.outputs.tag }} + title: SUSE Observability Process Agent + description: Process agent collecting per-process and per-container telemetry for SUSE Observability. + component: stackstate-k8s-process-agent + dockerfile: BCI.dockerfile + base-name: registry.suse.com/bci/bci-micro:15.7 + - name: Build local BCI runtime image uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0 with: @@ -169,6 +183,9 @@ jobs: EBPF_SUBFOLDER=${{ matrix.llvm-arch }} LONG_ARCH=${{ matrix.long-arch }} SHORT_ARCH=${{ matrix.arch }} + labels: | + ${{ steps.oci.outputs.labels }} + org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} tags: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} - name: Smoke test packaged process-agent binary From eed627d9b371584156c183d392c1e4c1b54e76b7 Mon Sep 17 00:00:00 2001 From: Louis Lotter Date: Tue, 28 Jul 2026 13:01:24 +0200 Subject: [PATCH 17/17] STAC-25420 bridge unpublished image VEX matching --- .github/workflows/ci.yml | 18 +----------------- exceptions/GO-2026-5932.yaml | 26 ++++++++++++++++++++++++++ 2 files changed, 27 insertions(+), 17 deletions(-) create mode 100644 exceptions/GO-2026-5932.yaml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 98e7a8a0..d2b5691c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -155,20 +155,6 @@ jobs: short_sha="$(printf '%s' "${SOURCE_SHA}" | cut -c1-8)" echo "tag=${short_sha}" >> "${GITHUB_OUTPUT}" - # Image-scoped OpenVEX statements match the canonical OCI product - # identity, even though this architecture image remains local. - - name: Resolve canonical OCI labels - id: oci - uses: StackVista/image-pipeline/.github/actions/apply-oci-labels@6284a6fc006a7cc46a7f00d02c50d5f21b117b63 - with: - image-name: stackstate-k8s-process-agent - tag: ${{ steps.image.outputs.tag }} - title: SUSE Observability Process Agent - description: Process agent collecting per-process and per-container telemetry for SUSE Observability. - component: stackstate-k8s-process-agent - dockerfile: BCI.dockerfile - base-name: registry.suse.com/bci/bci-micro:15.7 - - name: Build local BCI runtime image uses: docker/build-push-action@bcafcacb16a39f128d818304e6c9c0c18556b85f # v7.1.0 with: @@ -183,9 +169,6 @@ jobs: EBPF_SUBFOLDER=${{ matrix.llvm-arch }} LONG_ARCH=${{ matrix.long-arch }} SHORT_ARCH=${{ matrix.arch }} - labels: | - ${{ steps.oci.outputs.labels }} - org.opencontainers.image.revision=${{ github.event.pull_request.head.sha || github.sha }} tags: ${{ env.IMAGE }}:${{ steps.image.outputs.tag }}-${{ matrix.arch }} - name: Smoke test packaged process-agent binary @@ -211,6 +194,7 @@ jobs: mode: gate severity: UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL with-grype: true + exceptions-path: exceptions upload-sarif: false sarif-category: process-agent-${{ matrix.arch }} diff --git a/exceptions/GO-2026-5932.yaml b/exceptions/GO-2026-5932.yaml new file mode 100644 index 00000000..d6ef718b --- /dev/null +++ b/exceptions/GO-2026-5932.yaml @@ -0,0 +1,26 @@ +schema_version: "1" +vulnerability: + id: GO-2026-5932 + severity: UNKNOWN +product: + consumer: stackstate-process-agent + image: quay.io/stackstate/stackstate-k8s-process-agent +component: + purl: pkg:golang/golang.org/x/crypto@v0.53.0 + paths: + - opt/stackstate-agent/bin/agent/process-agent +status: accepted_with_compensating_control +reason: unpublished_image_vex_identity_bridge +expires: 2026-08-11 +owner: "@StackVista/observability-team" +upstream_owner: golang +upstream_reference: https://pkg.go.dev/vuln/GO-2026-5932 +statement: | + The affected openpgp and openpgp/clearsign packages are absent from the + process-agent command dependency graph. StackVista/vexhub contains the + reviewed image-scoped not_affected statement, but Grype and Trivy require an + exact image digest or tag to match an image product. This pre-publication + scan uses a newly built commit image whose identity cannot be present in the + VEX hub in advance. Keep this bridge only until the scan pipeline can apply + the reviewed statement to unpublished images without broadening it to every + consumer of golang.org/x/crypto.