Skip to content

CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java - #6257

Merged
mary-georgiou merged 1 commit into
masterfrom
CLP-918
Oct 5, 2026
Merged

mary-georgiou merged 1 commit into
masterfrom
CLP-918

Conversation

@guillaume-dequenne

@guillaume-dequenne guillaume-dequenne commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Part of CLP-918

Summary

  • Route Maven dependency resolution and Orchestrator downloads through the dev JFrog Edge (https://repox-internal.dev.sonar.build). build-maven and config-maven in build.yml and unified-dogfooding.yml receive the Edge repox-url. The existing shared action references stay at @v2.
  • The Edge URL selects the Edge reader-token path in Vault, so these jobs need no SaaS-to-Edge token federation wait. Publishing and promotion continue to use SaaS Artifactory.
  • Orchestrator 6.4.3 reads ARTIFACTORY_URL and ARTIFACTORY_ACCESS_TOKEN from the configured environment. Master already contains sonar-scanner-integration-tester 1.3.0.1396, whose bundled Orchestrator is 6.4.3; this PR no longer changes that dependency.

Validation

  • Rebased onto current master. The final diff has one commit adding only eight repox-url inputs across the two workflows; git diff --check passes.
  • Build on the final @v2 head: build, Windows unit and scanner integration tests, plugin QA, ruling QA, and Test Analyze passed. The first analysis attempt received HTTP 503 from the Sonar server at /api/server/version; the rerun passed.

@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Migrate Orchestrator downloads to the JFrog Edge node for sonar-java CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java Sep 28, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

CLP-1097

@datadog-sonarsource

datadog-sonarsource Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Pipelines

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: a01053a | Docs | View more details | Give us feedback!

Comment thread .github/actions/wait-for-artifactory-token-federation/action.yml Outdated
Comment thread .github/workflows/build.yml Outdated
Comment thread .github/workflows/build.yml Outdated
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

❌ Ruling needs updating. A fix PR has been created: #6290

Please review and merge it into your branch.

Comment thread .github/workflows/build.yml Outdated
with:
version: 2026.9.17
- uses: SonarSource/ci-github-actions/build-maven@v2
- uses: SonarSource/ci-github-actions/build-maven@c3a85ac3a2f67f86966e2fb1fdf9a7c1bdc997dc # 2.2.0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For our actions we should point to the tag.
External actions point to hash.

@guillaume-dequenne guillaume-dequenne Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Superseded by the correction below.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correction to my earlier reply: the final PR keeps the existing @v2 references. The v2 branch currently includes the 2.2.0 release and its Edge support. The final diff only adds the Edge repox-url inputs.

@mary-georgiou mary-georgiou left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mary-georgiou
mary-georgiou enabled auto-merge (squash) October 5, 2026 12:20
@gitar-bot

gitar-bot Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Code Review ✅ Approved 3 closed / 3 findings

🟡 Medium risk · CI dependency and Orchestrator downloads now resolve through a different artifact endpoint.

Routes Maven dependency resolution and Orchestrator downloads through the JFrog Edge node by configuring repox-url across build workflows. Probe curl timeout, unified-dogfooding.yml Edge configuration, and PR description updates were addressed.

✅ 3 closed
✅ Edge Case: Probe curl has no timeout, so the 2-minute bound can be exceeded

📄 .github/actions/wait-for-artifactory-token-federation/action.yml:22-36
The retry loop assumes each attempt is fast: 12 × 10s sleeps, and the failure message says "within 2 minutes". The curl call sets no --connect-timeout or --max-time, though. curl's default connect timeout is 300s and it has no default overall limit, so a slow or unresponsive Edge node can hold one attempt for minutes or indefinitely. The ruling-qa and plugin-qa jobs then stall until the job timeout, and the 2-minute message doesn't match the real behaviour. The 000 retry branch is meant to handle an unreachable Edge, but it only runs after curl returns. Adding per-attempt timeouts fixes this.

✅ Quality: unified-dogfooding.yml still uses build-maven@v2 without the Edge repox-url

📄 .github/workflows/build.yml:37-42
This commit moves every Maven step in build.yml to ci-github-actions@c3a85ac… (v2.2.0) with repox-url: https://repox-internal.dev.sonar.build. .github/workflows/unified-dogfooding.yml:19 still uses the floating build-maven@v2 with the same private-reader/qa-deployer roles and no repox-url, so it keeps resolving through repox.jfrog.io. pr-cleanup.yml also stays on the floating @v2. Nothing in the repo shows this is deliberate. Either apply the same pin and repox-url there, or document why dogfooding should stay on the public Repox.

✅ Quality: PR description no longer matches the code: token-wait and #353 were dropped

📄 .github/workflows/build.yml:95-97 📄 .github/workflows/build.yml:109-123 📄 .github/workflows/build.yml:215-217 📄 .github/workflows/build.yml:229-237
The description says both jobs "wait for token federation", use the shared action from SonarSource/ci-github-actions#353, and that #353 must be merged and repinned before this PR merges. Commit dca4538 removed both wait-for-artifactory-token-federation steps and the explicit -Dorchestrator.artifactory.* flags. Orchestrator now reads ARTIFACTORY_URL/ARTIFACTORY_ACCESS_TOKEN from config-maven@v2.2.0 with repox-url set, and every ci-github-actions step is pinned to v2.2.0. Reviewers and mergers following the description would wait on an unrelated upstream PR, and they would expect a federation wait that the code no longer has. Update the summary, validation and merge-order notes to describe the Edge-issued-token approach.

Review coverage

🧪 Functional validation 1 of 1 objectives covered

📋 Rules No rules evaluated

🤖 Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ CLP-918 - 1 of 1 objectives covered

This PR covers migrating the Orchestrator's SonarQube download source to the JFrog Edge node.

✅ 1 covered here
  • ✅ Migrate the Orchestrator's SonarQube download source to the JFrog Edge node
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqube-next

sonarqube-next Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@mary-georgiou
mary-georgiou merged commit 9af9747 into master Oct 5, 2026
31 of 32 checks passed
@mary-georgiou
mary-georgiou deleted the CLP-918 branch October 5, 2026 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants