Repository navigation
Merge/develop into main - #588
Merged
Merged
Conversation
* Update dependency prism-api to v1.30.0-723.v97277866cece * Update dependency credentials-binding to v720 * Update dependency script-security to v1402 * Add ContentLoaderTest, remove obsolete test folder ../features * introduce sane defaults for renovate * Fix bug rollout with operator-mandants profile * Fix test JsonConfigurationGenerator * Fix ScmManagerSetup * Fix unit tests * Add missing unit tests * Fiy unit test ArgoCD by using deployer instead of helmCommands * Fiy unit test compile errors * Fiy unit test ArgoCDTest by removing test for repoUrl with prefix, because this is tested already by ScmManagerUrlResolver * Renaming values file in template back to values.ftl.yaml; Fix ArgoCDTest and remove test for prefix in repoURL(tested by ScmManagerUrlResolver) * Fix Jenkins unit tests and some of ArgoCDTest * Fix ArgoCDTest with email address * Fix RegistryTest * Fix ContentLoaderTest and comment out airgapped-mode test in ArgoCDTest * Fix ArgoCDTest * Fix link * Delete obsolete test * Rename integration/features to integration/tools * Remove installOperator parameter from Config and ConfigConstants * Fix deployHelmChart: add missing repoURL etc. * Refactor SCM-Manager bootstrap orchestration Move internal SCM-Manager deployment and setup out of GitHandler into ScmManagerTool. GitHandler is now responsible only for validating SCM configuration, preparing Git providers, and creating repositories for external SCM providers. ScmManagerTool now owns the SCM-Manager namespace, performs the initial Helm deployment, waits for SCM-Manager to become available, configures it, creates required GitOps repositories, and creates the ArgoCD Application after repository creation to fix the bootstrap order. This also ensures the scm-manager namespace is collected as a managed namespace for ArgoCD operator mode and prevents other tools from deploying before a Git provider is available. * Fix unit test ApplicationTest * Fix "delete file fail" by monitoring dashboard * Fix unit test ArgoCDRepoSetupTest * Remove install-operator script * Remove unused argo-helm chart * reformat code * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: David Daehne <47227343+DerDaehne@users.noreply.github.com> * Rename ScmManager to ScmManagerProvider in infrastructure/git; rename ScmManagerTool to ScmManager * Rename Gitlab to GitlabProvider; use assertFalse in unit tests * use ?. only for optional values * Add unit test for Deployer --------- Co-authored-by: Renovate Bot <renovate@whitesourcesoftware.com> Co-authored-by: David Daehne <47227343+DerDaehne@users.noreply.github.com> Co-authored-by: Anna Vetcininova <anna.vetcininova@cloudogu.com> Co-authored-by: David Daehne <david.daehne@cloudogu.com> Co-authored-by: avetgit <111436035+avetgit@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Introduce SonarQube scans for code quality analysis
#505) * get config-map from right namespace * fix k8sClient unit test * Configure ArgoCD annotation-based resource tracking to prevent cross-namespace pruning * Use tenant-specific SCM Manager release names * Add logs * Use prefixed SCM Manager release names for tenant setups and add logs in GitHandler * Fix unit tests * Fix unit test ScmManagerSetupTest * Fix ScmManagerSetup releasename with prefix by avoiding double -- (prefix--scmm) * Deploy SCM Manager without self-referencing values source * Prefix tenant SCM Manager ArgoCD application names * Clarify repository setup guard for internal SCM bootstrap * Clarify inline values logging for bootstrap deployments * Fix compile Error * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
* Fix SCM-Manager URL resolution for tenant and central providers Resolve SCM-Manager service names and namespaces using a provider-specific service prefix instead of the tenant application's global name prefix. Previously, the SCM-Manager URL resolver always used `config.application.namePrefix` when building internal service URLs. In dedicated multi-tenant setups this caused the central SCM-Manager provider to be resolved with the tenant prefix, producing URLs such as `t3-scmm.t3-scm-manager.svc.cluster.local` instead of the central `scmm.scm-manager.svc.cluster.local`. This broke tenant bootstrap generation because central Argo CD tried to load the tenant cluster-resources repository from the tenant SCM-Manager instead of the central SCM-Manager. Tenant SCM providers now receive the tenant service prefix, while central SCM providers are resolved independently. This keeps tenant SCM URLs prefixed and central SCM URLs stable. * Fix ScmManagerProviderTest and ScmManagerUrlResolverTest * Fix prefixed central SCM-Manager lookup Resolve the central SCM-Manager service name correctly when the central GOP was installed with a name prefix, e.g. `my-prefix-scmm` in `my-prefix-scm-manager`.
* Update dependency prism-api to v1.30.0-723.v97277866cece * Update dependency credentials-binding to v720 * Update dependency script-security to v1402 * introduce sane defaults for renovate * Fix a regression resulting in GOP not able to find its config when running in sub-mandant (#506) * get config-map from right namespace * fix k8sClient unit test * bump micronaut version to 4.10.16 * small adoptions and more loginfo --------- Co-authored-by: Anna Vetcininova <anna.vetcininova@cloudogu.com> Co-authored-by: Thomas Michael <thomas.michael@cloudogu.com> * update tools.jackson.core dependencies for jackson-databind because of CVEs * add jackson-core dependency to pom because of CVEs * add jackson-databind dependency to pom because of CVEs * this new step scans the code quality with sonarqube * This PR updates K8sClient to resolve custom resources via the Kubernetes Discovery API (#512) * update implementation to resolve custom resource definitions via discovery API to avoid cluster-wide list permissions. * Change Exceptiontype for better information Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * better logging information Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Renovate Bot <renovate@whitesourcesoftware.com> Co-authored-by: David Daehne <47227343+DerDaehne@users.noreply.github.com> Co-authored-by: David Daehne <david.daehne@cloudogu.com> Co-authored-by: Anna Vetcininova <anna.vetcininova@cloudogu.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* start impl image for SCM-M * support custom Jenkins and SCM-Manager images * Apply suggestions from code review Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fix: nest SCM-Manager cert-manager values under ingress * fix: skip Jenkins image pull secrets for external deployments * add code-format instruction to exclude format types * Fix Jenkins rerun after failed integration tests * Use latest tags for mirrored dev core images * Fix Jenkins plugin lock cleanup * Update src/main/groovy/com/cloudogu/gitops/tools/core/Jenkins.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Revert "Update src/main/groovy/com/cloudogu/gitops/tools/core/Jenkins.groovy" This reverts commit f45cd15. * remove unit test permissions change in jenkinsfile * Avoid parallel Sonar scan during unit test report publishing --------- Co-authored-by: Thomas Michael <thomas.michael@cloudogu.com> Co-authored-by: Felix Wende <felix.wende@cloudogu.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Introduce deployment context and context builder * Refine deployment context attributes * Refactor deployment flow to use DeploymentContext * Fix DeploymentContext initialization in tools * Use hook config in ContentLoader pre-config validation * Use context to check if repositorySetup is blocked by internal ScmManager bootstrap * Rename feature to tool e.g. featureName in toolName * Fix Jenkins plugin lock cleanup * Fix recursive Jenkins config accessor * Wait for profile infrastructure before app pods integration tests * remove ErrImagePull and ImagePullBackOff from fatal container waiting reasons --------- Co-authored-by: Felix Wende <felix.wende@cloudogu.com> Co-authored-by: Anna Vetcininova <anna.vetcininova@cloudogu.com>
Co-authored-by: Niklas Hußmann <niklas.hussmann-extern@cloudogu.com> Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
* disable petclinic check at full-prefix tests * readd ErrImagePull and ImagePullBackOff to fatal container waiting reasons --------- Co-authored-by: Thomas Michael <thomas.michael@cloudogu.com> Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
* Separate SCM-Manager setup from Git provider initialization * Introduce RepositoryProvisioning for providing repositories and RepositoryWorkspace * Call GitHandler and RepositoryProvisioning explicitly from Application * Add namePrefix logic in RepositoryProvisioning and remove setup of repos from GitHandler * Centralize repository target naming in RepositoryProvisioning Move namePrefix handling out of GitRepo and build the final repository target in RepositoryProvisioning instead. This makes repository naming explicit and avoids hidden prefixing inside the technical GitRepo abstraction. * Rename getRepo to create, because you get always a new GitRepo * Use RepositoryProvisioning in SCMManagerTool * Initialize local Git repository if missing Add initialization of the temporary local repository when no .git directory exists yet. This allows the initial repository state to be committed and pushed after the local workspace has been prepared without cloning from an already existing remote repository. * fix static compile error * Reformat code * Fix unit tests * Fix cluster-resources.ftl.yaml * Fix ScmManagerTool and apps/argocd/argocd/values.ftl.yaml * Merge develop and introduce RepositoryProvisioning amd RepositoryWorkspace in ScmManager * Migrate ArgoCD to RepositoryProvisioning Use RepositoryProvisioning and RepositoryWorkspace for ArgoCD repository setup instead of handling repository creation, cloning, and pushing inside ArgoCD. Adjust SCM-Manager bootstrapping so it no longer writes scm-manager resources into the shared cluster-resources workspace, preventing ArgoCD from processing SCM-Manager-specific templates. * Migrate ArgoCD application strategy to shared repository workspace Update ArgoCdApplicationStrategy to use RepositoryProvisioning and the shared RepositoryWorkspace instead of creating and cloning its own Git repository. The strategy now writes ArgoCD Application manifests and value files into the central cluster-resources workspace and delegates publishing to RepositoryProvisioning. This avoids competing temporary clones and keeps repository lifecycle handling centralized. * Sync initialized Git workspaces before publishing Add origin remote configuration for repositories created with Git.init() and pull/rebase shared RepositoryWorkspace repositories before publishing changes. This keeps locally initialized workspaces aligned with remote main and fixes non-fast-forward push rejections. The strategy now writes ArgoCD Application manifests and value files into the central cluster-resources workspace and delegates publishing to RepositoryProvisioning. This avoids competing temporary clones and keeps repository lifecycle handling centralized. * Centralize cluster-resources Git handling Move argocd/cluster-resources handling to RepositoryProvisioning and the shared RepositoryWorkspace. ArgoCD application generation and ContentLoader updates no longer create separate Git clones or push directly. Initialize locally created Git workspaces with an origin remote and validate push results to detect rejected pushes early. * Use shared repository workspace for monitoring resources Move Monitoring updates for dashboards, RBAC and network policies to the shared RepositoryWorkspace and publish them through RepositoryProvisioning. This removes the separate cluster-resources clone/push flow and prevents non-fast-forward conflicts during monitoring deployment. * Fix ContentLoader unit tests * ContentLoaderTest cleanup and reformat code * Fix GitHandler unit test * Fix ApplicationConfigurator unit tests * Fix ArgoCDRepoSetupTest unit tests * Fix ArgoCDApplicationStrategyTest and add new tests * Fix Monitoring unit tests * Fix ArgoCDTest and reformat MonitoringTest * Remove unused methods in GitProvider like deleteUser; introduce servicePrefix in ScmManagerProvider and ScmManagerUrlResolver * Fix SCM-Manager deployment context in dedicated multi-tenant setup Ensure the SCM-Manager tool always deploys the tenant SCM-Manager instead of using the central SCM provider in dedicated multi-tenant mode. The central SCM-Manager is only used for central repository access, while the tenant SCM-Manager remains responsible for the tenant-local deployment and bootstrap flow. Also keep central cluster-resources and tenant bootstrap repository workspaces separated to prevent overlapping ArgoCD templates from overwriting each other. * Fix ArgoCDRepoSetupTest unit test * Fix compile errors * Fix unit tests * Fix prefixed namespace in ScmManager * Use context in RepositoryProvisioning and unit test * Add RepositoryWorkspace unit tests * Remove log.debug statements * Fix/remove petclinic test from prefix * Use log.trace in ContentLoader * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryProvisioning.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryProvisioning.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Extract bootstrapRepositoriesAfterScmManagerDeployment to RepositoryBootstrapper * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryWorkspace.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * rename prepareLocalDirectories to createLocalDirectories * Add javadoc for RepositoryProvisioning class, RepositoryWorkspace class and RepositoryBootstrapper class. * rename checkoutMainFromRemoteIfLocalMainMissing to alignWithRemoteMainIfPresent * remove unused config field * remove double secret patching * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Remove unused RepositoryProvisioning from ScmManager and use repositoryBootstrapper instead * Remove special handling for cluster-resources in ContentLoader Revert the dedicated ContentLoader handling for the cluster-resources repository. The additional branch is no longer needed because the existing ContentLoader flow already clones the current remote state and merges FOLDER_BASED content with overwriteMode UPGRADE. Keeping cluster-resources in the regular ContentLoader path avoids coupling the ContentLoader to RepositoryWorkspace internals and keeps repository handling consistent with the existing content repository flow. Additional trace logging remains to make ContentLoader target repo handling easier to debug, especially repo type, overwrite mode, target ref and local clone paths. * Fix ContentLoader unit tests * Fix ApplicationConfiguratorTest * Update Jenkins plugin pins for SCM-Manager compatibility * Move SCM repository bootstrap into ScmManagerSetup Move the post-SCM-Manager repository bootstrap logic into ScmManagerSetup, because the bootstrap flow is only used as part of the internal SCM-Manager setup. The bootstrap step now ensures the required remote repositories exist, initializes the local workspace, aligns it with the remote main branch, recreates the local directory structure, and pushes the generated bootstrap content. * Adjust logs by setting info to debug * Add Exception * Reformat Code --------- Co-authored-by: Thomas <thomas.michael@cloudogu.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
…-yaml to v2.22.0 (#525)
Introduce a central DeploymentOrchestrator that owns the outer tool execution order and passes the prepared DeploymentContext and RepositoryWorkspace into each enabled tool through Tool.execute(context, workspace). Create the DeploymentContext once in Application, prepare Git providers and repositories explicitly, and use RepositoryProvisioning/RepositoryWorkspace as the shared repository runtime for tools. The shared workspace now handles cluster-resources and, in dedicated multi-tenant mode, the tenant bootstrap repository. Refactor tools and deployment strategies to use the orchestrator-provided context and workspace instead of injected runtime state or separate repository clones. Keep isEnabled(context) as a pure activation check, move preparation into the tool execution flow, and remove DeploymentContext from GitRepo creation. Adjust SCM-Manager bootstrap, ArgoCD repository setup, ArgoCD application generation, Monitoring resources, Air-Gapped Helm mirroring, and destroy handlers to follow the explicit runtime context flow.
* Separate SCM-Manager setup from Git provider initialization * Introduce RepositoryProvisioning for providing repositories and RepositoryWorkspace * Call GitHandler and RepositoryProvisioning explicitly from Application * Add namePrefix logic in RepositoryProvisioning and remove setup of repos from GitHandler * Centralize repository target naming in RepositoryProvisioning Move namePrefix handling out of GitRepo and build the final repository target in RepositoryProvisioning instead. This makes repository naming explicit and avoids hidden prefixing inside the technical GitRepo abstraction. * Rename getRepo to create, because you get always a new GitRepo * Use RepositoryProvisioning in SCMManagerTool * Initialize local Git repository if missing Add initialization of the temporary local repository when no .git directory exists yet. This allows the initial repository state to be committed and pushed after the local workspace has been prepared without cloning from an already existing remote repository. * Merge develop and introduce RepositoryProvisioning amd RepositoryWorkspace in ScmManager * Migrate ArgoCD to RepositoryProvisioning Use RepositoryProvisioning and RepositoryWorkspace for ArgoCD repository setup instead of handling repository creation, cloning, and pushing inside ArgoCD. Adjust SCM-Manager bootstrapping so it no longer writes scm-manager resources into the shared cluster-resources workspace, preventing ArgoCD from processing SCM-Manager-specific templates. * Migrate ArgoCD application strategy to shared repository workspace Update ArgoCdApplicationStrategy to use RepositoryProvisioning and the shared RepositoryWorkspace instead of creating and cloning its own Git repository. The strategy now writes ArgoCD Application manifests and value files into the central cluster-resources workspace and delegates publishing to RepositoryProvisioning. This avoids competing temporary clones and keeps repository lifecycle handling centralized. * Sync initialized Git workspaces before publishing Add origin remote configuration for repositories created with Git.init() and pull/rebase shared RepositoryWorkspace repositories before publishing changes. This keeps locally initialized workspaces aligned with remote main and fixes non-fast-forward push rejections. The strategy now writes ArgoCD Application manifests and value files into the central cluster-resources workspace and delegates publishing to RepositoryProvisioning. This avoids competing temporary clones and keeps repository lifecycle handling centralized. * Centralize cluster-resources Git handling Initialize locally created Git workspaces with an origin remote and validate push results to detect rejected pushes early. * Use shared repository workspace for monitoring resources Move Monitoring updates for dashboards, RBAC and network policies to the shared RepositoryWorkspace and publish them through RepositoryProvisioning. This removes the separate cluster-resources clone/push flow and prevents non-fast-forward conflicts during monitoring deployment. * Remove unused methods in GitProvider like deleteUser; introduce servicePrefix in ScmManagerProvider and ScmManagerUrlResolver * Fix SCM-Manager deployment context in dedicated multi-tenant setup Ensure the SCM-Manager tool always deploys the tenant SCM-Manager instead of using the central SCM provider in dedicated multi-tenant mode. The central SCM-Manager is only used for central repository access, while the tenant SCM-Manager remains responsible for the tenant-local deployment and bootstrap flow. Also keep central cluster-resources and tenant bootstrap repository workspaces separated to prevent overlapping ArgoCD templates from overwriting each other. * Fix prefixed namespace in ScmManager * Use context in RepositoryProvisioning and unit test * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryProvisioning.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryProvisioning.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Extract bootstrapRepositoriesAfterScmManagerDeployment to RepositoryBootstrapper * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryWorkspace.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * rename prepareLocalDirectories to createLocalDirectories * Add javadoc for RepositoryProvisioning class, RepositoryWorkspace class and RepositoryBootstrapper class. * rename checkoutMainFromRemoteIfLocalMainMissing to alignWithRemoteMainIfPresent * remove unused config field * remove double secret patching * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Remove unused RepositoryProvisioning from ScmManager and use repositoryBootstrapper instead * Remove special handling for cluster-resources in ContentLoader Revert the dedicated ContentLoader handling for the cluster-resources repository. The additional branch is no longer needed because the existing ContentLoader flow already clones the current remote state and merges FOLDER_BASED content with overwriteMode UPGRADE. Keeping cluster-resources in the regular ContentLoader path avoids coupling the ContentLoader to RepositoryWorkspace internals and keeps repository handling consistent with the existing content repository flow. Additional trace logging remains to make ContentLoader target repo handling easier to debug, especially repo type, overwrite mode, target ref and local clone paths. * Fix ContentLoader unit tests * Fix ApplicationConfiguratorTest * Update Jenkins plugin pins for SCM-Manager compatibility * Extract ArgoCD application target resolution from ArgoCdApplicationStrategy ArgoCdApplicationStrategy now receives the resolved target and focuses on creating the ArgoCD Application manifest and writing it to the shared cluster-resources workspace. This removes the direct DeploymentContext dependency from the strategy and keeps single-tenant and dedicated multi-tenant decisions in one dedicated place. * Fix duplicated SCM-Manager namespace prefix in ArgoCD NetworkPolicy The ArgoCD allow-namespaces template prefixed the SCM-Manager namespace even though the configured namespace can already be fully resolved. In prefixed setups this produced namespaces such as my-prefix-my-prefix-scm-manager and caused the ArgoCD Helm installation to fail because the namespace did not exist. Use the resolved SCM-Manager namespace directly and add a regression test for prefixed network policy rendering. * Monitoring writes monitoring-specific GitOps artifacts into the shared cluster-resources workspace. * Move monitoring GitOps preparation to Monitoring tool Extract the reusable cluster-resources subdirectory filter from ArgoCDRepoSetup and use it for tool-owned repository preparation. Monitoring now copies and templates its own apps/monitoring content into the shared cluster-resources RepositoryWorkspace before generating RBAC, network policies and dashboard cleanup changes. ArgoCDRepoSetup no longer copies monitoring resources as part of its transitional cluster-resources setup. This keeps ArgoCD focused on ArgoCD-owned repository content and moves monitoring-specific GitOps artifacts closer to the Monitoring tool. Publishing remains centralized through RepositoryProvisioning; Monitoring does not clone or push repositories directly. * Move Jenkins GitOps preparation to Jenkins tool Move preparation of the Jenkins cluster-resources content out of ArgoCDRepoSetup and into the Jenkins tool. Jenkins now copies its own apps/jenkins resources into the shared RepositoryWorkspace before deploying the Helm chart. The Helm values template continues to be rendered through the common Tool.deployHelmChart flow, while Jenkins only provides its tool-specific template data such as dockerGid and jenkinsBootPlugins. ArgoCDRepoSetup no longer copies Jenkins resources as part of the transitional cluster-resources setup. This keeps ArgoCD focused on ArgoCD-owned repository content and moves Jenkins-specific GitOps artifacts closer to the owning tool. * Fiy MonitoringTest and remove unused buildTemplateValues from Monitoring * Fix unit test ClusterResourcesCopyFilterTest * Remove redundant copy filter unit test * Move cert-manager GitOps preparation to CertManager tool CertManager now copies its own apps/cert-manager resources into the shared RepositoryWorkspace before deploying the Helm chart. Helm values rendering remains handled by the common Tool.deployHelmChart flow. * Move external-secrets GitOps preparation to ExternalSecretsOperator tool * Move ingress GitOps preparation to Ingress tool Ingress now copies its own apps/ingress resources into the shared RepositoryWorkspace before deploying the Helm chart. Helm values rendering remains handled by the common Tool.deployHelmChart flow. * Move vault GitOps preparation to Vault tool Vault now copies its own apps/vault resources into the shared RepositoryWorkspace before deploying the Helm chart. Helm values rendering and the dev post-start script templating remain handled by the existing Vault and Tool flows. * Restrict ArgoCDRepoSetup to ArgoCD-owned resources ArgoCDRepoSetup now only copies and templates the apps/argocd resources into the shared RepositoryWorkspace. Tool-specific apps are prepared by their owning tools, so the legacy transitional copy list has been removed. * Change tool name to external-secrets instead of external-secrets-operator * Fix ExternalSecretsOperatorTest * Fix Unit Tests * Render Vault GitOps templates after copying resources Ensure Vault-owned GitOps resources are rendered after they are copied into the cluster-resources repository. This prevents FreeMarker template files from remaining in the deployable apps/vault path and being parsed by ArgoCD as raw Kubernetes manifests. * Render cert-manager templates after copying resources * Split SCM-Manager bootstrap preparation and push Separate SCM-Manager bootstrap repository preparation from the final push step. This ensures generated GitOps artifacts, such as the SCM-Manager ArgoCD Application, are written before the initial bootstrap state is committed and pushed. * Fix Ingress app content preparation --------- Co-authored-by: Thomas <thomas.michael@cloudogu.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
* Separate SCM-Manager setup from Git provider initialization * Introduce RepositoryProvisioning for providing repositories and RepositoryWorkspace * Call GitHandler and RepositoryProvisioning explicitly from Application * Add namePrefix logic in RepositoryProvisioning and remove setup of repos from GitHandler * Centralize repository target naming in RepositoryProvisioning Move namePrefix handling out of GitRepo and build the final repository target in RepositoryProvisioning instead. This makes repository naming explicit and avoids hidden prefixing inside the technical GitRepo abstraction. * Rename getRepo to create, because you get always a new GitRepo * Use RepositoryProvisioning in SCMManagerTool * Initialize local Git repository if missing Add initialization of the temporary local repository when no .git directory exists yet. This allows the initial repository state to be committed and pushed after the local workspace has been prepared without cloning from an already existing remote repository. * fix static compile error * Reformat code * Fix unit tests * Fix cluster-resources.ftl.yaml * Fix ScmManagerTool and apps/argocd/argocd/values.ftl.yaml * Merge develop and introduce RepositoryProvisioning amd RepositoryWorkspace in ScmManager * Migrate ArgoCD to RepositoryProvisioning Use RepositoryProvisioning and RepositoryWorkspace for ArgoCD repository setup instead of handling repository creation, cloning, and pushing inside ArgoCD. Adjust SCM-Manager bootstrapping so it no longer writes scm-manager resources into the shared cluster-resources workspace, preventing ArgoCD from processing SCM-Manager-specific templates. * Migrate ArgoCD application strategy to shared repository workspace Update ArgoCdApplicationStrategy to use RepositoryProvisioning and the shared RepositoryWorkspace instead of creating and cloning its own Git repository. The strategy now writes ArgoCD Application manifests and value files into the central cluster-resources workspace and delegates publishing to RepositoryProvisioning. This avoids competing temporary clones and keeps repository lifecycle handling centralized. * Sync initialized Git workspaces before publishing Add origin remote configuration for repositories created with Git.init() and pull/rebase shared RepositoryWorkspace repositories before publishing changes. This keeps locally initialized workspaces aligned with remote main and fixes non-fast-forward push rejections. The strategy now writes ArgoCD Application manifests and value files into the central cluster-resources workspace and delegates publishing to RepositoryProvisioning. This avoids competing temporary clones and keeps repository lifecycle handling centralized. * Centralize cluster-resources Git handling Move argocd/cluster-resources handling to RepositoryProvisioning and the shared RepositoryWorkspace. ArgoCD application generation and ContentLoader updates no longer create separate Git clones or push directly. Initialize locally created Git workspaces with an origin remote and validate push results to detect rejected pushes early. * Use shared repository workspace for monitoring resources Move Monitoring updates for dashboards, RBAC and network policies to the shared RepositoryWorkspace and publish them through RepositoryProvisioning. This removes the separate cluster-resources clone/push flow and prevents non-fast-forward conflicts during monitoring deployment. * Fix ContentLoader unit tests * ContentLoaderTest cleanup and reformat code * Fix GitHandler unit test * Fix ApplicationConfigurator unit tests * Fix ArgoCDRepoSetupTest unit tests * Fix ArgoCDApplicationStrategyTest and add new tests * Fix Monitoring unit tests * Fix ArgoCDTest and reformat MonitoringTest * Remove unused methods in GitProvider like deleteUser; introduce servicePrefix in ScmManagerProvider and ScmManagerUrlResolver * Fix SCM-Manager deployment context in dedicated multi-tenant setup Ensure the SCM-Manager tool always deploys the tenant SCM-Manager instead of using the central SCM provider in dedicated multi-tenant mode. The central SCM-Manager is only used for central repository access, while the tenant SCM-Manager remains responsible for the tenant-local deployment and bootstrap flow. Also keep central cluster-resources and tenant bootstrap repository workspaces separated to prevent overlapping ArgoCD templates from overwriting each other. * Fix ArgoCDRepoSetupTest unit test * Fix compile errors * Fix unit tests * Fix prefixed namespace in ScmManager * Use context in RepositoryProvisioning and unit test * Add RepositoryWorkspace unit tests * Remove log.debug statements * Fix/remove petclinic test from prefix * Use log.trace in ContentLoader * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryProvisioning.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryProvisioning.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * Extract bootstrapRepositoriesAfterScmManagerDeployment to RepositoryBootstrapper * Update src/main/groovy/com/cloudogu/gitops/application/repository/RepositoryWorkspace.groovy Co-authored-by: Thomas <thomas.michael@cloudogu.com> * rename prepareLocalDirectories to createLocalDirectories * Add javadoc for RepositoryProvisioning class, RepositoryWorkspace class and RepositoryBootstrapper class. * rename checkoutMainFromRemoteIfLocalMainMissing to alignWithRemoteMainIfPresent * remove unused config field * remove double secret patching * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Remove unused RepositoryProvisioning from ScmManager and use repositoryBootstrapper instead * Remove special handling for cluster-resources in ContentLoader Revert the dedicated ContentLoader handling for the cluster-resources repository. The additional branch is no longer needed because the existing ContentLoader flow already clones the current remote state and merges FOLDER_BASED content with overwriteMode UPGRADE. Keeping cluster-resources in the regular ContentLoader path avoids coupling the ContentLoader to RepositoryWorkspace internals and keeps repository handling consistent with the existing content repository flow. Additional trace logging remains to make ContentLoader target repo handling easier to debug, especially repo type, overwrite mode, target ref and local clone paths. * Fix ContentLoader unit tests * Fix ApplicationConfiguratorTest * Update Jenkins plugin pins for SCM-Manager compatibility * Extract ArgoCD application target resolution from ArgoCdApplicationStrategy ArgoCdApplicationStrategy now receives the resolved target and focuses on creating the ArgoCD Application manifest and writing it to the shared cluster-resources workspace. This removes the direct DeploymentContext dependency from the strategy and keeps single-tenant and dedicated multi-tenant decisions in one dedicated place. * Fix duplicated SCM-Manager namespace prefix in ArgoCD NetworkPolicy The ArgoCD allow-namespaces template prefixed the SCM-Manager namespace even though the configured namespace can already be fully resolved. In prefixed setups this produced namespaces such as my-prefix-my-prefix-scm-manager and caused the ArgoCD Helm installation to fail because the namespace did not exist. Use the resolved SCM-Manager namespace directly and add a regression test for prefixed network policy rendering. * Monitoring writes monitoring-specific GitOps artifacts into the shared cluster-resources workspace. * Move monitoring GitOps preparation to Monitoring tool Extract the reusable cluster-resources subdirectory filter from ArgoCDRepoSetup and use it for tool-owned repository preparation. Monitoring now copies and templates its own apps/monitoring content into the shared cluster-resources RepositoryWorkspace before generating RBAC, network policies and dashboard cleanup changes. ArgoCDRepoSetup no longer copies monitoring resources as part of its transitional cluster-resources setup. This keeps ArgoCD focused on ArgoCD-owned repository content and moves monitoring-specific GitOps artifacts closer to the Monitoring tool. Publishing remains centralized through RepositoryProvisioning; Monitoring does not clone or push repositories directly. * Move Jenkins GitOps preparation to Jenkins tool Move preparation of the Jenkins cluster-resources content out of ArgoCDRepoSetup and into the Jenkins tool. Jenkins now copies its own apps/jenkins resources into the shared RepositoryWorkspace before deploying the Helm chart. The Helm values template continues to be rendered through the common Tool.deployHelmChart flow, while Jenkins only provides its tool-specific template data such as dockerGid and jenkinsBootPlugins. ArgoCDRepoSetup no longer copies Jenkins resources as part of the transitional cluster-resources setup. This keeps ArgoCD focused on ArgoCD-owned repository content and moves Jenkins-specific GitOps artifacts closer to the owning tool. * Fiy MonitoringTest and remove unused buildTemplateValues from Monitoring * Fix unit test ClusterResourcesCopyFilterTest * Remove redundant copy filter unit test * Move cert-manager GitOps preparation to CertManager tool CertManager now copies its own apps/cert-manager resources into the shared RepositoryWorkspace before deploying the Helm chart. Helm values rendering remains handled by the common Tool.deployHelmChart flow. * Move external-secrets GitOps preparation to ExternalSecretsOperator tool * Move ingress GitOps preparation to Ingress tool Ingress now copies its own apps/ingress resources into the shared RepositoryWorkspace before deploying the Helm chart. Helm values rendering remains handled by the common Tool.deployHelmChart flow. * Move vault GitOps preparation to Vault tool Vault now copies its own apps/vault resources into the shared RepositoryWorkspace before deploying the Helm chart. Helm values rendering and the dev post-start script templating remain handled by the existing Vault and Tool flows. * Restrict ArgoCDRepoSetup to ArgoCD-owned resources ArgoCDRepoSetup now only copies and templates the apps/argocd resources into the shared RepositoryWorkspace. Tool-specific apps are prepared by their owning tools, so the legacy transitional copy list has been removed. * Change tool name to external-secrets instead of external-secrets-operator * Fix ExternalSecretsOperatorTest * Fix Unit Tests * refactor: replace ToolWithImage with explicit image pull secret creation Replace the ToolWithImage trait with an ImagePullSecretCreator to make image pull secret handling explicit in the owning tools. Previously, image pull secrets were created implicitly through Tool.execute() by checking whether a tool implemented ToolWithImage. This hid deployment preparation inside the Tool base class and forced tools to expose a K8sClient dependency even when they only needed image pull secret support. The new ImagePullSecretCreator encapsulates the Kubernetes-specific secret creation logic and keeps the registry configuration handling in one place. Tools now call it explicitly when an image pull secret is relevant for their namespace. This removes the hidden ToolWithImage lifecycle behavior, reduces unnecessary coupling to K8sClient, and prepares the codebase for the upcoming tool lifecycle phases where image pull secret creation can be assigned clearly to preDeploy. * refactor: introduce tool lifecycle phases Introduce explicit lifecycle phases for GOP tools and adapt ContentLoader to the new Tool execution model. Tool execution now follows the phases validate, preDeploy, deploy, postDeploy and publishChanges. This makes the internal deployment flow of each tool more explicit and prepares the codebase for migrating the individual tools step by step. The legacy enable-based execution path is removed from the Tool base class so deployment logic is no longer hidden behind the old hook structure. ContentLoader is adapted by moving its existing execution logic into the deploy phase without changing its behavior. Publishing remains an explicit lifecycle step so tools can clearly show when they commit and push their GitOps resources. * refactor: structure SCM-Manager deployment by lifecycle phases Split the SCM-Manager deployment flow into explicit lifecycle phases. Namespace preparation and image pull secret creation now happen in preDeploy, while the Helm deployment and availability check are handled in deploy. Post-deployment configuration, repository bootstrap and ArgoCD application creation are moved into postDeploy. The final cluster-resources commit is handled through publishChanges, making the regular SCM-Manager GitOps publishing step explicit while keeping the initial repository bootstrap push as a dedicated SCM-Manager setup step. This makes the SCM-Manager deployment flow easier to follow and aligns it with the new tool lifecycle model. * refactor: structure ArgoCD deployment by lifecycle phases Split the ArgoCD deployment flow into explicit lifecycle phases. Repository preparation, namespace setup, credential secrets, RBAC generation and values preparation now happen in preDeploy. The actual ArgoCD installation is handled in deploy, while bootstrap resources and Helm secret cleanup are moved into postDeploy. The final repository publication is handled through publishChanges, making the ArgoCD GitOps publishing step explicit and aligning the class with the new tool lifecycle model. This makes the ArgoCD deployment flow easier to follow and separates preparation, installation, post-deployment bootstrap and GitOps publishing more clearly. * refactor: structure Jenkins deployment by lifecycle phases Split the Jenkins deployment flow into explicit lifecycle phases. Jenkins-specific preparation such as namespace setup, image pull secret creation, node labeling, credentials, Helm values data and GitOps resource preparation now happens in preDeploy. The Helm/ArgoCD deployment is handled in deploy, while Jenkins URL resolution and the Jenkins setup script are moved into postDeploy. GitOps repository publication is handled explicitly in publishChanges. This makes the Jenkins deployment flow easier to follow and aligns it with the new tool lifecycle model while preserving the existing behavior for internal and external Jenkins setups. * Split SCM-Manager bootstrap preparation and push Separate SCM-Manager bootstrap repository preparation from the final push step. This ensures generated GitOps artifacts, such as the SCM-Manager ArgoCD Application, are written before the initial bootstrap state is committed and pushed. CertManager add replace templates methodes * Introduce life-cycle-phases in CertManager * Introduce life-cycle-phases in ExternalSecretsOperator * Cherry pick fix Ingress app * introduce life-cycle-phases in Ingress tool * introduce life-cycle-phases in Monitoring tool * introduce life-cycle-phases in registry tool * Fix registry test * refactor: introduce ArgoCD deployment modes Extract ArgoCD single-tenant and dedicated multi-tenant behavior into dedicated deployment mode classes. Previously, ArgoCD handled mode-specific logic directly across bootstrap resource application, RBAC generation, managed namespace updates and repository credential secret creation. This made the ArgoCD tool responsible for both the deployment lifecycle and the details of each deployment mode. The new DeploymentMode abstraction keeps the ArgoCD lifecycle focused on orchestration while SingleTenantMode and DedicatedMultiTenantMode encapsulate the mode-specific behavior. This improves readability, reduces scattered multi-tenant conditionals, and makes future changes to ArgoCD deployment variants easier to reason about. * Fix unit test ApplicationConfiguratorTest * Fix deployment of extern tools by contentLoader * test: add focused image pull secret creator tests Replace the outdated Tool/ToolWithImage image pull secret tests with dedicated ImagePullSecretCreator coverage. The new tests verify that image pull secrets are only created when enabled and that credential selection works correctly for proxy, read-only and default registry credentials. This keeps ToolTest focused on the Tool execution lifecycle and ensures image pull secret creation is covered by assertions against the actual Kubernetes Secret. * Fix ContentLoaderTest * Remove unused method * Delete ToolWithImage trait * Change commit message to reflect releaseName usage --------- Co-authored-by: Thomas <thomas.michael@cloudogu.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
* add typed OIDC setup for GOP tools Configure Argo CD, Jenkins, Grafana and Vault via typed OIDC fields and map the configured admin group to full admin permissions. Add a local Keycloak profile, make target and developer documentation for testing the OIDC setup end to end. Also define Jenkins OIDC fallback via generated JCasC and harden Vault OIDC setup against Keycloak startup timing. * reformat configuration.md tables * Fix phony declaration for keycloak Make target * Handle nullable OIDC config in tool templates * Allow Argo CD redirects for HTTP and HTTPS URLs --------- Co-authored-by: Felix Wende <felix.wende@cloudogu.com>
* Add sonar-maven-plugin * Fix indentation
This reverts commit f6ec71b.
* Update dependency prism-api to v1.30.0-723.v97277866cece * Update dependency credentials-binding to v720 * Update dependency script-security to v1402 * introduce sane defaults for renovate * Fix a regression resulting in GOP not able to find its config when running in sub-mandant (#506) * get config-map from right namespace * fix k8sClient unit test * bump micronaut version to 4.10.16 * small adoptions and more loginfo --------- Co-authored-by: Anna Vetcininova <anna.vetcininova@cloudogu.com> Co-authored-by: Thomas Michael <thomas.michael@cloudogu.com> * update tools.jackson.core dependencies for jackson-databind because of CVEs * add jackson-core dependency to pom because of CVEs * add jackson-databind dependency to pom because of CVEs * this new step scans the code quality with sonarqube * This PR updates K8sClient to resolve custom resources via the Kubernetes Discovery API (#512) * update implementation to resolve custom resource definitions via discovery API to avoid cluster-wide list permissions. * Change Exceptiontype for better information Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * better logging information Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * fix(ci): pin Sonar Maven plugin version (#555) * fix(ci): pin Sonar Maven plugin version * update jenkins plugins * fix(vault): update Helm chart to 0.34.1 for CVE-2026-33186 (#554) * Fix curl CVE (#557) * Using base image alpine:3.24 * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Set vault image to 2.0.4 (#558) * Update Vault chart version in documentation and fix test * Fix Java 25 runtime after main sync * Restore develop Docker runtime configuration --------- Co-authored-by: Renovate Bot <renovate@whitesourcesoftware.com> Co-authored-by: David Daehne <47227343+DerDaehne@users.noreply.github.com> Co-authored-by: David Daehne <david.daehne@cloudogu.com> Co-authored-by: Thomas Michael <thomas.michael@cloudogu.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Closed
Copilot stopped reviewing on behalf of
ThomasMichael1811 due to an error
September 16, 2026 08:57
ThomasMichael1811
approved these changes
Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR merges the current develop state into main.
Highlights:
Validation: