Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 6 additions & 14 deletions .bazelrc
Original file line number Diff line number Diff line change
Expand Up @@ -9,24 +9,16 @@ import %workspace%/envoy.bazelrc
# MSAN does not recognize host libc's stat() as initializing the rules_cc runfiles buffer
# (@bazel_tools//tools/cpp/runfiles is an alias for @rules_cc//cc/runfiles since Bazel 8).
# Scope zero initialization to this helper so proxy and Envoy sources remain fully checked.
build:msan --per_file_copt=external/rules_cc/cc/runfiles/runfiles[.]cc@-ftrivial-auto-var-init=zero

# Rust crate repinning for repository rules. Inherit CARGO_BAZEL_REPIN from the
# invocation environment so developers can repin explicitly without forcing
# every normal Bazel invocation to recompute the crate index.
common --repo_env=CARGO_BAZEL_REPIN
build:msan --per_file_copt=external/rules_cc[^/]*/cc/runfiles/runfiles[.]cc@-ftrivial-auto-var-init=zero

# Retry on transient repository download failures
common --experimental_repository_downloader_retries=5

# Use our own toolchains in all builds. Local builds need this to not pull in external Envoy sysroot
# that only supports glibc 2.31, while for Ubuntu 24.04 builds we need at least 2.38, and actually
# use 2.39.
build --extra_toolchains=//bazel/toolchains:all

# Use platforms based toolchain resolution
build --incompatible_enable_cc_toolchain_resolution
build --platform_mappings=bazel/platform_mappings
# Build with Envoy's hermetic LLVM toolchain: clang, lld, libc++ and the glibc sysroots are
# downloaded by Bazel and the toolchain is registered by Envoy's MODULE.bazel, so no compiler is
# needed on the host or in the builder image. The target architecture is selected with
# --platforms=//bazel:linux_{x86_64,aarch64}; the hermetic sysroots cover both.
common --repo_env=BAZEL_DO_NOT_DETECT_CPP_TOOLCHAIN=1

# envoy.bazelrc always sets -fPIC, tell bazel about it to suppress building both .o and .pic.o
# objects from the same C++ sources.
Expand Down
2 changes: 1 addition & 1 deletion .bazelversion
Original file line number Diff line number Diff line change
@@ -1 +1 @@
8.7.0
8.8.0
5 changes: 3 additions & 2 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
'go.mod',
'go.sum',
'tools/install_bazelisk.sh',
'WORKSPACE',
'MODULE.bazel',
'ENVOY_VERSION',
],
pinDigests: true,
Expand Down Expand Up @@ -106,6 +106,7 @@
{
matchFileNames: [
'Dockerfile',
'Dockerfile.tests',
],
matchPackageNames: [
'docker.io/library/ubuntu',
Expand Down Expand Up @@ -186,7 +187,7 @@
{
customType: 'regex',
managerFilePatterns: [
'/^WORKSPACE$/',
'/^MODULE\\.bazel$/',
],
matchStrings: [
'# renovate: datasource=(?<datasource>.*?) depName=(?<depName>.*?)\\s+.+_VERSION = "(?<currentValue>.*)"',
Expand Down
105 changes: 17 additions & 88 deletions .github/workflows/build-envoy-image-ci.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
name: CI Build & Push
on:
pull_request_target:
types: [opened, synchronize, reopened]
# pull_request_target:
# types: [opened, synchronize, reopened]
pull_request: {}

permissions:
# To be able to access the repository with `actions/checkout`
Expand Down Expand Up @@ -81,89 +82,6 @@ jobs:
else
echo "Invalid ENVOY_VERSION format: '$VERSION'" && exit 1
fi
echo "BUILDER_DOCKER_HASH=$(git ls-tree --full-tree HEAD -- ./Dockerfile.builder | awk '{ print $3 }')" >> $GITHUB_ENV

- name: Checking if cilium-envoy-builder image exists
id: cilium-builder-tag-in-repositories
shell: bash
run: |
if docker buildx imagetools inspect quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }} &>/dev/null; then
echo exists="true" >> $GITHUB_OUTPUT
else
echo exists="false" >> $GITHUB_OUTPUT
fi

- name: PR Multi-arch build of Builder image (dev)
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
id: docker_build_builder_ci
with:
provenance: false
context: .
file: ./Dockerfile.builder
platforms: linux/amd64,linux/arm64
push: false
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
outputs: type=oci,dest=${{ runner.temp }}/builder-dev.tar

# Quay's registry endpoint only accepts credentials or a JWT signed by
# Quay itself, so the GitHub OIDC token cannot be used as the registry
# password directly. Trade it for a short lived robot token first.
#
# Because the job references an environment, the subject of the token is
# repo:cilium@21054566/proxy@155294575:environment:publish-ci-images, the
# immutable form that carries the owner and repository ids. That is the
# identity federated with the robot account on the Quay side, so renaming
# the environment breaks the login.
#
# Quay gives the token one hour and the builds below take hours, so every
# artifact gets its own token once its build finishes. Nothing before the
# first push needs Quay auth: the builder tag lookup and the BUILDER_BASE
# and ARCHIVE_IMAGE pulls all read public repositories.
- name: Get a quay.io robot token via OIDC for the Builder image (dev)
id: token-builder-dev
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
env:
ROBOT: ${{ vars.QUAY_ROBOT_CI }}
run: |
oidc_token="$(curl -sSf --retry 3 --retry-all-errors \
-H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=quay.io" \
| jq -er '.value')"
echo "::add-mask::${oidc_token}"

# Pass the credentials on stdin so that the OIDC token is not visible
# in the process list of the runner.
robot_token="$(printf 'user = "%s:%s"\n' "${ROBOT}" "${oidc_token}" \
| curl -sSf --retry 3 --retry-all-errors -K - \
"https://quay.io/oauth2/federation/robot/token" \
| jq -er '.token')"
echo "::add-mask::${robot_token}"

echo "token=${robot_token}" >> "$GITHUB_OUTPUT"

- name: Login to quay.io for the Builder image (dev)
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
with:
registry: quay.io
username: ${{ vars.QUAY_ROBOT_CI }}
password: ${{ steps.token-builder-dev.outputs.token }}

- name: PR Push of Builder image (dev)
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
run: |
skopeo copy --multi-arch all \
"oci-archive:${{ runner.temp }}/builder-dev.tar" \
docker://quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
rm -f "${{ runner.temp }}/builder-dev.tar"

- name: CI Builder Image Digest
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
shell: bash
run: |
echo "Digests:"
echo "quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}@${{ steps.docker_build_builder_ci.outputs.digest }}"

- name: PR Multi-arch build of cilium-envoy
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
Expand All @@ -174,7 +92,6 @@ jobs:
file: ./Dockerfile
platforms: linux/amd64,linux/arm64
build-args: |
BUILDER_BASE=quay.io/cilium/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
ARCHIVE_IMAGE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ github.base_ref }}-archive-latest
BAZEL_BUILD_OPTS=--remote_upload_local_results=false
cache-from: type=local,src=/tmp/buildx-cache
Expand All @@ -183,8 +100,20 @@ jobs:
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-dev:${{ github.event.pull_request.head.sha }}
outputs: type=oci,dest=${{ runner.temp }}/cilium-envoy-dev.tar

# A token of its own for this push; see the token exchange above. The
# cosign and SBOM steps below write to quay.io with it too.
# Quay's registry endpoint only accepts credentials or a JWT signed by
# Quay itself, so the GitHub OIDC token cannot be used as the registry
# password directly. Trade it for a short lived robot token first.
#
# Because the job references an environment, the subject of the token is
# repo:cilium@21054566/proxy@155294575:environment:publish-ci-images, the
# immutable form that carries the owner and repository ids. That is the
# identity federated with the robot account on the Quay side, so renaming
# the environment breaks the login.
#
# Quay gives the token one hour and the build above takes hours, so the
# token is fetched once the build finishes. Nothing before the push needs
# Quay auth: the ARCHIVE_IMAGE pull reads a public repository. The cosign
# and SBOM steps below write to quay.io with this token too.
- name: Get a quay.io robot token via OIDC for cilium-envoy
id: token-cilium-envoy-dev
env:
Expand Down
102 changes: 13 additions & 89 deletions .github/workflows/build-envoy-images-release-base.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,6 @@ jobs:
echo "${{ github.sha }}" >SOURCE_VERSION
echo "ENVOY_MINOR_RELEASE=$(cat ENVOY_VERSION | sed 's/envoy-\([0-9]\+\.[0-9]\+\)\..*/v\1/')" >> $GITHUB_ENV
echo "ENVOY_PATCH_RELEASE=$(cat ENVOY_VERSION | sed 's/^envoy-\([0-9]\+\.[0-9]\+\.[0-9]\+$\)/v\1/')" >> $GITHUB_ENV
echo "BUILDER_DOCKER_HASH=$(git ls-tree --full-tree HEAD -- ./Dockerfile.builder | awk '{ print $3 }')" >> $GITHUB_ENV

- name: Cache Docker layers
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
Expand All @@ -66,13 +65,6 @@ jobs:
- name: Clear cache
run: rm -rf /tmp/buildx-cache/*

- name: Wait for builder image
uses: ./.github/workflows/wait-for-image
with:
SHA: ${{ env.BUILDER_DOCKER_HASH }}
repo: cilium
images: cilium-envoy-builder

- name: Run integration tests on amd64 & build of test artifact archive
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
id: docker_tests_ci_cache_update
Expand All @@ -83,7 +75,6 @@ jobs:
target: builder-archive
platforms: linux/amd64
build-args: |
BUILDER_BASE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ env.BUILDER_DOCKER_HASH }}
ARCHIVE_IMAGE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:test-${{ github.ref_name }}-archive-latest
COPY_CACHE_EXT=.new
BAZEL_BUILD_OPTS=--remote_upload_local_results=false
Expand Down Expand Up @@ -174,31 +165,22 @@ jobs:
echo "${{ github.sha }}" >SOURCE_VERSION
echo "ENVOY_MINOR_RELEASE=$(cat ENVOY_VERSION | sed 's/envoy-\([0-9]\+\.[0-9]\+\)\..*/v\1/')" >> $GITHUB_ENV
echo "ENVOY_PATCH_RELEASE=$(cat ENVOY_VERSION | sed 's/^envoy-\([0-9]\+\.[0-9]\+\.[0-9]\+$\)/v\1/')" >> $GITHUB_ENV
echo "BUILDER_DOCKER_HASH=$(git ls-tree --full-tree HEAD -- ./Dockerfile.builder | awk '{ print $3 }')" >> $GITHUB_ENV
echo "SOURCE_TIMESTAMP=$(git log -1 --pretty=format:"%ct" .)" >> $GITHUB_ENV

- name: Checking if cilium-envoy-builder image exists
id: cilium-builder-tag-in-repositories
shell: bash
run: |
if docker buildx imagetools inspect quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ env.BUILDER_DOCKER_HASH }} &>/dev/null; then
echo exists="true" >> $GITHUB_OUTPUT
else
echo exists="false" >> $GITHUB_OUTPUT
fi

- name: Multi-arch build of Builder image
- name: Multi-arch build of build artifact archive
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
id: docker_build_builder
with:
provenance: false
context: .
file: ./Dockerfile.builder
file: ./Dockerfile
target: builder-archive
platforms: linux/amd64,linux/arm64
build-args: |
ARCHIVE_IMAGE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ github.ref_name }}-archive-latest
COPY_CACHE_EXT=.new
BAZEL_BUILD_OPTS="--jobs=HOST_CPUS*.75"
push: false
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ env.BUILDER_DOCKER_HASH }}
outputs: type=oci,dest=${{ runner.temp }}/builder.tar
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ github.ref_name }}-archive-latest
outputs: type=oci,dest=${{ runner.temp }}/archive.tar

# Quay's registry endpoint only accepts credentials or a JWT signed by
# Quay itself, so the GitHub OIDC token cannot be used as the registry
Expand All @@ -210,67 +192,10 @@ jobs:
# identity federated with the robot account on the Quay side, so renaming
# the environment breaks the login.
#
# Quay gives the token one hour and the builds below take hours, so every
# artifact gets its own token once its build finishes. Nothing before the
# first push needs Quay auth: the builder tag lookup and the BUILDER_BASE
# and ARCHIVE_IMAGE pulls all read public repositories.
- name: Get a quay.io robot token via OIDC for the Builder image
id: token-builder
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
env:
ROBOT: ${{ vars.QUAY_ROBOT_RELEASE }}
run: |
oidc_token="$(curl -sSf --retry 3 --retry-all-errors \
-H "Authorization: bearer ${ACTIONS_ID_TOKEN_REQUEST_TOKEN}" \
"${ACTIONS_ID_TOKEN_REQUEST_URL}&audience=quay.io" \
| jq -er '.value')"
echo "::add-mask::${oidc_token}"

# Pass the credentials on stdin so that the OIDC token is not visible
# in the process list of the runner.
robot_token="$(printf 'user = "%s:%s"\n' "${ROBOT}" "${oidc_token}" \
| curl -sSf --retry 3 --retry-all-errors -K - \
"https://quay.io/oauth2/federation/robot/token" \
| jq -er '.token')"
echo "::add-mask::${robot_token}"

echo "token=${robot_token}" >> "$GITHUB_OUTPUT"

- name: Login to quay.io for the Builder image
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
with:
registry: quay.io
username: ${{ vars.QUAY_ROBOT_RELEASE }}
password: ${{ steps.token-builder.outputs.token }}

- name: Push of Builder image
if: steps.cilium-builder-tag-in-repositories.outputs.exists == 'false'
run: |
for tag in ${{ env.BUILDER_DOCKER_HASH }} latest; do
skopeo copy --multi-arch all \
"oci-archive:${{ runner.temp }}/builder.tar" \
"docker://quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${tag}"
done
rm -f "${{ runner.temp }}/builder.tar"

- name: Multi-arch build of build artifact archive
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
file: ./Dockerfile
target: builder-archive
platforms: linux/amd64,linux/arm64
build-args: |
BUILDER_BASE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ env.BUILDER_DOCKER_HASH }}
ARCHIVE_IMAGE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ github.ref_name }}-archive-latest
COPY_CACHE_EXT=.new
BAZEL_BUILD_OPTS="--jobs=HOST_CPUS*.75"
push: false
tags: quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ github.ref_name }}-archive-latest
outputs: type=oci,dest=${{ runner.temp }}/archive.tar

# A token of its own for this push; see the token exchange above.
# Quay gives the token one hour and the builds in this job take hours, so
# every artifact gets its own token once its build finishes. Nothing before
# the first push needs Quay auth: the ARCHIVE_IMAGE pulls read a public
# repository.
- name: Get a quay.io robot token via OIDC for the build artifact archive
id: token-archive
env:
Expand Down Expand Up @@ -326,7 +251,6 @@ jobs:
file: ./Dockerfile
platforms: linux/amd64,linux/arm64
build-args: |
BUILDER_BASE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ env.BUILDER_DOCKER_HASH }}
BAZEL_BUILD_OPTS=--remote_upload_local_results=false
ARCHIVE_IMAGE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder:${{ github.ref_name }}-archive-latest
RELEASE_DEBUG=${{ inputs.release_debug && '1' || '' }}
Expand Down
19 changes: 0 additions & 19 deletions .github/workflows/ci-check-format.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -26,14 +26,6 @@ jobs:
- name: Prep for build
run: |
echo "${{ github.event.pull_request.head.sha }}" >SOURCE_VERSION
echo "BUILDER_DOCKER_HASH=$(git ls-tree --full-tree HEAD -- ./Dockerfile.builder | awk '{ print $3 }')" >> $GITHUB_ENV

- name: Wait for build image
uses: ./.github/workflows/wait-for-image
with:
SHA: ${{ env.BUILDER_DOCKER_HASH }}
repo: cilium
images: cilium-envoy-builder-dev

- name: Check format
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
Expand All @@ -45,8 +37,6 @@ jobs:
file: ./Dockerfile
platforms: linux/amd64
outputs: type=local,dest=check-format-results
build-args: |
BUILDER_BASE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
push: false

- name: Check for failure
Expand Down Expand Up @@ -74,17 +64,9 @@ jobs:
- name: Prep for build
run: |
echo "${{ github.event.pull_request.head.sha }}" >SOURCE_VERSION
echo "BUILDER_DOCKER_HASH=$(git ls-tree --full-tree HEAD -- ./Dockerfile.builder | awk '{ print $3 }')" >> $GITHUB_ENV
# git diff filter has everything else than deleted files (those need not be tidied)
echo "TIDY_SOURCES=$(git diff --name-only --diff-filter=d HEAD^1 HEAD -- '*.h' '*.cc' | tr '\n' ' ')" >> $GITHUB_ENV

- name: Wait for build image
uses: ./.github/workflows/wait-for-image
with:
SHA: ${{ env.BUILDER_DOCKER_HASH }}
repo: cilium
images: cilium-envoy-builder-dev

- name: Run clang-tidy
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
# skip if nothing changed
Expand All @@ -98,7 +80,6 @@ jobs:
platforms: linux/amd64
outputs: type=local,dest=clang-tidy-results
build-args: |
BUILDER_BASE=quay.io/${{ github.repository_owner }}/cilium-envoy-builder-dev:${{ env.BUILDER_DOCKER_HASH }}
TIDY_SOURCES=${{ env.TIDY_SOURCES }}
push: false

Expand Down
Loading
Loading