DevOps --- Pipeline和Yaml文件

DevOps --- Pipeline和Yaml文件

什么是Pipleine

  • 在DevOps中pipeline可以按顺序在一台虚拟机上实现一组特定的操作,包括但不限于
  • 执行git命令,如拉取代码,push代码等
  • 执行任意程序
  • 执行python或bash脚本
  • ...
  • 基于以上操作,pipeline通常可以完成以下场景
  • 持续集成:拉取代码,运行代码质量检查工具,运行集成测试,部署代码等
  • 使用第三方控件对代码进行安全扫描(DAST, Image,SAST等)
  • 定时运行E2E测试
  • ...

什么是Yaml文件

  • 和Json,XML类似,YAML(YAML Ain't Markup Language)是一种数据序列化格式。经常被用于配置文件和数据交换格式,特别适用于各种编程语言之间的数据传递.
  • 在微软的DevOps中,yaml通常用来定义一个pipeline

Yaml文件的构成

  • 一个pipeline 由多个stages组成
  • 一个stage由多个jobs组成
  • 每个Job可以在一个agent上执行(一个Job也可以没有agent)
  • an agent could be an VM or sometimes an VM can have multiple agents
  • 一个job由多个steps组成
  • steps可以是task或script,是pipeline的最小构建单元
  • task是一些Azure DevOps预先设定好的功能,可以直接使用. 常用的task包括,
  • PythonScript@0
  • PowerShell@2
  • Docker@1
  • CopyFiles@2
  • PublishTestResults@2
  • ...
  • 可以在ADO中搜索
  • Trigger
  • This states what changes trigger the pipeline. For the example in the below code, changes in the main branch alone trigger the pipeline run and not from the feature branches.
  • Pool
  • When your build or deployment runs, the system begins one or more jobs. An agent is a computing infrastructure with installed agent software that runs one job at a time. For example, your job could run on a Microsoft-hosted Ubuntu agent. The below pipeline yaml uses "ubuntu-latest"
  • Variables
  • Variables are a way to get key bits of data into various parts of the pipeline.
  • The most common use of variables is to define a value that you can then use in your pipeline.
  • All variables are strings and are mutable. The value of a variable can change from run to run or job to job of your pipeline.

Example

yaml 复制代码
trigger:
  branches:
    include:
    - main
    exclude:
    - feature_branches

pool:
  vmImage: 'ubuntu-latest'

variables:
  - name: tag
    value: '$(Build.BuildNumber)'
  - name: ImageName
    value: "demo Image"
  - name: python.version
    value: '3.8'

schedules:
 - cron: "0 18 1 * *"
   always: true
   displayName: Monthly, 2nd, 2:00 am (utc+8)
   branches:
     include:
     - master

stages:
  - stage: Lint
    displayName: Format and lint code
    jobs:
      - job: Linting
        steps:
        - script: |
            python3 -m pip install black
            python3 -m pip install pylint
          displayName: "Install dependencies"  

        - script: |
            #app is the folder in which the application code resides
            python3 -m black ./app
          displayName: "Apply black code formatting"

        - script: |
            python3 -m pylint ./app --recursive=true --exit-zero
          displayName: "Static code analysis with pylint"
  
  - stage: Test
    displayName: Unit test
    jobs:
      - job: Test
        steps:
        - script: |
            python3 -m pip install -r requirements.txt
            python3 -m pip install pytest-azurepipelines
          displayName: "Install dependencies"
        
        - script: |
            python3 -m pytest -v -s --junitxml=unittest/junit.xml --cov=. --cov-report=term-missing --cov-report=xml
  
  - stage: Build
    displayName: 'Build and Push Docker Image'
    jobs:
      - job: BuildAndPush
        displayName: 'Build and Push Docker Image'
        steps:
       - task: Docker@1
         displayName: 'Build an image'
        inputs:
        containerregistrytype: 'Azure Container Registry'
        azureSubscriptionEndpoint: 'Service connection name'
        azureContainerRegistry: '<<democontainer-DEV.azurecr.io>>'
        command: 'Build an Image'
        dockerFile: '$(System.DefaultWorkingDirectory)/Dockerfile'
        tags: |
          latest
          $(Build.BuildId)
        imageName: '$(ImageName):$(tag)'

       - task: Docker@1
         displayName: 'Push image to ACR to TEST'
         inputs:
           containerregistrytype: 'Azure Container Registry'
           azureSubscriptionEndpoint: '<<demoserviceconenction>>'
           azureContainerRegistry: 'container registary name-DEV.azurecr.io'
           command: 'Push an image'
           imageName: '$(ImageName):$(tag)'
      
       - task: Docker@1
         displayName: 'Build an image'
         inputs:
           containerregistrytype: 'Azure Container Registry'
           azureSubscriptionEndpoint: 'Service connection name'
           azureContainerRegistry: 'container registary name-PROD.azurecr.io'
           command: 'Build an Image'
           dockerFile: '$(System.DefaultWorkingDirectory)/Dockerfile'
           tags: |
               latest
               $(Build.BuildId)
           imageName: '$(ImageName):$(tag)'
      
       - task: Docker@1
         displayName: 'Push image to ACR to PROD'
         inputs:
           containerregistrytype: 'Azure Container Registry'
           azureSubscriptionEndpoint: 'Service connection name'
           azureContainerRegistry: 'container registary name-PROD.azurecr.io'
           command: 'Push an image'
           imageName: '$(ImageName):$(tag)'      
           
       - task: CopyFiles@2
         inputs:
           SourceFolder: 'kubernetes'
           Contents: '*.yaml'
           TargetFolder: '$(Build.ArtifactStagingDirectory)'
      
       - task: PublishBuildArtifacts@1
         inputs:
           PathtoPublish: '$(Build.ArtifactStagingDirectory)'
           ArtifactName: 'manifest'
           publishLocation: 'Container'
相关推荐
Lsetea4 小时前
curl指定CA目录仍报证书不受信任:--capath与OpenSSL rehash排查
运维·https·ssl·openssl·curl
优化Henry4 小时前
LTE 载波频率与频点配置详解
运维·网络·学习·5g·信息与通信
代码方舟5 小时前
数据科学风控实战:基于天远全能消金报告构建自动化信用评估网关
运维·人工智能·自动化
科力锐品牌君5 小时前
应用级灾备 | 海量非结构化数据如何实现高效数据保护
linux·运维·网络·安全·系统安全·数据安全·灾备
KaiwuDB5 小时前
KaiwuDB 运维实战04:DRBD + KaiwuDB——物联网场景下的低成本数据库高可用方案
运维·数据库·物联网·时序数据库·kaiwudb·aiot·多模数据库
福建佰胜张工6 小时前
A5E00839230西门子工业核心配件详解:参数、安装调试与故障运维全攻略
运维·网络·安全·自动化
Lancker6 小时前
chnroute-linux — 中国大陆 IP 段每日自动更新 + 「仅允许国内访问」落地
linux·运维·tcp/ip
天远Date Lab7 小时前
零信任架构实战:基于天远全能消金报告(标准版)构建自动化骑手资信评估网关
运维·人工智能·架构·自动化
赛博守夜人7 小时前
反舞弊系列之二十一:数据驱动型反舞弊体系搭建,如何利用ERP与财务数据构建“异常交易自动化风控看板”?
运维·自动化
天衍四九-7 小时前
Docker容器实战系列(八):Docker生产最佳实践与避坑指南,系列终章
运维·docker·容器