-
Notifications
You must be signed in to change notification settings - Fork 15
Expand file tree
/
Copy pathload-binary.sh
More file actions
executable file
·311 lines (240 loc) · 12.8 KB
/
load-binary.sh
File metadata and controls
executable file
·311 lines (240 loc) · 12.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
#!/usr/bin/env bash
# Unless explicitly stated otherwise all files in this repository are licensed under the the Apache License Version 2.0.
# This product includes software developed at Datadog (https://www.datadoghq.com/).
# Copyright 2021 Datadog, Inc.
##########################################################################################
# The purpose of this script is to download the latest development version of a component.
#
# Binaries sources:
#
# * Agent: Docker hub datadog/agent-dev:master-py3
# * cpp_httpd: Github action artifact
# * Golang: github.com/DataDog/dd-trace-go/v2@main
# * .NET: ghcr.io/datadog/dd-trace-dotnet
# * Java: S3
# * Java Lambda: S3 (same binary as Java)
# * PHP: ghcr.io/datadog/dd-trace-php
# * Node.js: Direct from github source
# * Node.js Lambda: Fetch from GitHub Actions artifact
# * C++: Direct from github source
# * Python: S3 https://dd-trace-py-builds.s3.amazonaws.com/<GIT_REF>/index.html
# * Ruby: Direct from github source
# * WAF: Direct from github source, but not working, as this repo is now private
# * Python Lambda: Fetch from GitHub Actions artifact
# * Rust: Clone locally the github repo
##########################################################################################
set -eu
assert_version_is_dev() {
if [ $VERSION = 'dev' ]; then
return 0
fi
echo "Don't know how to load version $VERSION for $TARGET"
exit 1
}
assert_target_branch_is_not_set() {
if [[ -z "${LIBRARY_TARGET_BRANCH:-}" ]]; then
return 0
fi
echo "It is not possible to specify the '$LIBRARY_TARGET_BRANCH' target branch for $TARGET library yet"
exit 1
}
get_github_action_artifact() {
rm -rf artifacts artifacts.zip
SLUG=$1
WORKFLOW=$2
BRANCH=$3
ARTIFACT_NAME=$4
PATTERN=$5
IGNORE_FAILED_WORKFLOW=${6:-true} # 6th arg, with default "true"
# query filter seems not to be working ??
WORKFLOWS=$(curl --silent --fail --show-error -H "Authorization: token $GITHUB_TOKEN" "https://api.github.com/repos/$SLUG/actions/workflows/$WORKFLOW/runs?per_page=100")
if [ "$IGNORE_FAILED_WORKFLOW" = "true" ]; then
QUERY="[.workflow_runs[] | select(.conclusion != \"failure\" and .head_branch == \"$BRANCH\" and .status == \"completed\")][0]"
else
QUERY="[.workflow_runs[] | select(.head_branch == \"$BRANCH\" and .status == \"completed\")][0]"
fi
# this wil fail if there are more than 100 artifacts
ARTIFACT_URL=$(echo $WORKFLOWS | jq -r "$QUERY | .artifacts_url")
ARTIFACT_URL="$ARTIFACT_URL?per_page=100"
HTML_URL=$(echo $WORKFLOWS | jq -r "$QUERY | .html_url")
echo "Load artifacts for $HTML_URL"
ARTIFACTS=$(curl --silent -H "Authorization: token $GITHUB_TOKEN" $ARTIFACT_URL)
ARCHIVE_URL=$(echo $ARTIFACTS | jq -r --arg ARTIFACT_NAME "$ARTIFACT_NAME" '.artifacts | map(select(.name | contains($ARTIFACT_NAME))) | .[0].archive_download_url')
echo "Load archive $ARCHIVE_URL"
curl -H "Authorization: token $GITHUB_TOKEN" --output artifacts.zip -L $ARCHIVE_URL
mkdir -p artifacts/
unzip artifacts.zip -d artifacts/
find artifacts/ -type f -name "$PATTERN" -exec cp '{}' . ';'
rm -rf artifacts artifacts.zip
}
get_github_release_asset() {
SLUG=$1
PATTERN=$2
release=$(curl --silent --fail --show-error -H "Authorization: token $GITHUB_TOKEN" "https://api.github.com/repos/$SLUG/releases/latest")
name=$(echo $release | jq -r ".assets[].name | select(test(\"$PATTERN\"))")
url=$(echo $release | jq -r ".assets[].browser_download_url | select(test(\"$PATTERN\"))")
echo "Load $url"
curl -H "Authorization: token $GITHUB_TOKEN" --output $name -L $url
}
if test -f ".env"; then
source .env
fi
TARGET=$1
VERSION=${2:-'dev'}
GITHUB_TOKEN="${GITHUB_TOKEN:-}"
GITHUB_AUTH_HEADER=()
if [ -n "$GITHUB_TOKEN" ]; then
GITHUB_AUTH_HEADER=(-H "Authorization: Bearer $GITHUB_TOKEN")
fi
echo "Load $VERSION binary for $TARGET"
cd binaries/
if [ "$TARGET" = "java" ] || [ "$TARGET" = "java_lambda" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-master}"
curl --fail --location --silent --show-error --output dd-java-agent.jar "https://s3.us-east-1.amazonaws.com/dd-trace-java-builds/${LIBRARY_TARGET_BRANCH}/dd-java-agent.jar"
elif [ "$TARGET" = "dotnet" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-latest_snapshot}"
# Normalize branch name for image tag: replace '/' with '_'
NORMALIZED_BRANCH=$(echo "$LIBRARY_TARGET_BRANCH" | sed 's/\//_/g')
rm -rf *.tar.gz
if [ -n "$GITHUB_TOKEN" ]; then
echo "Log to GHCR with token"
echo "$GITHUB_TOKEN" | docker login ghcr.io --password-stdin -u "actor" # username is ignored
fi
../utils/scripts/docker_base_image.sh ghcr.io/datadog/dd-trace-dotnet/dd-trace-dotnet:${NORMALIZED_BRANCH} .
elif [ "$TARGET" = "python" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
echo "Using $LIBRARY_TARGET_BRANCH in S3 for DataDog/dd-trace-py"
echo $LIBRARY_TARGET_BRANCH > python-load-from-s3
elif [ "$TARGET" = "ruby" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-master}"
echo "gem 'datadog', require: 'datadog/auto_instrument', git: 'https://github.com/Datadog/dd-trace-rb.git', branch: '$LIBRARY_TARGET_BRANCH'" > ruby-load-from-bundle-add
echo "Using $(cat ruby-load-from-bundle-add)"
elif [ "$TARGET" = "php" ]; then
rm -rf *.tar.gz
mkdir -p temp
if [ $VERSION = 'dev' ]; then
URL="https://s3.us-east-1.amazonaws.com/dd-trace-php-builds/latest/datadog-setup.php"
echo "Downloading datadog-setup.php from: $URL"
curl --fail --location --silent --show-error --output ./temp/datadog-setup.php "$URL"
echo "datadog-setup.php downloaded"
VERSION_HASH=$(grep "define('RELEASE_VERSION'" ./temp/datadog-setup.php | sed -E "s/.*urlencode\('([^']+)'\).*/\1/")
if [ -z "$VERSION_HASH" ]; then
echo "Failed to extract VERSION_HASH from datadog-setup.php"
exit 1
fi
VERSION_HASH_ENCODED=$(echo "$VERSION_HASH" | sed 's/+/%2B/g')
URL="https://s3.us-east-1.amazonaws.com/dd-trace-php-builds/${VERSION_HASH_ENCODED}/dd-library-php-${VERSION_HASH_ENCODED}-$(arch)-linux-gnu.tar.gz"
echo "Downloading dd-library-php from: $URL"
curl --fail --location --silent --show-error --output "./temp/dd-library-php-${VERSION_HASH}-$(arch)-linux-gnu.tar.gz" "$URL"
echo "dd-library-php $(arch) downloaded"
elif [ $VERSION = 'prod' ]; then
../utils/scripts/docker_base_image.sh ghcr.io/datadog/dd-trace-php/dd-library-php:latest ./temp
else
echo "Don't know how to load version $VERSION for $TARGET"
fi
mv ./temp/dd-library-php*.tar.gz . && mv ./temp/datadog-setup.php . && rm -rf ./temp
elif [ "$TARGET" = "golang" ]; then
assert_version_is_dev
rm -rf golang-load-from-go-get
set -o pipefail
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
echo "load last commit on $LIBRARY_TARGET_BRANCH for DataDog/dd-trace-go"
COMMIT_ID=$(curl -sS --fail "${GITHUB_AUTH_HEADER[@]}" "https://api.github.com/repos/DataDog/dd-trace-go/branches/$LIBRARY_TARGET_BRANCH" | jq -r .commit.sha)
echo "Using github.com/DataDog/dd-trace-go/v2@$COMMIT_ID"
echo "github.com/DataDog/dd-trace-go/v2@$COMMIT_ID" > golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/database/sql/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/net/http/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/google.golang.org/grpc/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/99designs/gqlgen/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/gin-gonic/gin/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/graphql-go/graphql/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/graph-gophers/graphql-go/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/go-chi/chi.v5/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/IBM/sarama/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/labstack/echo.v4/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "github.com/DataDog/dd-trace-go/contrib/sirupsen/logrus/v2@$COMMIT_ID" >> golang-load-from-go-get
echo "Using github.com/DataDog/orchestrion@latest"
echo "github.com/DataDog/orchestrion@latest" > orchestrion-load-from-go-get
elif [ "$TARGET" = "envoy" ]; then
assert_version_is_dev
echo "Using ghcr.io/datadog/dd-trace-go/service-extensions-callout:dev"
echo "ghcr.io/datadog/dd-trace-go/service-extensions-callout:dev" > golang-service-extensions-callout-image
elif [ "$TARGET" = "haproxy" ]; then
assert_version_is_dev
echo "Using ghcr.io/datadog/dd-trace-go/haproxy-spoa:dev"
echo "ghcr.io/datadog/dd-trace-go/haproxy-spoa:dev" > golang-haproxy-spoa-image
elif [ "$TARGET" = "cpp" ]; then
assert_version_is_dev
# PROFILER: The main version is stored in s3, though we can not access this in CI
# Not handled for now for system-tests. this handles artifact for parametric
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
echo "https://github.com/DataDog/dd-trace-cpp@$LIBRARY_TARGET_BRANCH" > cpp-load-from-git
echo "Using $(cat cpp-load-from-git)"
elif [ "$TARGET" = "cpp_httpd" ]; then
assert_version_is_dev
get_github_action_artifact "DataDog/httpd-datadog" "dev.yml" "main" "mod_datadog_artifact" "mod_datadog.so"
elif [ "$TARGET" = "cpp_kong" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
echo "Cloning kong-plugin-ddtrace branch ${LIBRARY_TARGET_BRANCH}"
git clone --depth 1 --branch "$LIBRARY_TARGET_BRANCH" \
https://github.com/DataDog/kong-plugin-ddtrace.git kong-plugin-ddtrace
echo "Using kong-plugin-ddtrace@$(git -C kong-plugin-ddtrace rev-parse --short HEAD)"
elif [ "$TARGET" = "cpp_nginx" ]; then
assert_version_is_dev
ARCH=$(arch | sed -e s/x86_64/amd64/ -e s/aarch64/arm64/)
get_github_action_artifact "DataDog/nginx-datadog" "system-tests.yml" "master" "binaries" "binaries.zip" "false"
elif [ "$TARGET" = "agent" ]; then
assert_version_is_dev
AGENT_TARGET_BRANCH="${AGENT_TARGET_BRANCH:-master-py3}"
echo "datadog/agent-dev:$AGENT_TARGET_BRANCH" > agent-image
echo "Using $(cat agent-image) image"
elif [ "$TARGET" = "nodejs" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-master}"
# NPM builds the package, so we put a trigger file that tells install script to get package from github#master
echo "DataDog/dd-trace-js#$LIBRARY_TARGET_BRANCH" > nodejs-load-from-npm
echo "Using $(cat nodejs-load-from-npm)"
elif [ "$TARGET" = "rust" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
echo "$LIBRARY_TARGET_BRANCH" > rust-load-from-git
echo "Using $(cat rust-load-from-git)"
elif [ "$TARGET" = "waf_rule_set_v1" ]; then
exit 1
elif [ "$TARGET" = "waf_rule_set_v2" ]; then
assert_version_is_dev
assert_target_branch_is_not_set
curl --silent \
-H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3.raw" \
--output "waf_rule_set.json" \
https://api.github.com/repos/DataDog/appsec-event-rules/contents/build/recommended.json
elif [ "$TARGET" = "waf_rule_set" ]; then
assert_version_is_dev
assert_target_branch_is_not_set
curl --fail --output "waf_rule_set.json" \
-H "Authorization: token $GITHUB_TOKEN" \
-H "Accept: application/vnd.github.v3.raw" \
https://api.github.com/repos/DataDog/appsec-event-rules/contents/build/recommended.json
elif [ "$TARGET" = "python_lambda" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
get_github_action_artifact "DataDog/datadog-lambda-python" "build_layer.yml" $LIBRARY_TARGET_BRANCH "datadog-lambda-python-3.13-amd64" "datadog_lambda_py-amd64-3.13.zip" "false"
elif [ "$TARGET" = "nodejs_lambda" ]; then
assert_version_is_dev
LIBRARY_TARGET_BRANCH="${LIBRARY_TARGET_BRANCH:-main}"
get_github_action_artifact "DataDog/datadog-lambda-js" "build_layer.yml" $LIBRARY_TARGET_BRANCH "datadog_lambda_node18.12" "datadog_lambda_node18.12.zip" "false"
elif [ "$TARGET" = "otel_collector" ]; then
assert_version_is_dev
assert_target_branch_is_not_set
echo "otel/opentelemetry-collector-contrib:nightly" > otel_collector-image
echo "Using $(cat otel_collector-image) image"
else
echo "Unknown target: $1"
exit 1
fi;