Skip to content

Commit ff58c62

Browse files
authored
Merge pull request #223 from redhat-appstudio/konflux-sa-migration-rhtap-task-runner
Konflux build pipeline service account migration
2 parents 56af3a8 + be6dd79 commit ff58c62

File tree

2 files changed

+80
-91
lines changed

2 files changed

+80
-91
lines changed

.tekton/rhtap-task-runner-pull-request.yaml

Lines changed: 40 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,8 @@ metadata:
88
build.appstudio.redhat.com/target_branch: '{{target_branch}}'
99
pipelinesascode.tekton.dev/max-keep-runs: "3"
1010
pipelinesascode.tekton.dev/on-cel-expression: event == "pull_request" && target_branch
11-
== "main" &&
12-
(
13-
".tekton/rhtap-task-runner-pull-request.yaml".pathChanged() ||
14-
"Dockerfile".pathChanged() ||
15-
"rhtap/***".pathChanged() ||
16-
"tools/***".pathChanged()
11+
== "main" && ( ".tekton/rhtap-task-runner-pull-request.yaml".pathChanged() ||
12+
"Dockerfile".pathChanged() || "rhtap/***".pathChanged() || "tools/***".pathChanged()
1713
)
1814
creationTimestamp: null
1915
labels:
@@ -402,56 +398,54 @@ spec:
402398
- "false"
403399
- name: sast-shell-check
404400
params:
405-
- name: image-digest
406-
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
407-
- name: image-url
408-
value: $(tasks.build-image-index.results.IMAGE_URL)
409-
- name: SOURCE_ARTIFACT
410-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
411-
- name: CACHI2_ARTIFACT
412-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
401+
- name: image-digest
402+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
403+
- name: image-url
404+
value: $(tasks.build-image-index.results.IMAGE_URL)
405+
- name: SOURCE_ARTIFACT
406+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
407+
- name: CACHI2_ARTIFACT
408+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
413409
runAfter:
414-
- build-image-index
410+
- build-image-index
415411
taskRef:
416412
params:
417-
- name: name
418-
value: sast-shell-check-oci-ta
419-
- name: bundle
420-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
421-
- name: kind
422-
value: task
413+
- name: name
414+
value: sast-shell-check-oci-ta
415+
- name: bundle
416+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
417+
- name: kind
418+
value: task
423419
resolver: bundles
424420
when:
425-
- input: $(params.skip-checks)
426-
operator: in
427-
values:
428-
- "false"
429-
workspaces: []
421+
- input: $(params.skip-checks)
422+
operator: in
423+
values:
424+
- "false"
430425
- name: sast-unicode-check
431426
params:
432-
- name: image-url
433-
value: $(tasks.build-image-index.results.IMAGE_URL)
434-
- name: SOURCE_ARTIFACT
435-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
436-
- name: CACHI2_ARTIFACT
437-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
427+
- name: image-url
428+
value: $(tasks.build-image-index.results.IMAGE_URL)
429+
- name: SOURCE_ARTIFACT
430+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
431+
- name: CACHI2_ARTIFACT
432+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
438433
runAfter:
439-
- build-image-index
434+
- build-image-index
440435
taskRef:
441436
params:
442-
- name: name
443-
value: sast-unicode-check-oci-ta
444-
- name: bundle
445-
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
446-
- name: kind
447-
value: task
437+
- name: name
438+
value: sast-unicode-check-oci-ta
439+
- name: bundle
440+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
441+
- name: kind
442+
value: task
448443
resolver: bundles
449444
when:
450-
- input: $(params.skip-checks)
451-
operator: in
452-
values:
453-
- "false"
454-
workspaces: []
445+
- input: $(params.skip-checks)
446+
operator: in
447+
values:
448+
- "false"
455449
- name: clamav-scan
456450
params:
457451
- name: image-digest
@@ -539,7 +533,8 @@ spec:
539533
optional: true
540534
- name: netrc
541535
optional: true
542-
taskRunTemplate: {}
536+
taskRunTemplate:
537+
serviceAccountName: build-pipeline-rhtap-task-runner
543538
workspaces:
544539
- name: git-auth
545540
secret:

.tekton/rhtap-task-runner-push.yaml

Lines changed: 40 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -7,13 +7,8 @@ metadata:
77
build.appstudio.redhat.com/target_branch: '{{target_branch}}'
88
pipelinesascode.tekton.dev/max-keep-runs: "3"
99
pipelinesascode.tekton.dev/on-cel-expression: event == "push" && target_branch
10-
== "main" &&
11-
(
12-
".tekton/rhtap-task-runner-push.yaml".pathChanged() ||
13-
"Dockerfile".pathChanged() ||
14-
"rhtap/***".pathChanged() ||
15-
"tools/***".pathChanged()
16-
)
10+
== "main" && ( ".tekton/rhtap-task-runner-push.yaml".pathChanged() || "Dockerfile".pathChanged()
11+
|| "rhtap/***".pathChanged() || "tools/***".pathChanged() )
1712
creationTimestamp: null
1813
labels:
1914
appstudio.openshift.io/application: rhtap-task-runner
@@ -399,56 +394,54 @@ spec:
399394
- "false"
400395
- name: sast-shell-check
401396
params:
402-
- name: image-digest
403-
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
404-
- name: image-url
405-
value: $(tasks.build-image-index.results.IMAGE_URL)
406-
- name: SOURCE_ARTIFACT
407-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
408-
- name: CACHI2_ARTIFACT
409-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
397+
- name: image-digest
398+
value: $(tasks.build-image-index.results.IMAGE_DIGEST)
399+
- name: image-url
400+
value: $(tasks.build-image-index.results.IMAGE_URL)
401+
- name: SOURCE_ARTIFACT
402+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
403+
- name: CACHI2_ARTIFACT
404+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
410405
runAfter:
411-
- build-image-index
406+
- build-image-index
412407
taskRef:
413408
params:
414-
- name: name
415-
value: sast-shell-check-oci-ta
416-
- name: bundle
417-
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
418-
- name: kind
419-
value: task
409+
- name: name
410+
value: sast-shell-check-oci-ta
411+
- name: bundle
412+
value: quay.io/konflux-ci/tekton-catalog/task-sast-shell-check-oci-ta:0.1@sha256:57b3262138eb06186ae7375f84ca53788bba2a66cfd03d39cb82c78df050aba5
413+
- name: kind
414+
value: task
420415
resolver: bundles
421416
when:
422-
- input: $(params.skip-checks)
423-
operator: in
424-
values:
425-
- "false"
426-
workspaces: []
417+
- input: $(params.skip-checks)
418+
operator: in
419+
values:
420+
- "false"
427421
- name: sast-unicode-check
428422
params:
429-
- name: image-url
430-
value: $(tasks.build-image-index.results.IMAGE_URL)
431-
- name: SOURCE_ARTIFACT
432-
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
433-
- name: CACHI2_ARTIFACT
434-
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
423+
- name: image-url
424+
value: $(tasks.build-image-index.results.IMAGE_URL)
425+
- name: SOURCE_ARTIFACT
426+
value: $(tasks.prefetch-dependencies.results.SOURCE_ARTIFACT)
427+
- name: CACHI2_ARTIFACT
428+
value: $(tasks.prefetch-dependencies.results.CACHI2_ARTIFACT)
435429
runAfter:
436-
- build-image-index
430+
- build-image-index
437431
taskRef:
438432
params:
439-
- name: name
440-
value: sast-unicode-check-oci-ta
441-
- name: bundle
442-
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
443-
- name: kind
444-
value: task
433+
- name: name
434+
value: sast-unicode-check-oci-ta
435+
- name: bundle
436+
value: quay.io/konflux-ci/tekton-catalog/task-sast-unicode-check-oci-ta:0.2@sha256:df185dbe4e2852668f9c46f938dd752e90ea9c79696363378435a6499596c319
437+
- name: kind
438+
value: task
445439
resolver: bundles
446440
when:
447-
- input: $(params.skip-checks)
448-
operator: in
449-
values:
450-
- "false"
451-
workspaces: []
441+
- input: $(params.skip-checks)
442+
operator: in
443+
values:
444+
- "false"
452445
- name: clamav-scan
453446
params:
454447
- name: image-digest
@@ -536,7 +529,8 @@ spec:
536529
optional: true
537530
- name: netrc
538531
optional: true
539-
taskRunTemplate: {}
532+
taskRunTemplate:
533+
serviceAccountName: build-pipeline-rhtap-task-runner
540534
workspaces:
541535
- name: git-auth
542536
secret:

0 commit comments

Comments
 (0)