@@ -32,7 +32,7 @@ parameters:
3232 c-sdk_dispatch :
3333 type : boolean
3434 default : false
35- c-docker_publish_dispatch :
35+ c-publish_contract_artifacts_dispatch :
3636 type : boolean
3737 default : false
3838 c-stale_check_dispatch :
@@ -1037,245 +1037,6 @@ jobs:
10371037 - notify-failures-on-develop :
10381038 mentions : " @security-oncall"
10391039
1040- docker-build :
1041- environment :
1042- DOCKER_BUILDKIT : 1
1043- parameters :
1044- docker_tags :
1045- description : Docker image tags, comma-separated
1046- type : string
1047- docker_name :
1048- description : " Docker buildx bake target"
1049- type : string
1050- default : " "
1051- registry :
1052- description : Docker registry
1053- type : string
1054- default : " us-docker.pkg.dev"
1055- repo :
1056- description : Docker repo
1057- type : string
1058- default : " oplabs-tools-artifacts/images"
1059- save_image_tag :
1060- description : Save docker image with given tag
1061- type : string
1062- default : " "
1063- platforms :
1064- description : Platforms to build for, comma-separated
1065- type : string
1066- default : " linux/amd64"
1067- publish :
1068- description : Publish the docker image (multi-platform, all tags)
1069- type : boolean
1070- default : false
1071- release :
1072- description : Run the release script
1073- type : boolean
1074- default : false
1075- resource_class :
1076- description : Docker resource class
1077- type : string
1078- default : medium
1079- machine :
1080- image : <<pipeline.parameters.c-base_image>>
1081- resource_class : " <<parameters.resource_class>>"
1082- docker_layer_caching : true # we rely on this for faster builds, and actively warm it up for builds with common stages
1083- steps :
1084- - utils/checkout-with-mise :
1085- checkout-method : blobless
1086- enable-mise-cache : true
1087- - attach_workspace :
1088- at : .
1089- - run :
1090- command : mkdir -p /tmp/docker_images
1091- - when :
1092- condition :
1093- or :
1094- - " <<parameters.publish>>"
1095- - " <<parameters.release>>"
1096- steps :
1097- - gcp-cli/install
1098- - when :
1099- condition :
1100- or :
1101- - " <<parameters.publish>>"
1102- - " <<parameters.release>>"
1103- steps :
1104- - gcp-oidc-authenticate
1105- - run :
1106- name : Build
1107- command : |
1108- # Check to see if DOCKER_HUB_READ_ONLY_TOKEN is set (i.e. we are in repo) before attempting to use secrets.
1109- # Building should work without this read only login, but may get rate limited.
1110- if [[ -v DOCKER_HUB_READ_ONLY_TOKEN ]]; then
1111- echo "$DOCKER_HUB_READ_ONLY_TOKEN" | docker login -u "$DOCKER_HUB_READ_ONLY_USER" --password-stdin
1112- fi
1113-
1114- export REGISTRY="<<parameters.registry>>"
1115- export REPOSITORY="<<parameters.repo>>"
1116- export IMAGE_TAGS="$(echo -ne "<<parameters.docker_tags>>" | sed "s/[^a-zA-Z0-9\n,]/-/g")"
1117- export GIT_COMMIT="$(git rev-parse HEAD)"
1118- export GIT_DATE="$(git show -s --format='%ct')"
1119- export PLATFORMS="<<parameters.platforms>>"
1120-
1121- echo "Checking git tags pointing at $GIT_COMMIT:"
1122- tags_at_commit=$(git tag --points-at $GIT_COMMIT)
1123- echo "Tags at commit:\n$tags_at_commit"
1124-
1125- filtered_tags=$(echo "$tags_at_commit" | grep "^<<parameters.docker_name>>/" || true)
1126- echo "Filtered tags: $filtered_tags"
1127-
1128- if [ -z "$filtered_tags" ]; then
1129- export GIT_VERSION="untagged"
1130- else
1131- sorted_tags=$(echo "$filtered_tags" | sed "s/<<parameters.docker_name>>\///" | sort -V)
1132- echo "Sorted tags: $sorted_tags"
1133-
1134- # prefer full release tag over "-rc" release candidate tag if both exist
1135- full_release_tag=$(echo "$sorted_tags" | grep -v -- "-rc" || true)
1136- if [ -z "$full_release_tag" ]; then
1137- export GIT_VERSION=$(echo "$sorted_tags" | tail -n 1)
1138- else
1139- export GIT_VERSION=$(echo "$full_release_tag" | tail -n 1)
1140- fi
1141- fi
1142-
1143- echo "Setting GIT_VERSION=$GIT_VERSION"
1144-
1145- # Create, start (bootstrap) and use a *named* docker builder
1146- # This allows us to cross-build multi-platform,
1147- # and naming allows us to use the DLC (docker-layer-cache)
1148- docker buildx create --driver=docker-container --name=buildx-build --bootstrap --use
1149-
1150- DOCKER_OUTPUT_DESTINATION=""
1151- if [ "<<parameters.publish>>" == "true" ]; then
1152- gcloud auth configure-docker <<parameters.registry>>
1153- echo "Building for platforms $PLATFORMS and then publishing to registry"
1154- DOCKER_OUTPUT_DESTINATION="--push"
1155- if [ "<<parameters.save_image_tag>>" != "" ]; then
1156- echo "ERROR: cannot save image to docker when publishing to registry"
1157- exit 1
1158- fi
1159- else
1160- if [ "<<parameters.save_image_tag>>" == "" ]; then
1161- echo "Running $PLATFORMS build without destination (cache warm-up)"
1162- DOCKER_OUTPUT_DESTINATION=""
1163- elif [[ $PLATFORMS == *,* ]]; then
1164- echo "ERROR: cannot perform multi-arch (platforms: $PLATFORMS) build while also loading the result into regular docker"
1165- exit 1
1166- else
1167- echo "Running single-platform $PLATFORMS build and loading into docker"
1168- DOCKER_OUTPUT_DESTINATION="--load"
1169- fi
1170- fi
1171-
1172- # Let them cook!
1173- docker buildx bake \
1174- --progress plain \
1175- --builder=buildx-build \
1176- -f docker-bake.hcl \
1177- $DOCKER_OUTPUT_DESTINATION \
1178- <<parameters.docker_name>>
1179-
1180- no_output_timeout : 45m
1181- - when :
1182- condition : " <<parameters.publish>>"
1183- steps :
1184- - notify-failures-on-develop
1185- - when :
1186- condition : " <<parameters.save_image_tag>>"
1187- steps :
1188- - run :
1189- name : Save
1190- command : |
1191- IMAGE_NAME="<<parameters.registry>>/<<parameters.repo>>/<<parameters.docker_name>>:<<parameters.save_image_tag>>"
1192- docker save -o /tmp/docker_images/<<parameters.docker_name>>.tar $IMAGE_NAME
1193- - persist_to_workspace :
1194- root : /tmp/docker_images
1195- paths : # only write the one file, to avoid concurrent workspace-file additions
1196- - " <<parameters.docker_name>>.tar"
1197- - when :
1198- condition : " <<parameters.release>>"
1199- steps :
1200- - run :
1201- name : Tag
1202- command : |
1203- ./ops/scripts/ci-docker-tag-op-stack-release.sh <<parameters.registry>>/<<parameters.repo>> $CIRCLE_TAG $CIRCLE_SHA1
1204- - when :
1205- condition :
1206- or :
1207- - and :
1208- - " <<parameters.publish>>"
1209- - " <<parameters.release>>"
1210- - and :
1211- - " <<parameters.publish>>"
1212- - equal : [develop, << pipeline.git.branch >>]
1213- steps :
1214- - gcp-oidc-authenticate :
1215- service_account_email : GCP_SERVICE_ATTESTOR_ACCOUNT_EMAIL
1216- - run :
1217- name : Sign
1218- command : |
1219- VER=$(yq '.tools.binary_signer' mise.toml)
1220- wget -O - "https://github.com/ethereum-optimism/binary_signer/archive/refs/tags/v${VER}.tar.gz" | tar xz
1221- cd "binary_signer-${VER}/signer"
1222-
1223- IMAGE_PATH="<<parameters.registry>>/<<parameters.repo>>/<<parameters.docker_name>>:<<pipeline.git.revision>>"
1224- echo $IMAGE_PATH
1225- pip3 install -r requirements.txt
1226-
1227- python3 ./sign_image.py --command="sign"\
1228- --attestor-project-name="$ATTESTOR_PROJECT_NAME"\
1229- --attestor-name="$ATTESTOR_NAME"\
1230- --image-path="$IMAGE_PATH"\
1231- --signer-logging-level="INFO"\
1232- --attestor-key-id="//cloudkms.googleapis.com/v1/projects/$ATTESTOR_PROJECT_NAME/locations/global/keyRings/$ATTESTOR_NAME-key-ring/cryptoKeys/$ATTESTOR_NAME-key/cryptoKeyVersions/1"
1233-
1234- # Verify newly published images (built on AMD machine) will run on ARM
1235- check-cross-platform :
1236- docker :
1237- - image : <<pipeline.parameters.c-default_docker_image>>
1238- resource_class : arm.medium
1239- parameters :
1240- registry :
1241- description : Docker registry
1242- type : string
1243- default : " us-docker.pkg.dev"
1244- repo :
1245- description : Docker repo
1246- type : string
1247- default : " oplabs-tools-artifacts/images"
1248- op_component :
1249- description : " Name of op-stack component (e.g. op-node)"
1250- type : string
1251- default : " "
1252- docker_tag :
1253- description : " Tag of docker image"
1254- type : string
1255- default : " <<pipeline.git.revision>>"
1256- steps :
1257- - setup_remote_docker
1258- - run :
1259- name : " Verify Image Platform"
1260- command : |
1261- image_name="<<parameters.registry>>/<<parameters.repo>>/<<parameters.op_component>>:<<parameters.docker_tag>>"
1262- echo "Retrieving Docker image manifest: $image_name"
1263- MANIFEST=$(docker manifest inspect $image_name)
1264-
1265- echo "Verifying 'linux/arm64' is supported..."
1266- SUPPORTED_PLATFORM=$(echo "$MANIFEST" | jq -r '.manifests[] | select(.platform.architecture == "arm64" and .platform.os == "linux")')
1267- echo $SUPPORT_PLATFORM
1268- if [ -z "$SUPPORTED_PLATFORM" ]; then
1269- echo "Platform 'linux/arm64' not supported by this image"
1270- exit 1
1271- fi
1272- - run :
1273- name : " Pull and run docker image"
1274- command : |
1275- image_name="<<parameters.registry>>/<<parameters.repo>>/<<parameters.op_component>>:<<parameters.docker_tag>>"
1276- docker pull $image_name || exit 1
1277- docker run $image_name <<parameters.op_component>> --version || exit 1
1278-
12791040 contracts-bedrock-tests :
12801041 circleci_ip_ranges : true
12811042 docker :
@@ -3129,18 +2890,6 @@ workflows:
31292890 - sanitize-op-program
31302891 context :
31312892 - circleci-repo-readonly-authenticated-github-tokens
3132- - docker-build :
3133- name : <<matrix.docker_name>>-docker-build
3134- docker_tags : <<pipeline.git.revision>>,<<pipeline.git.branch>>
3135- save_image_tag : <<pipeline.git.revision>>
3136- matrix :
3137- parameters :
3138- docker_name :
3139- - op-deployer
3140- context :
3141- - circleci-repo-readonly-authenticated-github-token
3142- requires :
3143- - contracts-bedrock-build
31442893 - cannon-prestate :
31452894 context :
31462895 - circleci-repo-readonly-authenticated-github-token
@@ -3330,47 +3079,6 @@ workflows:
33303079 only : /^(da-server|cannon|ufm-[a-z0-9\-]*|op-[a-z0-9\-]*)\/v.*/
33313080 branches :
33323081 ignore : /.*/
3333- - contracts-bedrock-build :
3334- context :
3335- - circleci-repo-readonly-authenticated-github-token
3336- requires :
3337- - initialize
3338- filters :
3339- tags :
3340- only : /^op-deployer.*/ # ensure contract artifacts are embedded in op-deployer binary
3341- branches :
3342- ignore : /.*/
3343- - docker-build :
3344- matrix :
3345- parameters :
3346- docker_name :
3347- - op-deployer
3348- name : <<matrix.docker_name>>-docker-release
3349- docker_tags : <<pipeline.git.revision>>
3350- platforms : " linux/amd64,linux/arm64"
3351- publish : true
3352- release : true
3353- filters :
3354- tags :
3355- only : /^<<matrix.docker_name>>\/v.*/
3356- branches :
3357- ignore : /.*/
3358- context :
3359- - oplabs-gcr-release
3360- - circleci-repo-readonly-authenticated-github-token
3361- requires :
3362- - initialize
3363- - contracts-bedrock-build
3364- - check-cross-platform :
3365- matrix :
3366- parameters :
3367- op_component :
3368- - op-deployer
3369- name : <<matrix.op_component>>-cross-platform
3370- requires :
3371- - op-deployer-docker-release
3372- context :
3373- - circleci-repo-readonly-authenticated-github-token
33743082 - cannon-prestate :
33753083 filters :
33763084 tags :
@@ -3495,42 +3203,6 @@ workflows:
34953203 - slack
34963204 - circleci-repo-readonly-authenticated-github-token
34973205
3498- scheduled-docker-publish :
3499- when :
3500- or :
3501- - equal : [build_daily, <<pipeline.schedule.name>>]
3502- # Trigger on manual triggers if explicitly requested
3503- - equal : [true, << pipeline.parameters.c-docker_publish_dispatch >>]
3504- jobs :
3505- - contracts-bedrock-build :
3506- context :
3507- - circleci-repo-readonly-authenticated-github-token
3508- - docker-build :
3509- matrix :
3510- parameters :
3511- docker_name :
3512- - op-deployer
3513- name : <<matrix.docker_name>>-docker-publish
3514- docker_tags : <<pipeline.git.revision>>,<<pipeline.git.branch>>
3515- platforms : " linux/amd64,linux/arm64"
3516- publish : true
3517- context :
3518- - oplabs-gcr
3519- - slack
3520- - circleci-repo-readonly-authenticated-github-token
3521- requires :
3522- - contracts-bedrock-build
3523- - check-cross-platform :
3524- matrix :
3525- parameters :
3526- op_component :
3527- - op-deployer
3528- name : <<matrix.op_component>>-cross-platform
3529- requires :
3530- - <<matrix.op_component>>-docker-publish
3531- context :
3532- - circleci-repo-readonly-authenticated-github-token
3533-
35343206 scheduled-flake-shake :
35353207 when :
35363208 or :
0 commit comments