Sitelet https://github.com/ethereum-optimism/optimism/commit/d4e5c26b9dab5ff6ebe9be8d1f1595b91edd48b8
Skip to content

Commit d4e5c26

Browse files
ci: migrate op-deployer Docker build from CircleCI to GitHub Actions#19329 (#19530)
* op-deployer: atomic Docker build with in-container contract compilation Build contracts inside the Docker image instead of relying on pre-compiled artifacts from CI workspace attachment. Fetches git submodules via shallow blobless clone and runs the full build atomically. Adds libc6-compat for solc glibc compatibility on Alpine. * ci: add op-deployer to GitHub Actions Docker build matrices Add op-deployer to the build, build-fork, and check-cross-platform matrices in branches.yaml, matching the pattern used by all other Go service images. * ci: remove op-deployer Docker build from CircleCI Remove the docker-build job, check-cross-platform job, and scheduled-docker-publish workflow that only served op-deployer. Remove the docker_publish_dispatch parameter from both config files. Preserve contracts-bedrock-build which is still used by other jobs. * ci: remove orphaned ci-docker-tag-op-stack-release.sh Only referenced by the now-removed docker-build job's release step. * remove newline for command clarity * fix: use gitsubmodule code instead of fetching * op-deployer: compile contracts in amd64 stage for cross-platform Docker builds * op-deployer: use glibc-based stage for contract compilation in Docker build * fix: hash comparison --------- Co-authored-by: Federico <14293929+falcorocks@users.noreply.github.com>
1 parent 9cb57b0 commit d4e5c26

7 files changed

Lines changed: 45 additions & 383 deletions

File tree

‎.circleci/config.yml‎

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ parameters:
3838
sdk_dispatch:
3939
type: boolean
4040
default: false
41-
docker_publish_dispatch:
41+
publish_contract_artifacts_dispatch:
4242
type: boolean
4343
default: false
4444
stale_check_dispatch:
@@ -105,8 +105,7 @@ workflows:
105105
.* c-kontrol_dispatch << pipeline.parameters.kontrol_dispatch >> .circleci/continue/main.yml
106106
.* c-cannon_full_test_dispatch << pipeline.parameters.cannon_full_test_dispatch >> .circleci/continue/main.yml
107107
.* c-sdk_dispatch << pipeline.parameters.sdk_dispatch >> .circleci/continue/main.yml
108-
.* c-docker_publish_dispatch << pipeline.parameters.docker_publish_dispatch >> .circleci/continue/main.yml
109-
108+
.* c-publish_contract_artifacts_dispatch << pipeline.parameters.publish_contract_artifacts_dispatch >> .circleci/continue/main.yml
110109
.* c-stale_check_dispatch << pipeline.parameters.stale_check_dispatch >> .circleci/continue/main.yml
111110
.* c-contracts_coverage_dispatch << pipeline.parameters.contracts_coverage_dispatch >> .circleci/continue/main.yml
112111
.* c-heavy_fuzz_dispatch << pipeline.parameters.heavy_fuzz_dispatch >> .circleci/continue/main.yml

‎.circleci/continue/main.yml‎

Lines changed: 1 addition & 329 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ parameters:
3232
c-sdk_dispatch:
3333
type: boolean
3434
default: false
35-
c-docker_publish_dispatch:
35+
c-publish_contract_artifacts_dispatch:
3636
type: boolean
3737
default: false
3838
c-stale_check_dispatch:
@@ -1037,245 +1037,6 @@ jobs:
10371037
- notify-failures-on-develop:
10381038
mentions: "@security-oncall"
10391039

1040-
docker-build:
1041-
environment:
1042-
DOCKER_BUILDKIT: 1
1043-
parameters:
1044-
docker_tags:
1045-
description: Docker image tags, comma-separated
1046-
type: string
1047-
docker_name:
1048-
description: "Docker buildx bake target"
1049-
type: string
1050-
default: ""
1051-
registry:
1052-
description: Docker registry
1053-
type: string
1054-
default: "us-docker.pkg.dev"
1055-
repo:
1056-
description: Docker repo
1057-
type: string
1058-
default: "oplabs-tools-artifacts/images"
1059-
save_image_tag:
1060-
description: Save docker image with given tag
1061-
type: string
1062-
default: ""
1063-
platforms:
1064-
description: Platforms to build for, comma-separated
1065-
type: string
1066-
default: "linux/amd64"
1067-
publish:
1068-
description: Publish the docker image (multi-platform, all tags)
1069-
type: boolean
1070-
default: false
1071-
release:
1072-
description: Run the release script
1073-
type: boolean
1074-
default: false
1075-
resource_class:
1076-
description: Docker resource class
1077-
type: string
1078-
default: medium
1079-
machine:
1080-
image: <<pipeline.parameters.c-base_image>>
1081-
resource_class: "<<parameters.resource_class>>"
1082-
docker_layer_caching: true # we rely on this for faster builds, and actively warm it up for builds with common stages
1083-
steps:
1084-
- utils/checkout-with-mise:
1085-
checkout-method: blobless
1086-
enable-mise-cache: true
1087-
- attach_workspace:
1088-
at: .
1089-
- run:
1090-
command: mkdir -p /tmp/docker_images
1091-
- when:
1092-
condition:
1093-
or:
1094-
- "<<parameters.publish>>"
1095-
- "<<parameters.release>>"
1096-
steps:
1097-
- gcp-cli/install
1098-
- when:
1099-
condition:
1100-
or:
1101-
- "<<parameters.publish>>"
1102-
- "<<parameters.release>>"
1103-
steps:
1104-
- gcp-oidc-authenticate
1105-
- run:
1106-
name: Build
1107-
command: |
1108-
# Check to see if DOCKER_HUB_READ_ONLY_TOKEN is set (i.e. we are in repo) before attempting to use secrets.
1109-
# Building should work without this read only login, but may get rate limited.
1110-
if [[ -v DOCKER_HUB_READ_ONLY_TOKEN ]]; then
1111-
echo "$DOCKER_HUB_READ_ONLY_TOKEN" | docker login -u "$DOCKER_HUB_READ_ONLY_USER" --password-stdin
1112-
fi
1113-
1114-
export REGISTRY="<<parameters.registry>>"
1115-
export REPOSITORY="<<parameters.repo>>"
1116-
export IMAGE_TAGS="$(echo -ne "<<parameters.docker_tags>>" | sed "s/[^a-zA-Z0-9\n,]/-/g")"
1117-
export GIT_COMMIT="$(git rev-parse HEAD)"
1118-
export GIT_DATE="$(git show -s --format='%ct')"
1119-
export PLATFORMS="<<parameters.platforms>>"
1120-
1121-
echo "Checking git tags pointing at $GIT_COMMIT:"
1122-
tags_at_commit=$(git tag --points-at $GIT_COMMIT)
1123-
echo "Tags at commit:\n$tags_at_commit"
1124-
1125-
filtered_tags=$(echo "$tags_at_commit" | grep "^<<parameters.docker_name>>/" || true)
1126-
echo "Filtered tags: $filtered_tags"
1127-
1128-
if [ -z "$filtered_tags" ]; then
1129-
export GIT_VERSION="untagged"
1130-
else
1131-
sorted_tags=$(echo "$filtered_tags" | sed "s/<<parameters.docker_name>>\///" | sort -V)
1132-
echo "Sorted tags: $sorted_tags"
1133-
1134-
# prefer full release tag over "-rc" release candidate tag if both exist
1135-
full_release_tag=$(echo "$sorted_tags" | grep -v -- "-rc" || true)
1136-
if [ -z "$full_release_tag" ]; then
1137-
export GIT_VERSION=$(echo "$sorted_tags" | tail -n 1)
1138-
else
1139-
export GIT_VERSION=$(echo "$full_release_tag" | tail -n 1)
1140-
fi
1141-
fi
1142-
1143-
echo "Setting GIT_VERSION=$GIT_VERSION"
1144-
1145-
# Create, start (bootstrap) and use a *named* docker builder
1146-
# This allows us to cross-build multi-platform,
1147-
# and naming allows us to use the DLC (docker-layer-cache)
1148-
docker buildx create --driver=docker-container --name=buildx-build --bootstrap --use
1149-
1150-
DOCKER_OUTPUT_DESTINATION=""
1151-
if [ "<<parameters.publish>>" == "true" ]; then
1152-
gcloud auth configure-docker <<parameters.registry>>
1153-
echo "Building for platforms $PLATFORMS and then publishing to registry"
1154-
DOCKER_OUTPUT_DESTINATION="--push"
1155-
if [ "<<parameters.save_image_tag>>" != "" ]; then
1156-
echo "ERROR: cannot save image to docker when publishing to registry"
1157-
exit 1
1158-
fi
1159-
else
1160-
if [ "<<parameters.save_image_tag>>" == "" ]; then
1161-
echo "Running $PLATFORMS build without destination (cache warm-up)"
1162-
DOCKER_OUTPUT_DESTINATION=""
1163-
elif [[ $PLATFORMS == *,* ]]; then
1164-
echo "ERROR: cannot perform multi-arch (platforms: $PLATFORMS) build while also loading the result into regular docker"
1165-
exit 1
1166-
else
1167-
echo "Running single-platform $PLATFORMS build and loading into docker"
1168-
DOCKER_OUTPUT_DESTINATION="--load"
1169-
fi
1170-
fi
1171-
1172-
# Let them cook!
1173-
docker buildx bake \
1174-
--progress plain \
1175-
--builder=buildx-build \
1176-
-f docker-bake.hcl \
1177-
$DOCKER_OUTPUT_DESTINATION \
1178-
<<parameters.docker_name>>
1179-
1180-
no_output_timeout: 45m
1181-
- when:
1182-
condition: "<<parameters.publish>>"
1183-
steps:
1184-
- notify-failures-on-develop
1185-
- when:
1186-
condition: "<<parameters.save_image_tag>>"
1187-
steps:
1188-
- run:
1189-
name: Save
1190-
command: |
1191-
IMAGE_NAME="<<parameters.registry>>/<<parameters.repo>>/<<parameters.docker_name>>:<<parameters.save_image_tag>>"
1192-
docker save -o /tmp/docker_images/<<parameters.docker_name>>.tar $IMAGE_NAME
1193-
- persist_to_workspace:
1194-
root: /tmp/docker_images
1195-
paths: # only write the one file, to avoid concurrent workspace-file additions
1196-
- "<<parameters.docker_name>>.tar"
1197-
- when:
1198-
condition: "<<parameters.release>>"
1199-
steps:
1200-
- run:
1201-
name: Tag
1202-
command: |
1203-
./ops/scripts/ci-docker-tag-op-stack-release.sh <<parameters.registry>>/<<parameters.repo>> $CIRCLE_TAG $CIRCLE_SHA1
1204-
- when:
1205-
condition:
1206-
or:
1207-
- and:
1208-
- "<<parameters.publish>>"
1209-
- "<<parameters.release>>"
1210-
- and:
1211-
- "<<parameters.publish>>"
1212-
- equal: [develop, << pipeline.git.branch >>]
1213-
steps:
1214-
- gcp-oidc-authenticate:
1215-
service_account_email: GCP_SERVICE_ATTESTOR_ACCOUNT_EMAIL
1216-
- run:
1217-
name: Sign
1218-
command: |
1219-
VER=$(yq '.tools.binary_signer' mise.toml)
1220-
wget -O - "https://github.com/ethereum-optimism/binary_signer/archive/refs/tags/v${VER}.tar.gz" | tar xz
1221-
cd "binary_signer-${VER}/signer"
1222-
1223-
IMAGE_PATH="<<parameters.registry>>/<<parameters.repo>>/<<parameters.docker_name>>:<<pipeline.git.revision>>"
1224-
echo $IMAGE_PATH
1225-
pip3 install -r requirements.txt
1226-
1227-
python3 ./sign_image.py --command="sign"\
1228-
--attestor-project-name="$ATTESTOR_PROJECT_NAME"\
1229-
--attestor-name="$ATTESTOR_NAME"\
1230-
--image-path="$IMAGE_PATH"\
1231-
--signer-logging-level="INFO"\
1232-
--attestor-key-id="//cloudkms.googleapis.com/v1/projects/$ATTESTOR_PROJECT_NAME/locations/global/keyRings/$ATTESTOR_NAME-key-ring/cryptoKeys/$ATTESTOR_NAME-key/cryptoKeyVersions/1"
1233-
1234-
# Verify newly published images (built on AMD machine) will run on ARM
1235-
check-cross-platform:
1236-
docker:
1237-
- image: <<pipeline.parameters.c-default_docker_image>>
1238-
resource_class: arm.medium
1239-
parameters:
1240-
registry:
1241-
description: Docker registry
1242-
type: string
1243-
default: "us-docker.pkg.dev"
1244-
repo:
1245-
description: Docker repo
1246-
type: string
1247-
default: "oplabs-tools-artifacts/images"
1248-
op_component:
1249-
description: "Name of op-stack component (e.g. op-node)"
1250-
type: string
1251-
default: ""
1252-
docker_tag:
1253-
description: "Tag of docker image"
1254-
type: string
1255-
default: "<<pipeline.git.revision>>"
1256-
steps:
1257-
- setup_remote_docker
1258-
- run:
1259-
name: "Verify Image Platform"
1260-
command: |
1261-
image_name="<<parameters.registry>>/<<parameters.repo>>/<<parameters.op_component>>:<<parameters.docker_tag>>"
1262-
echo "Retrieving Docker image manifest: $image_name"
1263-
MANIFEST=$(docker manifest inspect $image_name)
1264-
1265-
echo "Verifying 'linux/arm64' is supported..."
1266-
SUPPORTED_PLATFORM=$(echo "$MANIFEST" | jq -r '.manifests[] | select(.platform.architecture == "arm64" and .platform.os == "linux")')
1267-
echo $SUPPORT_PLATFORM
1268-
if [ -z "$SUPPORTED_PLATFORM" ]; then
1269-
echo "Platform 'linux/arm64' not supported by this image"
1270-
exit 1
1271-
fi
1272-
- run:
1273-
name: "Pull and run docker image"
1274-
command: |
1275-
image_name="<<parameters.registry>>/<<parameters.repo>>/<<parameters.op_component>>:<<parameters.docker_tag>>"
1276-
docker pull $image_name || exit 1
1277-
docker run $image_name <<parameters.op_component>> --version || exit 1
1278-
12791040
contracts-bedrock-tests:
12801041
circleci_ip_ranges: true
12811042
docker:
@@ -3129,18 +2890,6 @@ workflows:
31292890
- sanitize-op-program
31302891
context:
31312892
- circleci-repo-readonly-authenticated-github-tokens
3132-
- docker-build:
3133-
name: <<matrix.docker_name>>-docker-build
3134-
docker_tags: <<pipeline.git.revision>>,<<pipeline.git.branch>>
3135-
save_image_tag: <<pipeline.git.revision>>
3136-
matrix:
3137-
parameters:
3138-
docker_name:
3139-
- op-deployer
3140-
context:
3141-
- circleci-repo-readonly-authenticated-github-token
3142-
requires:
3143-
- contracts-bedrock-build
31442893
- cannon-prestate:
31452894
context:
31462895
- circleci-repo-readonly-authenticated-github-token
@@ -3330,47 +3079,6 @@ workflows:
33303079
only: /^(da-server|cannon|ufm-[a-z0-9\-]*|op-[a-z0-9\-]*)\/v.*/
33313080
branches:
33323081
ignore: /.*/
3333-
- contracts-bedrock-build:
3334-
context:
3335-
- circleci-repo-readonly-authenticated-github-token
3336-
requires:
3337-
- initialize
3338-
filters:
3339-
tags:
3340-
only: /^op-deployer.*/ # ensure contract artifacts are embedded in op-deployer binary
3341-
branches:
3342-
ignore: /.*/
3343-
- docker-build:
3344-
matrix:
3345-
parameters:
3346-
docker_name:
3347-
- op-deployer
3348-
name: <<matrix.docker_name>>-docker-release
3349-
docker_tags: <<pipeline.git.revision>>
3350-
platforms: "linux/amd64,linux/arm64"
3351-
publish: true
3352-
release: true
3353-
filters:
3354-
tags:
3355-
only: /^<<matrix.docker_name>>\/v.*/
3356-
branches:
3357-
ignore: /.*/
3358-
context:
3359-
- oplabs-gcr-release
3360-
- circleci-repo-readonly-authenticated-github-token
3361-
requires:
3362-
- initialize
3363-
- contracts-bedrock-build
3364-
- check-cross-platform:
3365-
matrix:
3366-
parameters:
3367-
op_component:
3368-
- op-deployer
3369-
name: <<matrix.op_component>>-cross-platform
3370-
requires:
3371-
- op-deployer-docker-release
3372-
context:
3373-
- circleci-repo-readonly-authenticated-github-token
33743082
- cannon-prestate:
33753083
filters:
33763084
tags:
@@ -3495,42 +3203,6 @@ workflows:
34953203
- slack
34963204
- circleci-repo-readonly-authenticated-github-token
34973205

3498-
scheduled-docker-publish:
3499-
when:
3500-
or:
3501-
- equal: [build_daily, <<pipeline.schedule.name>>]
3502-
# Trigger on manual triggers if explicitly requested
3503-
- equal: [true, << pipeline.parameters.c-docker_publish_dispatch >>]
3504-
jobs:
3505-
- contracts-bedrock-build:
3506-
context:
3507-
- circleci-repo-readonly-authenticated-github-token
3508-
- docker-build:
3509-
matrix:
3510-
parameters:
3511-
docker_name:
3512-
- op-deployer
3513-
name: <<matrix.docker_name>>-docker-publish
3514-
docker_tags: <<pipeline.git.revision>>,<<pipeline.git.branch>>
3515-
platforms: "linux/amd64,linux/arm64"
3516-
publish: true
3517-
context:
3518-
- oplabs-gcr
3519-
- slack
3520-
- circleci-repo-readonly-authenticated-github-token
3521-
requires:
3522-
- contracts-bedrock-build
3523-
- check-cross-platform:
3524-
matrix:
3525-
parameters:
3526-
op_component:
3527-
- op-deployer
3528-
name: <<matrix.op_component>>-cross-platform
3529-
requires:
3530-
- <<matrix.op_component>>-docker-publish
3531-
context:
3532-
- circleci-repo-readonly-authenticated-github-token
3533-
35343206
scheduled-flake-shake:
35353207
when:
35363208
or:

0 commit comments

Comments
 (0)