Skip to content

CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java - #6257

Open
guillaume-dequenne wants to merge 5 commits into
masterfrom
CLP-918
Open

guillaume-dequenne wants to merge 5 commits into
masterfrom
CLP-918

Conversation

@guillaume-dequenne

@guillaume-dequenne guillaume-dequenne commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Part of CLP-918

Summary

Validation

  • Workflow YAML parses and git diff --check passes.
  • PR CI validates Edge reachability, token federation, and the integration tests.

Merge SonarSource/ci-github-actions#353 first, then repin this PR to a retained commit or release tag before merging it.

@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Migrate Orchestrator downloads to the JFrog Edge node for sonar-java CLP-1097 Migrate Orchestrator downloads to the JFrog Edge node for sonar-java Sep 28, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

CLP-1097

@datadog-sonarsource

This comment has been minimized.

Comment thread .github/actions/wait-for-artifactory-token-federation/action.yml Outdated
@gitar-bot

gitar-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Code Review ✅ Approved 1 closed / 1 findings

🟡 Medium risk · Ruling and plugin QA now fetch Orchestrator artifacts through authenticated JFrog Edge.

Migrates Orchestrator downloads to JFrog Edge with token federation for ruling and plugin QA jobs, addressing the probe curl timeout issue that could exceed the 2-minute bound. No open issues remain.

✅ 1 closed
✅ Edge Case: Probe curl has no timeout, so the 2-minute bound can be exceeded

📄 .github/actions/wait-for-artifactory-token-federation/action.yml:22-36
The retry loop assumes each attempt is fast: 12 × 10s sleeps, and the failure message says "within 2 minutes". The curl call sets no --connect-timeout or --max-time, though. curl's default connect timeout is 300s and it has no default overall limit, so a slow or unresponsive Edge node can hold one attempt for minutes or indefinitely. The ruling-qa and plugin-qa jobs then stall until the job timeout, and the 2-minute message doesn't match the real behaviour. The 000 retry branch is meant to handle an unreachable Edge, but it only runs after curl returns. Adding per-attempt timeouts fixes this.

Review coverage

🧪 Functional validation 1 of 1 objectives covered

📋 Rules No rules evaluated

🤖 Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ CLP-918 - 1 of 1 objectives covered

This PR covers the migration of Orchestrator downloads to the JFrog Edge node by adding the artifactory token federation wait action and configuring the artifactory URL and access token properties.

✅ 1 covered here
  • ✅ Migrate the Orchestrator's SonarQube download source to the JFrog Edge node
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqube-next

Copy link
Copy Markdown
Contributor

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant