Skip to content

CLP-1102 Migrate Orchestrator downloads to the JFrog Edge node for sonar-rust - #401

Open
guillaume-dequenne wants to merge 5 commits into
masterfrom
CLP-918
Open

guillaume-dequenne wants to merge 5 commits into
masterfrom
CLP-918

Conversation

@guillaume-dequenne

@guillaume-dequenne guillaume-dequenne commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Part of CLP-918

Summary

Validation

  • Workflow YAML parses and git diff --check passes.
  • The current PR Build passed all E2E jobs with the shared-action replacement.

Merge SonarSource/ci-github-actions#353 first, then repin this PR to a retained commit or release tag before merging it.

@hashicorp-vault-sonar-prod hashicorp-vault-sonar-prod Bot changed the title Migrate Orchestrator downloads to the JFrog Edge node for sonar-rust CLP-1102 Migrate Orchestrator downloads to the JFrog Edge node for sonar-rust Sep 28, 2026
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

CLP-1102

@datadog-sonarsource

This comment has been minimized.

Comment thread .github/actions/wait-for-artifactory-token-federation/action.yml Outdated
@gitar-bot

gitar-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Code Review ✅ Approved 1 closed / 1 findings

🟡 Medium risk · CI E2E jobs change the authenticated Orchestrator artifact source to JFrog Edge.

Migrates Orchestrator downloads to JFrog Edge for Linux and Windows E2E jobs while keeping ARM on its current source. Resolves the probe curl timeout issue to enforce the promised 2-minute limit. No issues remain.

✅ 1 closed
✅ Edge Case: Probe curl has no timeout, so the promised 2-minute limit can be exceeded

📄 .github/actions/wait-for-artifactory-token-federation/action.yml:22-36
Each probe calls curl --silent with no --max-time or --connect-timeout. curl has no overall timeout by default, and its default connect timeout is 300s. If the Edge node accepts the connection and then stalls, or the TCP handshake hangs, a single attempt can block for minutes or until the job timeout. That breaks the step's promise that it gives up "within 2 minutes". The loop also sleeps another 10s after the 12th failed attempt before exiting. Fix: add --connect-timeout 5 --max-time 10 to the curl call so a stalled request falls into the existing 000 retry branch, and skip the sleep on the last attempt.

Review coverage

🧪 Functional validation 1 of 1 objectives covered

📋 Rules No rules evaluated

🤖 Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ CLP-918 - 1 of 1 objectives covered

This PR covers the migration of Orchestrator downloads to the JFrog Edge node for sonar-rust.

✅ 1 covered here
  • ✅ Migrate Orchestrator downloads to the JFrog Edge node for sonar-rust
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqube-next

Copy link
Copy Markdown

Quality Gate passed Quality Gate passed for 'sonar-rust'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant