Workaround for allowing BuildBuddy fetch of the Docker build image After the upgrade of the on-prem BuildBuddy runner to enterprise-v2.312.0, the fetch of the container specified in Gerrit's tools/remote/BUILD under the platform's exec_properties container-image. See the official BuildBuddy documentation on how to use credentials for fetching Docker images from GCR at [1]. [1] https://www.buildbuddy.io/docs/rbe-platforms/ Change-Id: I75db4ca8526cdcb6a85b8aacb9e350705a3ab9f4
diff --git a/jenkins/gerrit-bazel-build.sh b/jenkins/gerrit-bazel-build.sh index d31d6fa..25ceb3e 100644 --- a/jenkins/gerrit-bazel-build.sh +++ b/jenkins/gerrit-bazel-build.sh
@@ -35,7 +35,12 @@ if [[ "$MODE" == *"rbe"* ]] then - bazelisk build --config=remote_bb --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY plugins:core release api + # Workaround to Docker executor pull issue: + # error getting credentials - err: exit status 1, out: `docker-credential-gcr/helper: could not retrieve GCR's access token: + # docker-credential-gcr/helper: failed to detect default credentials: credentials: could not find default credentials. + export BB_GCR_WORKAROUND="--remote_exec_header=x-buildbuddy-platform.container-registry-username=_dcgcloud_token --remote_exec_header=x-buildbuddy-platform.container-registry-password=foo" + + bazelisk build --config=remote_bb $BB_GCR_WORKAROUND --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY plugins:core release api elif [[ "$MODE" == *"polygerrit"* ]] then echo "Skipping building eclipse and maven"
diff --git a/jenkins/gerrit-bazel-test.sh b/jenkins/gerrit-bazel-test.sh index c6846ea..3edfca9 100755 --- a/jenkins/gerrit-bazel-test.sh +++ b/jenkins/gerrit-bazel-test.sh
@@ -9,8 +9,14 @@ . set-java.sh --branch "{branch}" +# Workaround to Docker executor pull issue: +# error getting credentials - err: exit status 1, out: `docker-credential-gcr/helper: could not retrieve GCR's access token: +# docker-credential-gcr/helper: failed to detect default credentials: credentials: could not find default credentials. +export BB_GCR_WORKAROUND="--remote_exec_header=x-buildbuddy-platform.container-registry-username=_dcgcloud_token --remote_exec_header=x-buildbuddy-platform.container-registry-password=foo" + export BAZEL_OPTS="$(echo $BAZEL_OPTS | xargs) \ --config=remote_bb \ + $BB_GCR_WORKAROUND \ --jobs=50 \ --remote_header=x-buildbuddy-api-key=$BB_API_KEY \ --flaky_test_attempts 3 \
diff --git a/jenkins/gerrit-bazel-verifier-test.sh b/jenkins/gerrit-bazel-verifier-test.sh index 4f3cc97..38f3a25 100755 --- a/jenkins/gerrit-bazel-verifier-test.sh +++ b/jenkins/gerrit-bazel-verifier-test.sh
@@ -10,7 +10,13 @@ case $TARGET_BRANCH$MODE in masterrbe|stable-3.12rbe|stable-3.13rbe|stable-3.14rbe) TEST_TAG_FILTER="-flaky,-elastic,-no_rbe,-lucene" - BAZEL_OPTS="$BAZEL_OPTS --config=remote_bb --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY" + + # Workaround to Docker executor pull issue: + # error getting credentials - err: exit status 1, out: `docker-credential-gcr/helper: could not retrieve GCR's access token: + # docker-credential-gcr/helper: failed to detect default credentials: credentials: could not find default credentials. + export BB_GCR_WORKAROUND="--remote_exec_header=x-buildbuddy-platform.container-registry-username=_dcgcloud_token --remote_exec_header=x-buildbuddy-platform.container-registry-password=foo" + + BAZEL_OPTS="$BAZEL_OPTS --config=remote_bb --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY $BB_GCR_WORKAROUND" ;; masternotedb|stable-3.12notedb|stable-3.13notedb|stable-3.14notedb) TEST_TAG_FILTER="-flaky,elastic,no_rbe"