Workaround for allowing BuildBuddy fetch of the Docker build image

After the upgrade of the on-prem BuildBuddy runner to
enterprise-v2.312.0, the fetch of the container specified in Gerrit's
tools/remote/BUILD under the platform's exec_properties container-image.

See the official BuildBuddy documentation on how to use credentials for
fetching Docker images from GCR at [1].

[1] https://www.buildbuddy.io/docs/rbe-platforms/

Change-Id: I75db4ca8526cdcb6a85b8aacb9e350705a3ab9f4
diff --git a/jenkins/gerrit-bazel-build.sh b/jenkins/gerrit-bazel-build.sh
index d31d6fa..25ceb3e 100644
--- a/jenkins/gerrit-bazel-build.sh
+++ b/jenkins/gerrit-bazel-build.sh
@@ -35,7 +35,12 @@
 
 if [[ "$MODE" == *"rbe"* ]]
 then
-  bazelisk build --config=remote_bb --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY plugins:core release api
+  # Workaround to Docker executor pull issue:
+  # error getting credentials - err: exit status 1, out: `docker-credential-gcr/helper: could not retrieve GCR's access token:
+  # docker-credential-gcr/helper: failed to detect default credentials: credentials: could not find default credentials.
+  export BB_GCR_WORKAROUND="--remote_exec_header=x-buildbuddy-platform.container-registry-username=_dcgcloud_token --remote_exec_header=x-buildbuddy-platform.container-registry-password=foo"
+
+  bazelisk build --config=remote_bb $BB_GCR_WORKAROUND --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY plugins:core release api
 elif [[ "$MODE" == *"polygerrit"* ]]
 then
   echo "Skipping building eclipse and maven"
diff --git a/jenkins/gerrit-bazel-test.sh b/jenkins/gerrit-bazel-test.sh
index c6846ea..3edfca9 100755
--- a/jenkins/gerrit-bazel-test.sh
+++ b/jenkins/gerrit-bazel-test.sh
@@ -9,8 +9,14 @@
 
 . set-java.sh --branch "{branch}"
 
+# Workaround to Docker executor pull issue:
+# error getting credentials - err: exit status 1, out: `docker-credential-gcr/helper: could not retrieve GCR's access token:
+# docker-credential-gcr/helper: failed to detect default credentials: credentials: could not find default credentials.
+export BB_GCR_WORKAROUND="--remote_exec_header=x-buildbuddy-platform.container-registry-username=_dcgcloud_token --remote_exec_header=x-buildbuddy-platform.container-registry-password=foo"
+
 export BAZEL_OPTS="$(echo $BAZEL_OPTS | xargs) \
                    --config=remote_bb \
+                   $BB_GCR_WORKAROUND \
                    --jobs=50 \
                    --remote_header=x-buildbuddy-api-key=$BB_API_KEY \
                    --flaky_test_attempts 3 \
diff --git a/jenkins/gerrit-bazel-verifier-test.sh b/jenkins/gerrit-bazel-verifier-test.sh
index 4f3cc97..38f3a25 100755
--- a/jenkins/gerrit-bazel-verifier-test.sh
+++ b/jenkins/gerrit-bazel-verifier-test.sh
@@ -10,7 +10,13 @@
 case $TARGET_BRANCH$MODE in
   masterrbe|stable-3.12rbe|stable-3.13rbe|stable-3.14rbe)
     TEST_TAG_FILTER="-flaky,-elastic,-no_rbe,-lucene"
-    BAZEL_OPTS="$BAZEL_OPTS --config=remote_bb --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY"
+
+    # Workaround to Docker executor pull issue:
+    # error getting credentials - err: exit status 1, out: `docker-credential-gcr/helper: could not retrieve GCR's access token:
+    # docker-credential-gcr/helper: failed to detect default credentials: credentials: could not find default credentials.
+    export BB_GCR_WORKAROUND="--remote_exec_header=x-buildbuddy-platform.container-registry-username=_dcgcloud_token --remote_exec_header=x-buildbuddy-platform.container-registry-password=foo"
+
+    BAZEL_OPTS="$BAZEL_OPTS --config=remote_bb --jobs=50 --remote_header=x-buildbuddy-api-key=$BB_API_KEY $BB_GCR_WORKAROUND"
     ;;
   masternotedb|stable-3.12notedb|stable-3.13notedb|stable-3.14notedb)
     TEST_TAG_FILTER="-flaky,elastic,no_rbe"