Disable validation of Jenkinsfile changes

The validation of arbitrary Jenkinsfile changes allows for Remote Code
Execution (RCE) on the Jenkins controller and agents. This may allow
unauthorised write access to untrusted build artifacts (e.g.,
/var/jenkins_home/jobs), disclosure of untrusted credentials (including
Git read-only credentials for fetching code for builds, BuildBuddy RBE
keys for accessing the build cache).

The RCE is, however, inherently linked with the concept of CI/CD because
the whole point of build validation is to fetch _potentially untrusted_
code from a contributor and running it on a server system.

All the credentials potentially exposed are untrusted and have no power
to submit or push any code to Gerrit. The sole purpose of the service
users running the build is to provide a `Verified` label, and they
cannot approve any incoming change automatically.

Bug: Issue 568458159
Change-Id: I2c1c6c16714d2297424ba15a4fa4ed021964d2e3
4 files changed
tree: 53165e0b5a2a4e1e187852fbaece0514a78a717b
  1. jenkins/
  2. jenkins-docker/
  3. jenkins-internal/
  4. vars/
  5. .gitignore
  6. Jenkinsfile
  7. README.md
  8. yamllint-config.yaml
README.md

Gerrit CI scripts

Providing jobs

This project uses Jenkins Jobs Builder [1] to generate jobs from yaml descriptor files.

To add new jobs reuse existing templates, defaults etc. as much as possible. E.g. adding a job to build an additional branch of a project may be as easy as adding the name of the branch to an existing project.

To ensure well readable yaml-files, use yamllint [2] to lint the yaml-files. Yamllint can be downloaded using Python Pip:

pip3 install --require-hashes yamllint

To run the linter, execute this command from the project's root directory:

yamllint -c yamllint-config.yaml jenkins/**/*.yaml

Yamllint will not fix detected issues itself.

[1] https://docs.openstack.org/infra/jenkins-job-builder/index.html [2] https://pypi.org/project/yamllint/