Disable validation of Jenkinsfile changes The validation of arbitrary Jenkinsfile changes allows for Remote Code Execution (RCE) on the Jenkins controller and agents. This may allow unauthorised write access to untrusted build artifacts (e.g., /var/jenkins_home/jobs), disclosure of untrusted credentials (including Git read-only credentials for fetching code for builds, BuildBuddy RBE keys for accessing the build cache). The RCE is, however, inherently linked with the concept of CI/CD because the whole point of build validation is to fetch _potentially untrusted_ code from a contributor and running it on a server system. All the credentials potentially exposed are untrusted and have no power to submit or push any code to Gerrit. The sole purpose of the service users running the build is to provide a `Verified` label, and they cannot approve any incoming change automatically. Bug: Issue 568458159 Change-Id: I2c1c6c16714d2297424ba15a4fa4ed021964d2e3
This project uses Jenkins Jobs Builder [1] to generate jobs from yaml descriptor files.
To add new jobs reuse existing templates, defaults etc. as much as possible. E.g. adding a job to build an additional branch of a project may be as easy as adding the name of the branch to an existing project.
To ensure well readable yaml-files, use yamllint [2] to lint the yaml-files. Yamllint can be downloaded using Python Pip:
pip3 install --require-hashes yamllint
To run the linter, execute this command from the project's root directory:
yamllint -c yamllint-config.yaml jenkins/**/*.yaml
Yamllint will not fix detected issues itself.
[1] https://docs.openstack.org/infra/jenkins-job-builder/index.html [2] https://pypi.org/project/yamllint/