4 ms·
My philosophy is keeping the CI/CD workflow definition as simple as possible, and passing off the task itself into a shell or python script. The only thing I ty
by chrisdalke 4y ago
My philosophy is keeping the CI/CD workflow definition as simple as possible, and passing off the task itself into a shell or python script. The only thing I typically perform in a task definition is secret management, tagging & uploading build artifacts, managing distributed build agents, etc. and leave any complicated build process and success/failure criteria for the script to decide.
Jenkins works great for this purpose. It's fairly sketchy and held together by duct tape, but I find its developer experience to be much better than equivalent commercial options for a small scrappy team.
My playbook for a small team building a variety of software (Robotics software, web-based UI, AI, mostly running in Docker or built to static executables):
- Spin up a Jenkins master on a cheap VM
- Spin up platform/project specific VMs or physical machines as build agents, leave developers in charge of dependency and tooling installations on the build machine for their product. Don't bother with 100% reproducible tooling until you need to scale up to more than a few build agents.
- Maintain all build and deployment scripts inside the repository, next to the code, managed by developers. Store build pipeline/task definitions in the repository, and keep developers responsible for their service.
- Keep some boilerplate and convention around for pipelines and enforce it. Make sure all build pipelines use a similar git scheme. Doesn't matter as long as it's easy + reliable (ex. deploy every commit from develop w/ staged rollout? "Git flow"-based release workflows, etc)
- provide SSO access to the whole team via a plugin ASAP -- Avoid managing individual credentials to the machine
- Limit Jenkins plugins used for build actions! never use a plugin doing some action interacting w/ cloud resources, eg "AWS S3 Upload". Just asking for a security breach, and eventually turns the Jenkins UI into a giant mess of random UI controls. Instead, where possible use native tools eg. the AWS CLI instead of a Jenkins AWS plugin.