Repository navigation
feat(cli): add code, traced and legacy docker builds to generators - #2614
Conversation
aaf6fb8 to
2218442
Compare
There was a problem hiding this comment.
Hi Sahil, nice work on this.
The shared deps image instead of an npm ci per service is a real speedup, and the docs are genuinely useful. Good to see the personal git identity, the Snyk org and the gobinaries | bash step gone too.
I spent some time on the change detection and the build flow, and tried it out in a small two-service monorepo built from these templates (with Docker and lerna 9.0.7). A few cases end up shipping stale or broken images while the build stays green, so I'd like these sorted before merge.
Details and fixes are inline, and I tested each fix in the same repo:
- A code build on top of a traced image can't load a newly imported module.
- Full builds triggered by root files (lockfile,
patches/,Dockerfile.deps, tracer, rootnft) are never pushed, tagged or deployed. - The lockfile rule is skipped whenever any package.json changes, including a version bump.
- The service's nested
node_modulesis merged into the root one, so shared packages get the service's versions. sudo docker pushfails in the generated GitHub workflow.- Trivy is installed unpinned, as root.
- The build gate is hardcoded to
dev, and promotion can retag a:devbuilt from commits the target branch doesn't have.
Smaller things, fine as follow-ups:
sudo npm install -g lerna@^9isn't pinned. lerna is already in the root devDependencies, sonpx lernaafternpm ciwould do.get-full-build-packages.shprints an empty list and exits 0 if jq is missing orgit difffails, which means code builds for everything. Acommand -v jqcheck andset -ewould catch it.- With
docker:buildremoved, an older Jenkinsfile silently skips newly generated services, and the service README template still mentions it. Maybe keep it as an alias fordocker:build:full. --helmPathnow needs to start with<project>-helm/, otherwise helm-update edits a file outside the helm clone. Worth a line in the docs and the flag help.- A few tests for the script would be great. It's easy to drive with temp git repos.
9f600a6 to
b998edc
Compare
Add a shared deps image and a runtime dependency tracer (@vercel/nft) to the scaffold. A full build now runs one npm ci for all services and copies only the files that each app loads. Add Dockerfile.nft and Dockerfile.code to the microservice generator. Rewrite the legacy Dockerfile with build args. Add docker scripts for the full, traced and code builds, push, tag, retag and helm update. Add an nft.alwaysCopy entry for each datasource connector. Add a script that finds the services that need a full build. Rewrite the Jenkinsfile template to use it, with a USE_NFT_BUILD switch for the legacy build. Add docs for the three build modes.
Keep the repo layout in the images. The nested node_modules of a service stays at the service path, so it does not override the root versions for other packages. Force a full build when the src of a package imports a new module. Code builds then need only the published image, not the deps image. Set BUILD_ALL_PACKAGES when a root trigger marks every image, so push, tag and helm update do not skip them. Run trivy from a pinned image. Use the first PROMOTION_CHAIN entry as the build environment and fail on an unknown BUILD_ENV. Log in to docker hub as root in the github workflow. Apply patches in the legacy Dockerfile. Pin lerna. Stop the change script when jq, node or git diff fails. Document the helmPath prefix.
b998edc to
cec8f89
Compare
|
rohit-sourcefuse
left a comment
There was a problem hiding this comment.
Approving. I re-checked cec8f89. The earlier points are all addressed, the scaffold tests are fixed, and the deps_changed HEAD fix looks good. I agree with keeping cpio, the copyDirs throw, and the public/.env and BUILD_ENV behaviour as they are. The Trivy failure is from sandbox lockfiles this PR doesn't touch.
One follow-up for the next PR, inline on Dockerfile.code.



Description
This PR adds a faster Docker build flow to the monorepos that
sl scaffoldandsl microservicegenerate. Before, each full image ran its ownnpm ciover the whole lockfile. With many services that was slow, and the builds could not run in parallel because the installs used all the agent memory.Now the pipeline picks one of three modes for each changed service:
Dockerfile.code): puts the new host-builtdiston top of the last image for the environment. Most builds use this mode.Dockerfile.nft, default): starts from one shared deps image (Dockerfile.deps, onenpm ciper pipeline run). Thenscripts/node-file-tracer.js(@vercel/nft) copies only the files that the app loads.Dockerfile): the in-image build, kept as a fallback with theUSE_NFT_BUILDJenkins parameter.scripts/get-full-build-packages.shdecides which services need a full build. It reads changes to Dockerfiles, dependencies, thenftconfig, patches and the lockfile. Its header comment lists the conventions it depends on, e.g.@local/<folder>package names.Changes
Dockerfile.deps,.dockerignore, the tracer and the change detection script, plus adocker:build:depsscript and a rootnftconfig. The GitHub build workflow now uses the traced build.Dockerfile.nftandDockerfile.code, and a rewrittenDockerfile, all with build args and the same runtime layoutdocker:build:full|nft|code,docker:push,docker:tag,docker:retag,helm-updatenft.alwaysCopyfor eachloopback-connector-*dependencydocker:build,docker:build:devanddocker:push:devscripts, and the unused_appendDockerScriptSERVICE_NAME. The scripts now use the service folder name.BUILD_ALL_PACKAGES, and image promotion with retagpackages/cli/src/generators/microservice/docs/docker-builds.md: files, change detection, Jenkins parameters, code builds, traced builds (deps image, what a tracer cannot see,nftconfig, testing), legacy builds, local packages and adoption.Type of change
This changes only files in newly generated projects. Services generated before this change keep their old scripts.
How Has This Been Tested?
npm run buildandnpm testinpackages/cli(22 passing)package.json.tplparses as JSON.get-full-build-packages.shin a test git repo for 10 cases: first build, no change, source only, version bump, local package deps,Dockerfile.nftchange,Dockerfile.codechange, lockfile only, rootnftchange, unknown commit. Each case gave the expected output.docker buildx build --checkon all Dockerfile templates.Checklist: