Skip to content

Commit

Permalink
Revert "[DDO-3749] use gsm instead of vault" (#1633)
Browse files Browse the repository at this point in the history
  • Loading branch information
jyang-broad committed Jun 28, 2024
1 parent 2885912 commit 2648a79
Show file tree
Hide file tree
Showing 4 changed files with 10 additions and 38 deletions.
14 changes: 3 additions & 11 deletions automation/canary-prod-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ set -e
set -x

ENV=$1
VAULT_TOKEN=${2:-$(cat $HOME/.vault-token)}
WORKING_DIR=${3:-$PWD}
NEED_TOKEN=false

Expand All @@ -16,16 +17,7 @@ else
echo "Starting canary test in Production"
fi

DOCKER_ARGS=(
"run"
"--rm"
"-v ${HOME}/.config/gcloud:/root/.config/gcloud"
"google/cloud-sdk"
)

SECRET_ACCESS_ACCOUNT=jenkins-firecloud@broad-dsp-techops.iam.gserviceaccount.com
# Expand the array of args and pass them to `docker`
JSON_CREDS=$(docker ${DOCKER_ARGS[*]} /bin/bash -c "gcloud config set account ${SECRET_ACCESS_ACCOUNT} && gcloud secrets versions access latest --project broad-dsde-dev --secret firecloud-sa")
JSON_CREDS=`docker run --rm -e VAULT_TOKEN=$VAULT_TOKEN -e VAULT_ADDR=https://clotho.broadinstitute.org:8200 broadinstitute/dsde-toolbox vault read -format=json secret/dsde/firecloud/prod/common/canary/firecloud-account.json | jq '.data'`

users=(
dumbledore.admin@test.firecloud.org
Expand Down Expand Up @@ -66,7 +58,7 @@ if [ $ENV = "prod" ]; then

do
echo $i
sleep 60
sleep 1m
monitorSubmission dumbledore.admin@test.firecloud.org broad-firecloud-dsde CanaryTest $submissionId
((i++))
done
Expand Down
1 change: 0 additions & 1 deletion automation/canary_events.json

This file was deleted.

15 changes: 3 additions & 12 deletions automation/complex-prod-workflow-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ set -e
set -x

ENV=$1
VAULT_TOKEN=${2:-$(cat $HOME/.vault-token)}
WORKING_DIR=${3:-$PWD}
NEED_TOKEN=false

Expand All @@ -17,17 +18,7 @@ else
echo "Starting complex workflow test in Production"
fi


DOCKER_ARGS=(
"run"
"--rm"
"-v ${HOME}/.config/gcloud:/root/.config/gcloud"
"google/cloud-sdk"
)

SECRET_ACCESS_ACCOUNT=jenkins-firecloud@broad-dsp-techops.iam.gserviceaccount.com
# Expand the array of args and pass them to `docker`
JSON_CREDS=$(docker ${DOCKER_ARGS[*]} /bin/bash -c "gcloud config set account ${SECRET_ACCESS_ACCOUNT} && gcloud secrets versions access latest --project broad-dsde-dev --secret firecloud-sa")
JSON_CREDS=`docker run --rm -e VAULT_TOKEN=$VAULT_TOKEN -e VAULT_ADDR=https://clotho.broadinstitute.org:8200 broadinstitute/dsde-toolbox vault read -format=json secret/dsde/firecloud/prod/common/canary/firecloud-account.json | jq '.data'`

users=(
dumbledore.admin@test.firecloud.org
Expand Down Expand Up @@ -68,7 +59,7 @@ if [ $ENV = "prod" ]; then

do
echo $i
sleep 300
sleep 5m
monitorSubmission dumbledore.admin@test.firecloud.org broad-firecloud-dsde complex-featured-workflow $submissionId
((i++))
done
Expand Down
18 changes: 4 additions & 14 deletions jenkins/jenkins_build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,21 +4,11 @@ set -eux

GCR_SVCACCT_VAULT="secret/dsde/dsp-techops/common/dspci-wb-gcr-service-account.json"
GCR_REPO_PROJ="broad-dsp-gcr-public"
VAULT_TOKEN=${VAULT_TOKEN:-$(cat /etc/vault-token-dsde)}

gcloud auth activate-service-account --key-file=${DSP_TECHOPS_SVC_ACCT}

DOCKER_ARGS=(
"run"
"--rm"
"-v ${HOME}/.config/gcloud:/root/.config/gcloud"
"google/cloud-sdk"
)

SECRET_ACCESS_ACCOUNT=jenkins-firecloud@broad-dsp-techops.iam.gserviceaccount.com
# Expand the array of args and pass them to `docker`
JSON_CREDS=$(docker ${DOCKER_ARGS[*]} /bin/bash -c "gcloud config set account ${SECRET_ACCESS_ACCOUNT} && gcloud secrets versions access latest --project broad-dsp-techops --secret dspci-wb-gcr-service-account")

echo ${JSON_CREDS} | jq . > dspci-wb-gcr-service-account.json
docker run --rm -e VAULT_TOKEN=$VAULT_TOKEN \
broadinstitute/dsde-toolbox:latest vault read --format=json ${GCR_SVCACCT_VAULT} \
| jq .data > dspci-wb-gcr-service-account.json

./scripts/build.sh compile -d push -g gcr.io/broad-dsp-gcr-public/${PROJECT} -k "dspci-wb-gcr-service-account.json"

Expand Down

0 comments on commit 2648a79

Please sign in to comment.