In today’s tutorial, we are going to use the GitLab container registry to store images. Please refer to our GitLab guide for GitLab installation and configurations.
Let’s get started with installing container first.
1. Configure Container Registry
Navigate to the admin area, and the first thing you notice is the Container registry is turned off by default setting.
data:image/s3,"s3://crabby-images/6baa5/6baa5d79a87b3976ebb98a457e691285d146762e" alt="Container Registry"
Container Registry turned off
Install Container registry
We should modify the GitLab configuration file. Enter the following command:
a) Modify gitlab.rb
vim /etc/gitlab/gitlab.rb
Change the following line:
registry_external_url 'https://gitlab.fosslinux.com:5050'
data:image/s3,"s3://crabby-images/3288b/3288babebb92636c73a0af104b2796ec9fe8974f" alt="Registry Url"
Registry Url
Now the registry URL is listening on HTTPS under the existing GitLab URL with a different port.
b) After modification, you need to reconfigure Gitlab.
gitlab-ctl reconfigure
data:image/s3,"s3://crabby-images/54899/54899657d6fca211278b3499a42e0a088772407c" alt="Reconfigure"
Reconfigure
Once done, go to the admin area, and this time, you should see it enabled.
data:image/s3,"s3://crabby-images/3c2d3/3c2d3ec9fea2ec551849951fcaaa2c21ac5ace37" alt="Container Registry"
Container Registry
c) Test the container login from a different machine. However, note that the Docker should be installed on that system.
docker login gitlab.fosslinux.com:5050
The default images store location is as follows:
/var/opt/gitlab/gitlab-rails/shared/registry
If you want to change the path, use VIM to edit it.
vim /etc/gitlab/gitlab.rb
Change the following line:
gitlab_rails['registry_path'] = "/path/to/registry/storage"
Then reconfigure.
gitlab-ctl reconfigure
2. Creating a Project
We shall create a new project for a pipeline. To do that, go to the Admin Area.
data:image/s3,"s3://crabby-images/baddf/baddf6222d1b19f7aacf1d35d35e81ff026338b4" alt="Click On Admin"
Click On Admin
You should see Admin Area similar to this:
Then click on the New Group.
data:image/s3,"s3://crabby-images/8846b/8846b9b82c735aee9ca26ac385f76f6dc0eb4ee8" alt="Create Group"
Create a Group
You can give any name to your group. Then type a name for the project URL. Visibility level is “Private” here; we created a group called “gitdemo.”
Then again Go to Admin Area -> New Project
data:image/s3,"s3://crabby-images/85664/85664941ed12d361ce0e938d877c008b21478a15" alt="New Project"
New Project
Give a name for the project. Select the previously created group for the project.
After creating a Project, you can add a sample file to the repository.
3. Enable container registry for project
Go to Project settings -> General and then expand Visibility, Projet Features, Permissions.
Then enable the Container registry.
data:image/s3,"s3://crabby-images/b2e92/b2e92d3ac82d0e0f64f1420429f2bc9a2a51bef1" alt="Enable Registry For Project"
Enable Registry For Project
Now go your project, and you can see the container registry under the packages section.
data:image/s3,"s3://crabby-images/71d43/71d43e506e4371b3afbc1f241bd0ae6be73b5f34" alt="Added To Sidebar"
Added To Sidebar
4. Disable AutoDevops
Go to your project -> Settings -> CICD
data:image/s3,"s3://crabby-images/bd0ef/bd0ef8c334289d7447a32e2a6b50e247de255293" alt="Disable Auto Devops"
Disable Auto DevOps
Then expand Auto DevOps and unselect “Default to Auto DevOps pipeline.”
data:image/s3,"s3://crabby-images/369cf/369cf7b4d5c85383cde2716a986b2ef066da9008" alt="Disable Feature"
Disable Feature
5. Create an SSH Key from the client/developer machine
Here we are going to create ssh key and authenticate with our GitLab. After that, we can push, pull, clone git repositories from our client machine.
a) Run the following the command to generate key:
ssh-keygen -t rsa -b 4096 -C "darshana@fosslinux.com"
data:image/s3,"s3://crabby-images/48e93/48e937f32560754b9d2d3187051350c7929deb55" alt="Create Key"
Create Key
b) Copy public key:
cat ~/.ssh/is_rsa_pub
data:image/s3,"s3://crabby-images/0a014/0a01405bec730b1e5bd8c1d840db5ed9014a5383" alt="Get Key"
Get Key
Now login to the GitLab server. Go to Profile -> SSH Keys
c) Add Copied key to key section and save.
data:image/s3,"s3://crabby-images/1fd8c/1fd8c614a4d63b5315d3231806997576187684cf" alt="Add Key GitLab"
Add Key GitLab
d) Now we need to get Url for Clone repo using SSH.
Go to your project -> Clone.
Copy clone with ssh URL.
data:image/s3,"s3://crabby-images/5025c/5025ce63d4ead8b37b5e6ce7be9119bb412d4342" alt="Clone Repo"
Clone Repo
Before we are going to clone the repository to our machine, we need to install “git ”
Install git on client-server:
yum install git -y
Now we are going to Clone the repository and push our code to the Gitlab repository.
Git global setup
git config --global user.name "Darshana"
git config --global user.email "darshana@fosslinux.com"
Run the following command to clone the repository:
git clone git@git.fosslinuxcom:gitdemo/fosslinux.git
data:image/s3,"s3://crabby-images/7fdac/7fdac13cca94bbbd47c25d7fdf6b27cb6ea447f0" alt="Clone Repository"
Clone Repository
Copy your source code to the cloned folder.
Go to the cloned folder:
cd fosslinux
Now push code to the repository:
git add .
git status
git commit -m "demo Project files"
git push
6. Install GitLab Runner
It is recommended to install GitLab Runner on a server separate from where GitLab is installed. You can install it on the same server, too, if you still want it that way.
Here we are going to use Docker executor; therefore, we should install Docker before using the Runner.
a) The Docker executor
GitLab Runner can use Docker to run jobs on user-provided images due to the use of Docker executor.
The Docker executor, when used with GitLab CI, connects to Docker Engine and runs each build in a isolated container using the predefined image that is configured in the Gitlab CI file. We will see the Gitlab CI file when we discuss the Pipeline.
Install repository:
curl -L https://packages.gitlab.com/install/repositories/runner/gitlab-runner/script.deb.sh | bash
data:image/s3,"s3://crabby-images/681b2/681b29dcbec541a5317b76747d6fb16a825db359" alt="Runner Repo"
Runner Repo
Install Runner:
apt-get install gitlab-runner
data:image/s3,"s3://crabby-images/61d7b/61d7b22d1d3da28bdfddaf17c0f8d4112840c01b" alt="Install Runner"
Install Runner
Check Runner status:
gitlab-runner status
data:image/s3,"s3://crabby-images/fb316/fb3168248d3e4b7f07e14b1c83a8fe57bc83d4e2" alt="Runner Status"
Runner Status
Register Runner
Here we are going to add a shared Runner. Go to Admin Area -> Runners.
data:image/s3,"s3://crabby-images/e365a/e365a67b57cf8666e875563f595713afefeaad71" alt="Shared Runner"
Shared Runner
Then you can see Set up a shared Runner manually section. We need our Gitlab Url and token for the registered Runner.
data:image/s3,"s3://crabby-images/f159f/f159f831247021e4e271cfcdf5068e3a572fbf6f" alt="Runner Token"
Runner Token
Run Register Runner
Run the following command to register the Runner.
gitlab-runner register
data:image/s3,"s3://crabby-images/d8136/d8136e68925eabe7dc984df47db063ed4885709b" alt="Register Runner Register Runner"
Register Runner
It should ask a few questions. Answer the following questions.
a) Enter your GitLab instance URL:
Please enter the gitlab-ci coordinator URL (e.g. https://gitlab.com ) https://gitlab.fosslinux.com
b) Enter the token you obtained to register the Runner:
Please enter the gitlab-ci token for this runner xxxxxxxxxxxxxxxxxxxxxxx
c) Enter a description for the Runner; you can change this later in GitLab’s UI:
Please enter the gitlab-ci description for this runner [hostname] Docker-runner
d) Enter the tags associated with the Runner; you can change this later in GitLab’s UI:
Please enter the gitlab-ci tags for this runner (comma separated): master,dev,qa
e) Enter the Runner executor:
Please enter the executor: ssh, docker+machine, docker-ssh+machine, kubernetes, docker, parallels, virtualbox, docker-ssh, shell: docker
f) If you chose Docker as your executor, you’d be asked for the default image to be used for projects that do not define one in .gitlab-ci.yml:
Please enter the Docker image (eg. ruby:2.6): alpine:latest
Now Runner registered successfully.
Restart Runner
gitlab-runner restart
Now refresh the Runners page (Admin Area -> Runners). You can see the newly added Runner.
data:image/s3,"s3://crabby-images/24f32/24f327cb5e55fc2876123f2bd92cc31e68bc48c3" alt="Newly Added Runner"
Newly Added Runner
We need to modify some settings for the Runner. So click on the token.
data:image/s3,"s3://crabby-images/c0107/c0107f9f6191941ad60bad9031a2be5f2a937c51" alt="Shared Runner Setting"
Shared Runner Setting
Then select “Run untagged jobs” and save changes.
data:image/s3,"s3://crabby-images/60385/60385be3aa73e056edb0aa07843eea9ce5e1d2fe" alt="Untagged Projects"
Untagged Projects
Change Gitlab runner configurations
We are going to use docker-in-docker (dind) mode in the GitLab pipeline, So we have to use privileged = true in our Docker containers. Therefore we are going to enable privileged mode.
Edit configuration file:
vim /etc/gitlab-runner/config.toml
data:image/s3,"s3://crabby-images/ab076/ab07643cf63fa027388651693e1f3d8d02e527d3" alt="Runner Mode"
Runner Mode
Change the “privileged” section.
privileged = true
After modification, you can see a file similar to this.
data:image/s3,"s3://crabby-images/ed440/ed440c471b6715d0f1c41f1d8eaf1a4d2ecfffbf" alt="Modified Runner"
Modified Runner
Then restart Runner.
gitlab-runner restart
7. Configure variables for GitLab PipeLine
Add container registry variables
Click on project -> Settings ->CICD -> Variables (click on Expand).
data:image/s3,"s3://crabby-images/15669/15669aad178caea3fa4283c50268704d94c068cd" alt="Variables"
Variables
Add the following to the key and add value.
CI_REGISTRY_USER CI_REGISTRY_PASSWORD
data:image/s3,"s3://crabby-images/0cde0/0cde072b85986cb9c822e91b5f097c784f7943f3" alt="Adding Variable Values"
Adding Variable Values
Here you need to add GitLab login and password.
Integrate with SonarQube Server
Get SonarQube token and add it to GitLab. Login to SonarQube Server.
Go to Administration > click on Security > Users > Click on Tokens
data:image/s3,"s3://crabby-images/5309a/5309a0b8fa997570b46498320cbe59fb6971010b" alt="Sonar Token"
Sonar Token
It should open a token Window.
data:image/s3,"s3://crabby-images/13a5a/13a5af3d53a0ed557cee6aabf98a4f42e07547cf" alt="Generate Token Generate Token"
Generate Token
Generate token with any name -> Copy the token.
data:image/s3,"s3://crabby-images/84f87/84f87a7ae04db1578327045992de7e9e2eee71ef" alt="New Token"
New Token
Copy token and go to GitLab again. Click on project -> Settings ->CICD -> Variables
Add a new variable.
SONARQUBE_TOKEN
Paste sonar token to “SONARQUBE_TOKEN” value.
8. Create a Pipeline
Following files should be in the repository folder
a) Dockerfile
We need a docker file to build our image. Follow our docker file guide.
Here is our docker file:
FROM ddarshana/alpinenode10 ENV NODE_ENV=production RUN apk add --update curl && rm -rf /var/cache/apk/* RUN mkdir /app WORKDIR /app COPY package.json . RUN npm install COPY . . CMD ["npm", "start"]
Go to your project and create a new file called “Docker File.”
data:image/s3,"s3://crabby-images/8e555/8e5557b45145b7dec64851bb0270e85a9859f294" alt="Add Docker File"
Add Docker File
b) Add sonar-project.properties
Sonar property file should be in our source code root directory to send scan data to SonarQube Server.
Here is our file:
# Required metadata sonar.projectKey=fosslinux sonar.projectName=fosslinux # Comma-separated paths to directories with sources (required) sonar.sources=./ # Language sonar.language=js sonar.profile=node # Encoding of sources files sonar.sourceEncoding=UTF-8
Go to your project and create “sonar-project.properties.”
data:image/s3,"s3://crabby-images/3cd0d/3cd0da0732b509ac8ec4753536eb03cf432ece98" alt="Add Sonar Property File"
Add Sonar Property File
I. Create a GitLab-CI file
Go to your project and create a file called “.gitlab-ci.yml.”
data:image/s3,"s3://crabby-images/faaa4/faaa43380b2fd4f1c1bfcc20cae9cee87c475c34" alt="Pipeline File"
Pipeline File
This is our file.
stages: - Lint images - Codequality - Build and publish images variables: DOCKER_REGISTRY: gitlab.fosslinux.com:5050 APP_NAME: fosslinux linting: stage: Lint images image: node:4-alpine only: - master script: - npm install -g dockerlint && npm cache clean - find ./ -name Dockerfile -exec dockerlint {} \; codequality: stage: Codequality image: ddarshana/alpine-sonarscanner script: - sonar-scanner -Dsonar.host.url=https://sonar.fosslinux.com -Dsonar.login=$SONARQUBE_TOKEN -Dsonar.projectVersion=$CI_PIPELINE_ID -Dsonar.projectName=$CI_PROJECT_NAME+$CI_BUILD_REF_NAME only: - master publishing: stage: Build and publish images image: docker:18.09.7 services: - docker:18.09.7-dind only: - master script: - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $DOCKER_REGISTRY - docker build . -t $DOCKER_REGISTRY/gitdemo/$APP_NAME:$CI_PIPELINE_ID - docker push $DOCKER_REGISTRY/gitdemo/$APP_NAME:$CI_PIPELINE_ID - echo "pushed image $APP_NAME:$CI_PIPELINE_ID" - docker logout $DOCKER_REGISTRY
Here we have defined three stages for our Pipeline:
stages: - Lint images - Codequality - Build and publish images
Variables are set for the docker registry and Application name.
variables: DOCKER_REGISTRY: gitlab.fosslinux.com:5050 APP_NAME: fosslinux
Once you commit changes to the master branch, the Pipeline should start.
data:image/s3,"s3://crabby-images/c885f/c885fb76f8b3d839745aea58c8a15f60dc413704" alt="Pipeline Started"
Pipeline Started
As you see, the Pipeline is running. You can see the stages of the Pipeline.
data:image/s3,"s3://crabby-images/35462/3546231246a1f95e06d7b3940aeb406cf42264e6" alt="Pipeline"
Pipeline
If all stages are a success, you can see the output as follows.
data:image/s3,"s3://crabby-images/d0497/d04976cb8b942fe7dcde41c7598f7c34c9f7f9e1" alt="Completed Pipeline"
Completed Pipeline
You can click on any stages and see their logs.
data:image/s3,"s3://crabby-images/3baf1/3baf11b0724c7ee2ec76abfa03c7d9b59440b452" alt="Output Of Stage"
Output Of Stage
a) Check the container registry.
Project -> Packages -> container registry
data:image/s3,"s3://crabby-images/3efff/3efffb77448b26145116cbe1936aeabcf662c147" alt="Pushed Image"
Pushed Image
Then you can see our image.
b) Check Sonar report
Login to SonarQube, and you can see the report for our project.
data:image/s3,"s3://crabby-images/838f5/838f5d869face150515d260be5a3da2e0d9f5c36" alt="Sonar Report Sonar Report"
Sonar Report
That’s all about creating a GitLab pipeline with GitLab container service and Sonarqube integration.
3 comments
Excellent tutorial. Thank you
great tutorial
Hey, very informative article 😀 I have a couple of doubts would be helpful if you can clarify these.
What is the real purpose of container registry here? can we store the docker image of SonarQuebe in the GitLab container registry and pull it from there during the pipelines, if so how?
Thanks in advance.