Jump to: navigation, search

Hudson

About Hudson

Hudson is a continuous integration (CI) tool. The Hudson project is hosted at Eclipse.org, and is in use on Eclipse servers for Eclipse projects as part of the Common Build Infrastrure (CBI). This page is about the hosted service at Eclipse.org. For more information on the project itself, or to download Hudson, please see the Hudson project page.

General Information

Hudson instances are maintained by the Eclipse Webmasters. The Hudson CI servers are available in two different offerings (each explained below):

Asking for Help

  • Need help setting up your instance: contact webmaster @ eclipse.org or your project mentors
  • Need help actually building your code: ask your project mentors, or ask on the Common Build mailing list (cbi-dev). There are no dumb questions.
  • Subscribe to cbi-dev here: https://dev.eclipse.org/mailman/listinfo/cbi-dev

HIPP

HIPP (Hudson Instance Per Project) instances are recommended for those projects who prefer flexibility and convenience with their CI system, perhaps at the expense of security and webmaster support. A single Linux master is provided, and the instance is run under the security context of your project. Optionally, a project's Hudson instance can be configured to write into a project's downloads area and can be given write access to the code repository for automatic tagging of builds. This does create a security risk - see https://bugs.eclipse.org/bugs/show_bug.cgi?id=375350#c42 for a fix. Webmasters will install most plugins you request, including the Gerrit plugin, but will offer little support. In time, projects will be offered self-serve restarts and re-imaging of their instances.

Requesting a HIPP instance

Please file a bug against Eclipse Foundation > Community > Hudson to request your project's own instance. Please ensure your project lead can +1 the request. Please specify if you would like to use the Gerrit Trigger plugin, and if you wish to grant write access to your download or code repositories.

Note.png
About write access
If your git repo is handled by gerrit, granting write access to your code repositories is a different procedure, so you must ask specifically for it. If you don't use Gerrit, then granting write access to your download area automatically grants write access to your code repositories and vice-versa.


Important.png
Security issues
There may be security issues related to using the Gerrit plugin and there may be security issues related to allowing the CI system to write directly to your code repos and downloads area. If you request plugins other than those available on the Shared instance, webmaster may not be able to help troubleshoot any issues that you may encounter with your instance.


Important.png
No more HIPPs
Since the Hudson project became dormant, as of 2017 no more HIPPs will be provisioned. Instead JIPPs (Jenkins Instance Per Project) will be provisioned..


HIPP slaves

Both Shared and HIPP Hudson setups use SLES 11 x86_64 machines for Linux slaves. Windows 7 and Mac OS X slaves are available for UI testing on the Shared instance. These servers are behind a firewall so any outbound http(s) connections are proxied.

Platforms available as HIPP slaves:

  • Fedora 20 x86_64
  • CentOS 7 x86_64
  • OpenSuSE 13.1 x86_64

HIPP slaves are only provisioned for those projects who have a need. To request a HIPP slave, please file a bug.

You can also connect to your own external slave.

Choosing the right slave

  • hudson-slave1, hudson-slave2, hudson-slave4 - these are the main build nodes for Hudson jobs. You can specify them by name or by using the 'build2' label.
  • fastlane - this slave is intended for usage during a release train crunch when re-spins may require more capacity than hudson-slave1&2 can provide. By default jobs should not run here.
  • mac-tests and windows7tests - these 2 slaves are meant for running UI tests for their respective OS versions. By default jobs should not run on either slave.

See also: Hudson server performance metrics

Shared Instance

The Shared instance is recommended for general purpose builds and tests, and for all UI tests. Shared Hudson has several build slaves, a limited yet stable tool set, and full webmaster support. Shared Hudson cannot write into your downloads area or tag releases in your Git repo. Furthermore, the Gerrit trigger plugin is not permitted to run here.

Server Storage

Build and Hudson storage layout
Three tiers of storage are available for storing Workspaces, build artifacts, nightly and release builds. For optimal build performance and service availability, it is important that you use each storage device according to its intended purpose.

The image on the right illustrates the three storage tiers and their intended purpose.

If you are using a HIPP instance for your builds, the medium and long-term storage is accessible via the local filesystem to copy build artifacts to. The locations are as follows:

   # Medium-term storage:
   /shared/<project id with . replaced by />
   # Long-term storage:
   /home/data/httpd/download.eclipse.org/<project name />

For example, the ELK project's ID is modeling.elk and can thus publish its build artifacts to the following locations:

   /shared/modeling/elk/
   /home/data/httpd/download.eclipse.org/elk/

Be sure to request your HIPP instance to actually have write access to these locations. If there is a problem, file a bug against Eclipse Foundation > Community > Servers.

See Milestone and Release Builds.


Hudson configuration

Tools (and locations)

  • apache-maven-latest (/shared/common/apache-maven-latest)
  • apache-maven-3.0.5 (/shared/common/apache-maven-3.0.5)
  • jdk1.8.0-latest (/shared/common/jdk1.8.0_x64-latest)
  • jdk1.7.0-latest (/shared/common/jdk1.7.0-latest)
  • jdk1.6.0-latest (/shared/common/jdk1.6.0-latest)
  • jdk1.5.0-latest (/shared/common/jdk1.5.0-latest)
  • apache-ant-1.9.6 (/shared/common/apache-ant-1.9.6)
  • gradle-latest (/shared/common/gradle-latest)
  • gradle-3.1 (/shared/common/gradle-3.1)

Accessing the Internet using Proxy

Since April 2017 the proxy is no longer required to access the internet from HIPP instances.

Additional Troubleshooting Tips

Buckminster CVS materializing: proxy error: Forbidden

From Martin Taal, via Forums:

Buckminster cvs materializing, uses a proxy, how is this configured?

To finish this thread. Michael Wenz pointed me to a change made in the cdo build (to solve this issue), a snippet from his email to me:

But I saw that the CDO build is green again and they still do an Ant call from Hudson that again triggers Buckminster. Previously that build failed with the same exception as ours did or do.

Not sure what these guys changed, but I saw that they added something in their build.xml that seems to fix this. I found 2 snippets that appear to be in connection with this: ... <condition property="no.proxy" value="${env.no_proxy}, dev.eclipse.org" else="dev.eclipse.org"> <isset property="env.no_proxy" /> </condition> ...

... <java fork="true" jar="${@{app}.launcher}" dir="${@{app}.deploy.dir}" failonerror="true"> <env key="no_proxy" value="${no.proxy}" /> <properties /> <args /> </java> ...

Hudson for Committers

Hudson for Committer Project-level Administration

Normally "project level" administration is defined for a Hudson job. This allows for only one or a few committers to have "full access" to the job, to do builds, change the configuration, or even delete the job. To give access to everyone, say to "read" the builds, you can add the user "anonymous" and mark the "read" check box. Typically, it is desired to have some "in between" access to all the committers of a project, for example, to maybe any committer can kick off a build, but only the project-level administrator can change the configuration. If this is desired, there is a "role" groups that can be used instead of listing all committers by name. The "role" name is formed by perpending "ROLE_" to the upper case version of the Linux group that defines the committers. For example, EPP committers are authorized using the Linux group technology.packaging, so their Hudson group would be ROLE_TECHNOLOGY.PACKAGING. So, as an example, the project level authorization might look like the following, from the Hudson "configure project" page:

Example Project Level Security settings

If using the Promoted Builds plugin with a Promotion Criterion of "Only when manually approved", you can also use "role" groups (using the aforementioned "ROLE_" syntax). In fact, you *should* at least restrict the approvers to the group of project committers, as otherwise any anonymous can run a promotion job (Bug 424619).

Hudson for Administrators

Duties of Administrators

  1. Hudson upgrades and restarts
  2. New Hudson accounts
  3. Add plugins
  4. Set policy for Hudson usage
  5. Watch changes to this wiki page
  6. Monitor the Hudson Inbox.

Who are the Administrators

  • Eclipse Webmasters - webmaster@eclipse.org
  • Mikaël Barbero

You can contact the Hudson admins by opening a bug

Hudson for Distributed Builds

  • Testing on Multiple Platforms
  • What is the Test-Slave Node?
  • How do I use the Test Slave Node to run Tests?