Tekton Concepts: Difference between revisions

From NovaOrdis Knowledge Base
Jump to navigation Jump to search
 
(128 intermediate revisions by the same user not shown)
Line 1: Line 1:
=External=
* https://tekton.dev
=Internal=
=Internal=
* [[Tekton#Subjects|Tekton]]
* [[Tekton#Subjects|Tekton]]
Line 5: Line 7:


=Overview=
=Overview=
Tekton is a cloud-native solution for building CI/CD pipelines. Tekton installs and runs as an extension on your Kubernetes cluster and uses the well-established Kubernetes resource model. Tekton workloads execute inside Kubernetes containers. It has several components: [[#Tekton_Pipelines|Tekton Pipelines]], [[#Tekton_CLI|Tekton CLI]] and [[#Tekton_Catalog|Tekton Catalog]]. Tekton is part of the [https://cd.foundation/ CD Foundation], a [https://www.linuxfoundation.org/projects/ Linux Foundation] project. It is implemented as a set of Kubernetes [[Kubernetes_Custom_Resources#Overview|Custom Resources]]. Once deployed, Tekton can be accessed via [[#Tekton_CLI|Tekton CLI]] commands or API calls.
Tekton is a cloud-native solution for building CI/CD pipelines. Tekton installs and runs as an extension on your Kubernetes cluster and uses the well-established Kubernetes resource model. Tekton workloads execute inside Kubernetes containers. It is implemented as a set of Kubernetes [[Kubernetes_Custom_Resources#Overview|Custom Resources]]. It has several components: [[#Tekton_Pipelines|Tekton Pipelines]], [[#Tekton_CLI|Tekton CLI]] and [[#Tekton_Catalog|Tekton Catalog]]. Once deployed, Tekton can be accessed via [[#Tekton_CLI|Tekton CLI]] commands or API calls. Tekton is part of the [https://cd.foundation/ CD Foundation], a [https://www.linuxfoundation.org/projects/ Linux Foundation] project.
=Tekton Runtime Model=
[[#Tekton_Pipelines|Tekton Pipelines]] tracks the state of a [[Tekton_Pipeline#Overview|pipeline]] using [[Kubernetes_Labels_and_Annotations#Annotations|Kubernetes annotations]], which are projected inside each [[Tekton_Step#Step_Container|step container]] in the form of files with the [[Kubernetes_Downward_API_Concepts#Overview|Kubernetes Downward API]].  The step container entrypoint binary watches these projected files and will only start the command the step is supposed to execute only if a specific annotation appears as file. For more details see: {{Internal|Tekton_Labels_and_Annotations#Overview|Tekton Labels and Annotations}}


=Tekton Domain Model=
In addition, Tekton Pipelines schedules some containers to run automatically before and after the step containers to support built-in features such as the retrieval of input resources and the uploading the outputs to wherever they are supposed to go.
==Task==
{{External|https://github.com/tektoncd/pipeline/blob/main/docs/tasks.md}}
{{External|https://tekton.dev/docs/pipelines/tasks/}}
 
A '''task''' defines a series of ordered [[#Step|steps]], which are executed in order in which they are declared. The output of a step can be used as the input of the next step. Each task executes in its own Kubernetes pod, where individual [[#Step|steps]] are executed as pod's containers, so by default, tasks within a [[#Pipeline|pipeline]] do not share data. To make tasks share data, they must be explicitly configured to make their outputs available to the next task, and to ingest the outputs of a previously executed task, as inputs. A task can be executed on its own, or part of a pipeline. The task is implemented as a Kubernetes custom resource.
===Task Example===
<syntaxhighlight lang='yaml'>
apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: hello
spec:
  steps:
    - name: echo
      image: alpine
      script: |
        #!/bin/sh
        echo "Hello World"
</syntaxhighlight>
===Task Manifest===
<font size=-1>
apiVersion: tekton.dev/v1beta1 <font color=teal># required field</font>
kind: Task <font color=teal>                    # required field</font>
metadata: <font color=teal>                    # required field</font>
  name: <font color=indigo><''task-name''></font> <font color=teal>          # required field</font>
spec: <font color=teal>                        # required field</font>
  description: 'this is an optional description'
  [[#Task_Parameters|params]]:
    - name: <font color=indigo><''some-array-parameter''></font>
      type: array
    - name: <font color=indigo><''some-string-parameter''></font>
      type: string
  [[#Task_Results|results]]:
    - name: <font color=indigo><''some-name''></font>
      description: '...'
  [[#Task_Step_Template|stepTemplate]]:
    env:
      - name: '...'
          value: '...'
  steps: <font color=teal>  # required field</font>
    - name: step-1
      image: ubuntu
      args: ["ubuntu-build-example", "SECRETS-example.md"]
    - image: gcr.io/example-builders/build-example
      command: ["echo"]
      args: ["$(params.pathToDockerFile)"]
    - name: step-3
      image: gcr.io/example-builders/push-example
      args: ["push", "$(resources.outputs.builtImage.url)"]
      volumeMounts:
        - name: docker-socket-example
          mountPath: /var/run/docker.sock
  [[#Task_Workspace|workspaces]]:
    - name: <font color=indigo>''workspace-name''</font>
      description:
      mountPath: <font color=indigo>''path-relative-to-root''</font>
  [[#Task_Volume|volumes]]:
    - name: <font color=indigo>''volume-name''</font>
      emptyDir: {}
  [[#Task_Sidecar|sidecars]]:
    - image: <font color=indigo>''some-image''</font>
      name: <font color=indigo>''some-name''</font>
      securityContext:
        privileged: true
      volumeMounts:
        - name: <font color=indigo>''some-name''</font>
          mountPath: <font color=indigo>''some-mount-path''</font>
  <font color=darkgray>[[#Task_Resources|resources]]: # deprecated
    inputs:
      - name: ...
          type: ...
    outputs:
      - name: ...
          type: ... </font>
</font>
 
===Task Parameters===
{{External|https://tekton.dev/docs/pipelines/tasks/#specifying-parameters}}
Specifies execution parameters for this task.
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Resources===
{{External|https://tekton.dev/docs/pipelines/tasks/#specifying-resources}}
[[#PipelineResource|PipelineResources]] are deprecated. This field is valid for alpha only.
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Workspace===
{{External|https://tekton.dev/docs/pipelines/tasks/#specifying-workspaces}}
Specifies paths to volumes required by the this task.
 
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Results===
{{External|https://tekton.dev/docs/pipelines/tasks/#emitting-results}}
Specifies the names under which this task writes execution results.
 
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Volume===
{{External|https://tekton.dev/docs/pipelines/tasks/#specifying-volumes}}
Specifies one or more volumes that will be available to the [[#Step|steps]] in this task.
 
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Step Template===
{{External|https://tekton.dev/docs/pipelines/tasks/#specifying-a-step-template}}
Specifies a container step definition to use as the basis for all [[#Step|steps]] in this task.
 
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Sidecar===
{{External|https://tekton.dev/docs/pipelines/tasks/#specifying-sidecars}}
Specifies sidecar containers to run alongside the [[#Step|steps]] in the task.
 
<font color=darkkhaki>TO PROCESS.</font>
 
===Task Operations===
* [[Tekton_Operations#List_Tasks|List tasks]]


=Task=
{{Internal|Tekton Task|Task}}
==ClusterTask==
==ClusterTask==
A [[#Task|task]] is available in a certain namespace, while a ClusterTask is available across the entire cluster.
A [[#Task|task]] is available in a certain namespace, while a ClusterTask is available across the entire cluster. A ClusterTask behaves identically to a task. When declaring a ClusterTask in the pipeline definition, the <code>kind</code> sub-field of the <code>taskRef</code> should be explicitly set to <code>ClusterTask</code>. If not specified, <code>kind</code> defaults to <code>Task</code>.
 
==Step==
A '''step''' is an operation in a CI/CD workflow. An example is Java compilation or execution of unit tests. Each step is performed within a container image provided when the step is defined. A step processes a set of [[#Input|inputs]] and produces a set of [[#Output|outputs]]. Steps do not exist in isolation, they are part of [[#Task|tasks]], and they are executed as running containers with the task's pod. As such, a task's steps may share a volume, that allows them to exchange data. These containers are referred to as <span id='Step_Container'></span>'''step containers'''.
===Task Step Definition===
 
==TaskRun==
{{External|https://github.com/tektoncd/pipeline/blob/main/docs/taskruns.md}}
 
A '''task run''' (or '''taskRun''') instantiates a specific [[#Task|task]] to execute on a particular set of [[#Input|inputs]] and produce a particular set of [[#Output|outputs]], within specific conditions (for example, build flags). A task run connects [[#Resource|resources]] with [[#Task|tasks]]. A task run can be created individually via CLI, by a [[#PipelineRun|pipeline run]], as part of a pipeline, or by a Tekton components such as [[#Tekton_Trigger|Tekton Triggers]]. The task run is implemented as a Kubernetes custom resource.
 
Simple taskrun example:
<syntaxhighlight lang='yaml'>
<syntaxhighlight lang='yaml'>
apiVersion: tekton.dev/v1beta1
kind: TaskRun
metadata:
  name: hello-task-run
spec:
  taskRef:
    name: hello
</syntaxhighlight>
===TaskRun Operations===
* [[Tekton_Operations#List_TaskRuns|List taskruns]]
* [[Tekton_Operations#Display_Execution_Log_of_a_TaskRun|Display execution log of a taskrun]]
==Pipeline==
{{External|https://github.com/tektoncd/pipeline/blob/main/docs/README.md}}
{{External|https://github.com/tektoncd/pipeline/blob/main/docs/pipelines.md}}
{{External|https://tekton.dev/docs/pipelines/}}
A '''pipeline''' defines a series of ordered [[#Task|tasks]]. Just like [[#Step|steps]], a task in a pipeline can use as [[#Input|input]] the [[#Output|output]] of a previously executed task. Tekton collects all the tasks, and based on the dependency relationships declared in definition of the pipeline, it orders the tasks in a [[Graph_Concepts#Directed_Acyclic_Graph_.28DAG.29|DAG]], and executes the graph in sequence. That results in the materialization of a number of task pods. The pipeline comes up with additional features, such as the capability to fan-out task execution, retry task execution or verify conditions that tasks must meet before proceeding. The pipeline is implemented as a Kubernetes custom resource.
Simple pipeline example:
<syntaxhighlight lang='yaml'>
apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: task1
spec:
  steps:
    - name: echo
      image: alpine
      script: |
        #!/bin/sh
        echo "this is Task 1 output"
---
apiVersion: tekton.dev/v1beta1
kind: Task
metadata:
  name: task2
spec:
  steps:
    - name: echo
      image: alpine
      script: |
        #!/bin/sh
        echo "this is Task 2 output"
---
apiVersion: tekton.dev/v1beta1
apiVersion: tekton.dev/v1beta1
kind: Pipeline
kind: Pipeline
metadata:
metadata:
  name: simple-pipeline
[...]
spec:
spec:
   tasks:
   tasks:
     - name: task1
     - name: some-cluster-task
       taskRef:
       taskRef:
         name: task1
         name: some-task
    - name: task2
         kind: ClusterTask
      runAfter:
...
         - task1
      taskRef:
        name: task2
</syntaxhighlight>
</syntaxhighlight>


==PipelineRun==
==Custom Task and Run==
{{External|https://github.com/tektoncd/pipeline/blob/main/docs/pipelineruns.md}}
{{Internal|Tekton_Custom_Task_and_Run|Custom Task and Run}}


A '''pipeline run''' (or '''pipelineRun''') instantiates a specific [[#Pipeline|pipeline]] to execute on a particular set of [[#Input|inputs]] and produce a particular set of [[#Output|outputs]].  A pipeline run connects [[#Resource|resources]] with [[#Pipeline|pipelines]]. A pipeline run can be created via CLI, or by a Tekton components such as [[#Tekton_Trigger|Tekton Triggers]]. The pipeline run is implemented as a Kubernetes custom resource.
=Step=
{{Internal|Tekton Step|Step}}
=TaskRun=
Include discussion on [[Tekton_TaskRun#Pod_Template|pod templates]]:
{{Internal|Tekton TaskRun#Overview|TaskRun}}


Simple pipelinerun example:
=Pipeline=
<syntaxhighlight lang='yaml'>
{{Internal|Tekton Pipeline#Overview|Pipeline}}
apiVersion: tekton.dev/v1beta1
=PipelineRun=
kind: PipelineRun
{{Internal|Tekton_PipelineRun#Overview|PipelineRun}}
metadata:
=<span id='Workspace'></span>Workspaces=
  name: simple-pipeline-run
{{Internal|Tekton Workspaces#Overview|Workspaces}}
spec:
 
  pipelineRef:
=<span id='Input_Resource'></span><span id='Output_Resource'></span><span id='PipelineResource'></span><span id='Input'></span><span id='Output'></span>Resource=
    name: simple-pipeline
{{Internal|Tekton Resource#Overview|Resources}}
</syntaxhighlight>
===PipelineRun Operations===
* [[Tekton_Operations#List_PipelineRuns|List pipelinerun]]
* [[Tekton_Operations#Display_Execution_Log_of_a_PipelineRun|Display execution log of a pipelinerun]]


==PipelineResource==
=Result=
Deprecated. Defines locations for [[#Input|inputs]] ingested and [[#Output|outputs]] produced by the [[#Step|steps]] in [[#Tasks|tasks]]. Also see [[#Task_Resources|Task Resources]].
{{Internal|Tekton_Results#Overview|Results}}


==Trigger==
=<span id='Event'></span>Events=
Implemented as part of the [[#Tekton_Triggers|Tekton Triggers]] component.
{{Internal|Tekton Events|Events}}
==Resource==
Resources are used to share data between [[#Step|steps]] and [[#Task|tasks]], and depending on which direction they are looked at, the can be [[#Input|input]] or [[#Output|output]] resources. Resources are connected to [[#Task|tasks]] and [[#Pipeline|pipelines]] by [[#TaskRun|taskRuns]] and [[#PipelineRun|pipelineRuns]], respectively. A run must include the actual addresses of resources, such as the URLs of repositories, its task or pipeline needs.


Example of resources:
=<span id='Bundle'></span>Bundles=
* git repository
{{Internal|Tekton Bundle#Overview|Bundles}}
* a pull request
=Parameters=
* a container image
{{Internal|Tekton_Parameters|Parameters}}
* a Kubernetes cluster
=<span id='LimitRange'></span>Resource Management=
* storage: an object, a directory, etc.
This section contains a discussion on [[Tekton_Resource_Management#LimitRange|LimitRange]].
* a [[CloudEvents|CloudEvent]]
{{Internal|Tekton Resource Management#Overview|Resource Management}}
===<span id='Input'></span>Input Resource===
The input is defined relative to a [[#Step|step]]. Examples of input resources are: git repository.


===<span id='Output'></span>Output Resource===
=Security=
The output is defined relative to a [[#Step|step]]. Examples of output resources: container image.
{{Internal|Tekton_Security|Security}}
==Result==
=Metrics=
{{External|https://tekton.dev/docs/results/}}
{{Internal|Tekton Metrics#Overview|Tekton Metrics}}
Tekton Results aims to help users logically group CI/CD workload history and separate out long term result storage away from the Pipeline controller.
=Hermetic Builds=
==Run==
{{External|https://tekton.dev/docs/pipelines/hermetic/}}
Instantiates a Custom Task for execution when specific inputs.
=Conditions=
{{External|https://tekton.dev/docs/pipelines/conditions/}}
Conditions are deprecated, use <code>[[Tekton_Pipeline#Conditional_Execution_with_when|when]]</code> expressions instead.


=Tekton Runtime Model=
=Programming Model=
[[#Tekton_Pipelines|Tekton Pipelines]] tracks the state of a [[#Pipeline|pipeline]] using [[Kubernetes_Labels_and_Annotations#Annotations|Kubernetes annotations]], which are projected inside each [[#Step_Container|step container]] in the form of files with the [[Kubernetes_Downward_API_Concepts|Kubernetes Downward API]].  The step container entrypoint binary watches these projected files and will only start the command the step is supposed to execute only if a specific annotation appears as file.  
<font color=darkkhaki>
Process Task Authoring Recommendations: https://github.com/tektoncd/catalog/blob/main/recommendations.md
</font>
==<span id='Variable_Substitution'><span>Variables==
<font color=darkkhaki>TO PROCESS:
* https://tekton.dev/docs/pipelines/variables/
* https://tekton.dev/docs/pipelines/tasks/#using-variable-substitution
* Variables available in a Task https://tekton.dev/docs/pipelines/variables/#variables-available-in-a-task
* Variables available in a Pipeline https://tekton.dev/docs/pipelines/variables/#variables-available-in-a-pipeline
* Fields that accept variable substitutions: https://tekton.dev/docs/pipelines/variables/#fields-that-accept-variable-substitutions
* Using variable substitution in pipelines: https://tekton.dev/docs/pipelines/pipelines/#using-variable-substitution
</font>


In addition, Tekton Pipelines schedules some containers to run automatically before and after the step containers to support built-in features such as the retrieval of input resources and the uploading the outputs to wherever they are supposed to go.
==Code Examples==
<font color=darkkhaki>
* Code Examples: https://tekton.dev/docs/pipelines/tasks/#code-examples
* Code Examples: https://github.com/tektoncd/pipeline/tree/main/examples
* TaskRun code examples: https://tekton.dev/docs/pipelines/taskruns/#code-examples
* https://github.com/tektoncd/pipeline/blob/release-v0.35.x/examples/v1beta1/taskruns/run-steps-as-non-root.yaml
* Pipeline code examples: https://github.com/tektoncd/pipeline/tree/main/examples
* Variable substitution: https://tekton.dev/docs/pipelines/tasks/#using-variable-substitution
Start the list here:
* How to do this
* How to do that
</font>


=Playground=
{{External|https://github.com/ovidiuf/playground/tree/master/tekton}}
=Tekton Components=
=Tekton Components=
==Tekton Pipelines==
==Tekton Pipelines==
Line 262: Line 114:


==Tekton CLI==
==Tekton CLI==
{{External|https://github.com/tektoncd/cli/blob/main/README.md}}
{{Internal|Tekton_CLI#Overview|Tekton CLI}}
Tekton CLI provides the command interface called <code>tkn</code>.
 
===Tekton CLI Operations===
* [[Tekton_Operations#Tekton_CLI_Installation|Installation]]
==Tekton API==
==Tekton API==
Tekton APIs are currently available for [[#Pipeline|Pipelines]] and [[#Trigger|Triggers]] allow you to programmatically interact with the Tekton components.
Tekton APIs are currently available for [[#Pipeline|Pipelines]] and [[#Trigger|Triggers]] allow you to programmatically interact with the Tekton components.


==Tekton Catalog==
==Tekton Catalog==
{{External|https://github.com/tektoncd/catalog/blob/v1beta1/README.md}}
{{Internal|Tekton_Catalog#Overview|Tekton Catalog}}
Tekton Catalog is a repository of community-contributed Tekton [[#Building_Block|building blocks]].
 
==Tekton Hub==
==Tekton Hub==
{{External|https://hub.tekton.dev}}
{{Internal|Tekton_Hub#Overview|Tekton Hub}}
{{External|https://github.com/tektoncd/hub/blob/main/README.md}}
Tekton Hub is a web GUI to access [[#Tekton_Catalog|Tekton Catalog]].


==Tekton Triggers==
==<span id='Trigger'></span>Tekton Triggers==
{{External|https://github.com/tektoncd/triggers/blob/main/README.md}}
{{Internal|Tekton_Triggers#Overview|Tekton Triggers}}
Tekton Triggers provide [[#Trigger|triggers]], which allow instantiating pipelines based on events (a PR merge, etc.)


==Tekton Dashboard==
==Tekton Dashboard==
{{External|https://github.com/tektoncd/dashboard/blob/main/README.md}}
{{Internal|Tekton_Dashboard#Overview|Tekton Dashboard}}
Tekton Dashboard is the web GUI that displays information about pipeline execution.
 
==Tekton Operator==
==Tekton Operator==
{{External|https://github.com/tektoncd/operator/blob/main/README.md}}
{{Internal|Tekton_Operator#Overview|Tekton Operator}}
Tekton Operator is the implementation of the [[Kubernetes Operators Concepts|Kubernetes Operator pattern]] that assists with the operation of the Tekton projects.


=Building Block=
==HA Support==
Tekton documentation refers to "building blocks". <font color=darkkhaki>Those are ... </font>
{{Internal|Tekton_Operations#HA_Support|Tekton Operations &#124; HA Support}}
=Programming Model=
{{External|https://github.com/tektoncd/pipeline/tree/main/examples}}

Latest revision as of 05:45, 29 April 2022

External

Internal

Overview

Tekton is a cloud-native solution for building CI/CD pipelines. Tekton installs and runs as an extension on your Kubernetes cluster and uses the well-established Kubernetes resource model. Tekton workloads execute inside Kubernetes containers. It is implemented as a set of Kubernetes Custom Resources. It has several components: Tekton Pipelines, Tekton CLI and Tekton Catalog. Once deployed, Tekton can be accessed via Tekton CLI commands or API calls. Tekton is part of the CD Foundation, a Linux Foundation project.

Tekton Runtime Model

Tekton Pipelines tracks the state of a pipeline using Kubernetes annotations, which are projected inside each step container in the form of files with the Kubernetes Downward API. The step container entrypoint binary watches these projected files and will only start the command the step is supposed to execute only if a specific annotation appears as file. For more details see:

Tekton Labels and Annotations

In addition, Tekton Pipelines schedules some containers to run automatically before and after the step containers to support built-in features such as the retrieval of input resources and the uploading the outputs to wherever they are supposed to go.

Task

Task

ClusterTask

A task is available in a certain namespace, while a ClusterTask is available across the entire cluster. A ClusterTask behaves identically to a task. When declaring a ClusterTask in the pipeline definition, the kind sub-field of the taskRef should be explicitly set to ClusterTask. If not specified, kind defaults to Task.

apiVersion: tekton.dev/v1beta1
kind: Pipeline
metadata:
[...]
spec:
  tasks:
    - name: some-cluster-task
      taskRef:
        name: some-task
        kind: ClusterTask
 ...

Custom Task and Run

Custom Task and Run

Step

Step

TaskRun

Include discussion on pod templates:

TaskRun

Pipeline

Pipeline

PipelineRun

PipelineRun

Workspaces

Workspaces

Resource

Resources

Result

Results

Events

Events

Bundles

Bundles

Parameters

Parameters

Resource Management

This section contains a discussion on LimitRange.

Resource Management

Security

Security

Metrics

Tekton Metrics

Hermetic Builds

https://tekton.dev/docs/pipelines/hermetic/

Conditions

https://tekton.dev/docs/pipelines/conditions/

Conditions are deprecated, use when expressions instead.

Programming Model

Process Task Authoring Recommendations: https://github.com/tektoncd/catalog/blob/main/recommendations.md

Variables

TO PROCESS:

Code Examples

Start the list here:

  • How to do this
  • How to do that

Playground

https://github.com/ovidiuf/playground/tree/master/tekton

Tekton Components

Tekton Pipelines

https://github.com/tektoncd/pipeline/blob/main/docs/README.md

Tekton Pipelines is the component that implements the core functionality of Tekton and sets the foundation for other components. It is implemented as a set of Kubernetes Custom Resources.

Tekton Pipeline Runtime

Tekton Pipelines Controller

Tekton Pipelines Webhook

Tekton Pipeline Operations

Tekton CLI

Tekton CLI

Tekton API

Tekton APIs are currently available for Pipelines and Triggers allow you to programmatically interact with the Tekton components.

Tekton Catalog

Tekton Catalog

Tekton Hub

Tekton Hub

Tekton Triggers

Tekton Triggers

Tekton Dashboard

Tekton Dashboard

Tekton Operator

Tekton Operator

HA Support

Tekton Operations | HA Support