Files
devops-lib-gcp/docs/wiki/pages/06-CONFIG-POLICY.md
T
2026-08-26 02:02:24 +05:30

5.7 KiB

Generated 2026-05-12 at base-sha 28f54cf7bef9. Type: top-level. 0 sources.

Config and Policy

constructParam.groovy does two things: it resolves all env.* variables from config.yaml and the current branch/environment, and it enforces five policy gates by fetching Meesho/whitelists at runtime.

TL;DR

  • config.yaml is the service's contract — getYamlParameter.getParam() reads it before any build runs.
  • constructParam.run() sets 15+ env.* vars (registry, vault, sonar, GCPProject, etc.) based on cicd_environment.
  • Five whitelist files are fetched from Meesho/whitelists at runtime via git clone — not bundled.
  • Whitelisted policies: skip-sonar, app-config-disabled, multizone, allowedNonDevelopPrToInt, ValidateCacConfig.
  • ValidateCacConfig gate triggers validate_configs_v2.py on Go and Maven PRs.

Mental model

constructParam is the policy layer. All build and deploy stages read env.* but never set it — they are consumers. constructParam is the sole producer. This ensures every stage shares a consistent view of which cloud, environment, registry, and policy applies to this build.

The whitelist pattern allows DevOps to grant exceptions without modifying any service's code — a repo is added to Meesho/whitelists/skip-sonar-whitelist.yaml and the next build automatically picks up the exception.

Structure / data flow

config.yaml (in service repo):
  repo_name, build_tool, dockerBuildVersion, bu, team,
  deployment_order, notify_channel, skip_sonar, deployArgo, appConfigEnabled

getYamlParameter.getParam(repo_name) → param Map

constructParam.run(param):
  ├─ environment_map → env.cicd_environment
  ├─ GCP accountDetails[env.cicd_environment]:
  │    env.GCPProject, env.registry, env.buildRegistry
  │    env.vaultURL/Token, env.sonarURL/Token
  │    env.objBucket, env.DOCKER_HOST
  │
  ├─ [whitelist gate] skipSonarCheckForbidden() → clone Meesho/whitelists/skip-sonar-whitelist.yaml
  ├─ [whitelist gate] appConfigDisabledForbidden() → app-config-disabled.yaml
  ├─ [whitelist gate] isMultizoneEnabled() → multizone-enabled-repos.yaml
  ├─ [whitelist gate] allowedNonDevelopPrDeploymentToIntRepos() → allowedNonDevelopPrDeploymentToInt.yaml
  └─ [whitelist gate] ValidateCacConfigForRepo() → ValidateCacConfig.yaml

Key code locations

Symbol File What it does
run src/com/meesho/utilities/constructParam.groovy:run Main env var setter
perDeploymentVars src/com/meesho/utilities/constructParam.groovy:perDeploymentVars Sets per-deployable ArgoCD vars
getWhitelistedRepos src/com/meesho/utilities/constructParam.groovy:getWhitelistedRepos Clones Meesho/whitelists and reads a YAML file
skipSonarCheckForbidden src/com/meesho/utilities/constructParam.groovy:skipSonarCheckForbidden Blocks Maven prd builds with skip_sonar=true if not whitelisted
appConfigDisabledForbidden src/com/meesho/utilities/constructParam.groovy:appConfigDisabledForbidden Blocks stg deploys if appConfig disabled and not whitelisted
isMultizoneEnabled src/com/meesho/utilities/constructParam.groovy:isMultizoneEnabled Returns true for deployables in multizone whitelist
ValidateCacConfigForRepo src/com/meesho/utilities/constructParam.groovy:ValidateCacConfigForRepo Returns true if repo must run CAC validation
getParam src/com/meesho/utilities/getYamlParameter.groovy:getParam Reads a YAML file from the workspace

Sharp edges

  • Each whitelist call does a fresh git clone: getWhitelistedRepos() clones Meesho/whitelists into a whitelist/ subdirectory every time it's called. Five separate calls = five clones in the same build. Network latency here directly adds to build time. This is deliberate — each clone captures the latest whitelist state so a DevOps policy change takes effect on the very next build without a library release. Never cache across calls.
  • Go sonar-skip logic is in constructParam.groovy, not buildGo.groovy: skipSonarCheckForGo(Map config) (src/com/meesho/utilities/constructParam.groovy:skipSonarCheckForGo) centralises all skip-sonar policy. Embedding whitelist checks inline in language build stages is the wrong pattern.
  • perDeploymentVars must run before ArgoCD steps: it sets env.argoURL, env.argoCreds, env.argoAppNS, and env.argoIncubator per deployable. Calling ArgoCD stages before this results in empty ArgoCD credentials.
  • bu drives GCP project name: prodGCPProject = "meesho-${config.bu}-prd-0622". An invalid or misspelled bu in config.yaml produces a nonexistent GCP project name.
  • Toolchain env skips several policies: when env.INFRA_ENV == 'toolchain', skip_sonar is forced true and vault/sonar are pointed at toolchain-dind-dev-svc.

Notes


← Previous · Index · Next →