Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
78 commits
Select commit Hold shift + click to select a range
dddc082
Gitops for SCMM, Registry, Jenkins (#386)
nihussmann Jun 16, 2026
95ecc4e
this new step scans the code quality with sonarqube
DerDaehne Jun 18, 2026
23252f2
Merge pull request #508 from cloudogu/feature/integrate-sonar-scanner
DerDaehne Jun 18, 2026
f017547
Prevent SCM-Manager Argo CD Tracking Collisions in Multi-Tenant Setup…
avetgit Jun 23, 2026
bfa23a7
fix k8s-debug file permissions in Jenkinsfile (#514)
FelixWende99 Jun 26, 2026
d2f2758
Fix SCM-Manager URL resolution for tenant and central providers (#516)
avetgit Jun 29, 2026
4a2f04e
Merge main into develop (#517)
ThomasMichael1811 Jun 29, 2026
362f496
Support Custom Jenkins and SCM-Manager Images (#511)
FelixWende99 Jun 30, 2026
5805a65
Introduce DeploymentContext for GOP runtime (#515)
FelixWende99 Jun 30, 2026
4559e99
Introduce OIDC Authentication Support for GOP Tools (#510)
FelixWende99 Jun 30, 2026
d2701b1
Fix/remove petclinic test from prefix (#518)
FelixWende99 Jul 1, 2026
ccc9ee8
remove .localhost from petclinic example (#520)
ThomasMichael1811 Jul 1, 2026
a34acb2
treat pod status succeeded as non fatal in integration tests (#521)
FelixWende99 Jul 2, 2026
5913f09
Introduce repository provisioning and workspace handling (#519)
avetgit Jul 3, 2026
9e5a1b3
Update dependency io.kubernetes:client-java to v26.0.1 (#524)
cesmarvin Jul 3, 2026
d27d1d8
Update dependency maven to v3.9.16 (#526)
cesmarvin Jul 7, 2026
04a70a4
Update dependency com.networknt:json-schema-validator to v3.0.5 (#523)
cesmarvin Jul 7, 2026
d0ea651
Update dependency com.fasterxml.jackson.dataformat:jackson-dataformat…
cesmarvin Jul 7, 2026
db7e890
Update dependency org.glassfish.jaxb:jaxb-runtime to v4.0.9 (#529)
cesmarvin Jul 7, 2026
6517cd0
Update dependency org.apache.groovy:groovy-all to v5.0.6 (#527)
cesmarvin Jul 7, 2026
46dd6b1
Introduce DeploymentOrchestrator for tool execution (#522)
FelixWende99 Jul 7, 2026
1a40603
Update dependency org.apache.maven.plugins:maven-surefire-plugin to v…
cesmarvin Jul 7, 2026
3fade85
Update dependency org.jacoco:jacoco-maven-plugin to v0.8.15 (#530)
cesmarvin Jul 7, 2026
0fd2b7e
Update dependency org.springframework:spring-jcl to v6.2.19 (#531)
cesmarvin Jul 8, 2026
83aa429
Update jetty monorepo to v12.1.10 (#532)
cesmarvin Jul 8, 2026
310cab5
Update dependency org.apache.groovy:groovy-all to v5.0.7 (#534)
cesmarvin Jul 8, 2026
1e8a910
Move tool-specific GitOps resource preparation into owning tools (#536)
avetgit Jul 8, 2026
6387145
Refactor tool execution into explicit lifecycle phases (#538)
avetgit Jul 10, 2026
3ed7f4a
Add typed OIDC setup for GOP tools (#539)
FelixWende99 Jul 14, 2026
2ba77a9
Add sonar-maven-plugin (#548)
avetgit Aug 6, 2026
ee2e02f
Complete Groovy to Java 25 migration and modernize with Lombok and Re…
DerDaehne Aug 13, 2026
3362f41
Publish unit test results in Jenkins
avetgit Aug 13, 2026
d663bff
Remove inactive Renovate assignee
avetgit Aug 13, 2026
57f9505
Merge pull request #551 from cloudogu/feature/publish-test-reports
alexander-dammeier Aug 14, 2026
0192640
Migrate config renovate.json (#550)
cesmarvin Aug 14, 2026
fb298e8
fix: update Jenkins Mina SSHD plugins to resolve critical CVE (#552)
avetgit Aug 14, 2026
16bfc8f
update jenkins plugins to newer version. (#556)
ThomasMichael1811 Aug 18, 2026
c746c07
Decouple deployable tools from the central Config (#549)
avetgit Aug 18, 2026
d60f570
Update dependency org.apache.maven.plugins:maven-dependency-plugin to…
cesmarvin Aug 18, 2026
c96a539
Remove Config from DeploymentContext (#553)
avetgit Aug 19, 2026
52dfe72
establishing compatibility with Apple architecture
ThomasMichael1811 Sep 7, 2026
eb10d61
Migrate tests from Groovy to Java and remove Groovy build dependencie…
avetgit Sep 8, 2026
95d01f3
Resolve credentials from Kubernetes Secrets at runtime (#563)
avetgit Sep 9, 2026
86b5076
Add secret-based full profile with integration coverage (#564)
avetgit Sep 9, 2026
435a490
Update dependency com.fasterxml.jackson.core:jackson-databind to v2.2…
cesmarvin Sep 9, 2026
1dabc97
remove assiginees for automate commits
ThomasMichael1811 Sep 9, 2026
496aa69
Merge pull request #565 from cloudogu/ThomasMichael1811-patch-1
alexander-dammeier Sep 9, 2026
111814c
Update dependency org.eclipse.jgit:org.eclipse.jgit to v7.7.1.2026072…
cesmarvin Sep 9, 2026
36441ce
Update dependency tools.jackson.core:jackson-databind to v3.2.1 [SECU…
cesmarvin Sep 9, 2026
0e13b84
document local setup on OpenShift with CRC
ThomasMichael1811 Sep 9, 2026
f947e57
Update dependency com.networknt:json-schema-validator to v3.0.7
cesmarvin Sep 9, 2026
6d7418b
Update dependency org.gitlab4j:gitlab4j-api to v6.3.0
cesmarvin Sep 9, 2026
be80112
Update dependency helm/helm to v4.2.4 (#567)
cesmarvin Sep 10, 2026
5543ac1
Update dependency io.micronaut.platform:micronaut-parent to v4.10.17 …
cesmarvin Sep 10, 2026
00ee9f4
Update dependency io.github.classgraph:classgraph to v4.8.194
cesmarvin Sep 10, 2026
d8ca88e
fix critical cve in netty-handler
mdroll Sep 10, 2026
2e456c0
Update dependency io.github.git-commit-id:git-commit-id-maven-plugin …
cesmarvin Sep 10, 2026
1558cef
Update dependency org.projectlombok:lombok to v1.18.48 (#574)
cesmarvin Sep 11, 2026
efa2052
update a lot of libs manually
ThomasMichael1811 Sep 11, 2026
ec61706
Update dependency org.apache.maven.plugins:maven-jar-plugin to v3.5.1
cesmarvin Sep 11, 2026
b7d1505
Update Helm release jenkins to v5.9.56
cesmarvin Sep 11, 2026
7e9277d
Update dependency org.freemarker:freemarker to v2.3.35 (#572)
cesmarvin Sep 11, 2026
f6ec71b
Update jackson monorepo
cesmarvin Sep 13, 2026
6849916
Revert "Update jackson monorepo"
ThomasMichael1811 Sep 14, 2026
982e1dc
Update Helm release traefik to v39.0.9
cesmarvin Sep 14, 2026
c2e0ecf
Remove system stubs from environment tests
avetgit Sep 11, 2026
06a576c
Replace OpenShift client with generic resources
avetgit Sep 11, 2026
f26621d
Use Fabric8 in monitoring integration tests
avetgit Sep 11, 2026
40e12d1
Disable Mockito agent-based mocking
avetgit Sep 11, 2026
d261277
Replace Awaitility with JDK polling
avetgit Sep 11, 2026
9ca6f12
Make timeout retry test deterministic
avetgit Sep 11, 2026
98ac7a5
Replace WireMock Jetty with approved standalone artifact
avetgit Sep 11, 2026
de3f365
Remove VersionName annotation processor
avetgit Sep 11, 2026
5f0af49
update ingress test
ThomasMichael1811 Sep 15, 2026
b00b2b9
update ingress to v39.0.9 and image to 3.6.15
ThomasMichael1811 Sep 15, 2026
f97e39e
reenable cve scanning and soft aborting on high critical cve
mdroll Sep 15, 2026
b4ea106
Sync main changes into develop (#586)
avetgit Sep 16, 2026
29114ae
Merge remote-tracking branch 'origin/main' into merge/develop-into-main
avetgit Sep 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 1 addition & 2 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,11 @@
!.curlrc
!LICENSE

# groovy cli
# CLI build
!src
!pom.xml
!mvnw
!.mvn
!compiler.groovy

# Including .git is risky, but required so maven can read the build number. At least keep it to a minium.
!.git/HEAD
Expand Down
811 changes: 718 additions & 93 deletions .editorconfig

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
.idea
.run
.codex
*.iml
target

Expand Down
2 changes: 1 addition & 1 deletion .mvn/wrapper/maven-wrapper.properties
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
wrapperVersion=3.3.4
distributionType=script
distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.15/apache-maven-3.9.15-bin.zip
distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.16/apache-maven-3.9.16-bin.zip
wrapperUrl=https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.3.4/maven-wrapper-3.3.4.jar
361 changes: 361 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,361 @@
# Contributing

Thanks for taking the time to contribute! This document describes the conventions we
follow so that the codebase stays consistent and reviews stay fast. Please read it
before opening a pull request.

## Table of Contents

- [Language](#language)
- [Branching Strategy](#branching-strategy)
- [Commit Guidelines](#commit-guidelines)
- [Pull Requests](#pull-requests)
- [Code Style (Java)](#code-style-java)
- [Testing](#testing)
- [Code Review Etiquette](#code-review-etiquette)

## Language

- Write all code and comments in English.
- Project documentation is written in German. (This CONTRIBUTING guide is in English,
following the convention of the platform it's hosted on.)

## Branching Strategy

- `develop` contains the latest state of development.
- `main` reflects the current release.
- Use `feature/<description>` branches for new functionality
(e.g. `feature/add-user-authentication`).
- Use `fix/<description>` branches for bug fixes in existing code
(e.g. `fix/login-button-not-working`).
- Use `hotfix/<description>` branches for critical fixes against `main`
(e.g. `hotfix/security-patch-for-cve-2024-1234`).

## Commit Guidelines

- **Write small, focused commits.** Each commit should contain a single, logical
change. Avoid bundling unrelated changes together.
- **Commit frequently.** Frequent commits with clear messages make rollbacks and
history easier to follow.
- **Write meaningful commit messages.** The diff already shows *what* changed; the
commit message should explain *why*. Write it so an outside developer can
understand it without additional context.

```
# bad
"Add method validate"

# good
"Validate feature configuration before enabling to prevent runtime errors in production"
```

- **Write commit messages in English.**
- **Use semantic versioning for tags.** Follow [SemVer](https://semver.org/) for
release tags (e.g. `v1.0.0`, `v2.3.1`).
- **Run a linter before committing or pushing** (e.g. Checkstyle or PMD) to catch
style issues and common bugs automatically.

## Pull Requests

- **Keep PRs small.** Large pull requests are hard to merge and either stall in
review or get rubber-stamped without a real look.
- **Provide context in the description.** Explain the goal of the PR and how the
change can be tested — it helps reviewers understand the code faster.
- **Ensure CI is green** before requesting review and before merging.
- **Use descriptive PR titles.** PR titles are often used to generate changelogs, so
avoid vague titles like "fix bug" or "refactoring". Prefer precise titles such as
`fix: resolve memory leak in session management`.
- **Prefer merge commits (`--no-ff`) over squash** when merging, so the full history
of development steps stays traceable. Squashing is acceptable for hotfixes or small
changes to keep the history clean.

## Code Style (Java)

- Use `camelCase` for variable and method names, `PascalCase` for class and enum
names, and tabs for indentation.
- Use descriptive names for variables and methods — verbose, speaking names help the
reader understand code faster and should reveal *what* a method does, not *how*.
- Use explicit typing; avoid overusing `var`. Only use `var` when the type is already
obvious from the right-hand side (e.g. `var client = new HttpClientFactory()`);
spell out the type when it comes from a method call or generic expression whose
return type isn't visible at the call site.

```java
// bad
var result = repository.find(id);

// good
Optional<Repository> result = repository.find(id);
```

- Use named lambda parameters instead of single letters, especially in nested streams.

```java
// bad
users.stream().filter(u -> u.isActive()).forEach(u -> u.sendNotification());

// good
users.stream()
.filter(user -> user.isActive())
.forEach(activeUser -> activeUser.sendNotification());
```

- Use `Optional<T>` only for genuinely optional values — reserve it for values that
are legitimately absent (e.g. a lookup that may find nothing), and use
`Objects.requireNonNull()` / fail-fast validation for values that must always be
present. Don't wrap required fields in `Optional` just to avoid a null check. Once a
value is an `Optional<T>`, unwrap it with `orElse`/`orElseGet` (or a ternary for
plain nullable references) rather than calling `.get()` behind a null check.

```java
// bad (address must always be present)
String zip = user.getAddress() == null ? null : user.getAddress().getZipCode();

// good (address is genuinely optional)
Optional<Address> address = user.getAddress();
String zip = address.map(Address::getZipCode).orElse(null);
```

```java
// bad
String name = user.getName() != null ? user.getName() : "Default";

// good (Optional-based)
String name = Optional.ofNullable(user.getName()).orElse("Default");
```

- Prefer builders over long constructors once a type has more than 2-3 fields, so call
sites read like named arguments (we use Lombok's `@Builder`). Whenever a fluent
chain (builder or otherwise) exceeds 2-3 calls, put each call on its own line for
readability.

```java
// bad
Config config = new Config(host, port, true, false, null, retries);
config.setHost("localhost").setPort(8080).setEnabled(true).setDebug(false);

// good
Config config = Config.builder()
.host(host)
.port(port)
.enabled(true)
.build();

config.setHost("localhost")
.setPort(8080)
.setEnabled(true)
.setDebug(false);
```

- Use comments to explain *why* code does something, not *what* it does. What the
code does should already be self-explanatory.

```java
// bad
// set retry to 3
int retryCount = 3;

// good
// we use 3 retries because the external API is unstable
int retryCount = 3;
```

- **Fail fast** and **use defensive programming** — validate inputs up front and
return safe defaults instead of propagating `null`.

```java
// fail fast
void processOrder(Order order) {
if (order == null) {
throw new IllegalArgumentException("Order must not be null");
}
// ... logic
}

// defensive programming
List<String> getTags(User user) {
if (user.getTags() == null) {
return List.of();
}
return user.getTags();
}
```

- Keep classes and methods small and focused, following the single responsibility
principle.

```java
// bad
class OrderManager {
void processOrder(Order order) { /* ... */ }
void sendEmail(String recipient, String message) { /* ... */ }
void saveToDatabase(Order order) { /* ... */ }
}

// good
class OrderService {
void processOrder(Order order) { /* ... */ }
}

class EmailService {
void sendEmail(String recipient, String message) { /* ... */ }
}
```

- Use the right exceptions. Prefer specific exceptions over the generic
`RuntimeException`/`Exception`, and create custom exception classes where the
context calls for it.

```java
// bad
throw new RuntimeException("Order not found");

// good
throw new OrderNotFoundException("Order with ID " + orderId + " not found");
```

- Avoid deeply nested code. Use guard clauses and fail-fast to keep nesting depth low.

```java
// bad
void process(User user) {
if (user != null) {
if (user.isActive()) {
// ... a lot of logic
}
}
}

// good
void process(User user) {
if (user == null || !user.isActive()) {
return;
}
// ... a lot of logic
}
```

- Obey the boy scout rule: "Always leave the campground cleaner than you found it."
When you touch a file, fix small messes (typos, formatting) in the immediate area of
your change.

- Prefer text blocks / `String.format` over ad hoc concatenation when building
strings — plain literals for static text, `String.format(...)` or text blocks
(`"""..."""`, Java 15+) when you actually need to build a string from parts.

```java
// good
String constant = "I am a static string";
String dynamic = String.format("I am dynamic: %s", constant);
```

- Avoid runtime metaprogramming and reflection. Reflection-based frameworks and
dynamic proxies bypass compile-time type checking, hurt performance, and are
fragile at runtime. Prefer direct API calls, interfaces, or
composition/polymorphism.

```java
// bad
Method method = UserService.class.getDeclaredMethod("doSomething");
method.invoke(userService);

// good
userService.doSomething();
```

- Use `@Slf4j` for logging. Lombok's `@Slf4j` annotation injects a
`private static final Logger log` field — don't hand-declare a `Logger` via
`LoggerFactory.getLogger(...)` for a class's own logging. (A deliberately-named,
cross-cutting logger not tied to the enclosing class name is a legitimate
exception, since `@Slf4j` can only produce a logger named after the class.)

```java
// bad
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

class UserService {
private static final Logger log = LoggerFactory.getLogger(UserService.class);
}

// good
import lombok.extern.slf4j.Slf4j;

@Slf4j
class UserService {
void doSomething() {
log.info("Doing something...");
}
}
```

- Use uniform logging levels, consistently and deliberately, to keep log volume and
readability sane in production:
- `debug` / `trace`: detailed diagnostic info for development-time troubleshooting
(e.g. method parameters, loop iterations).
- `info`: important, business-critical or systemic milestones (e.g. successful
startup, completed transaction). Don't overuse.
- `warn`: unexpected situations that don't block the flow (e.g. fallbacks, use of
deprecated APIs, transient connection errors).
- `error`: errors that require aborting or manual intervention (e.g. caught
exceptions, system failures).

## Testing

We use JUnit 5 and Mockito.

- Use descriptive test class names (e.g. `UserServiceTest`).
- Structure tests with given-when-then / arrange-act-assert comments.
- Use `@ParameterizedTest` (with `@ValueSource`, `@CsvSource` or `@MethodSource`) for
data-driven tests.
- Mock external dependencies using Mockito's `@Mock` / `Mockito.mock(...)`.

```java
class CalculatorTest {

private final Calculator calculator = new Calculator();

@ParameterizedTest
@CsvSource({
"5, 10, 15",
"0, 0, 0",
"-3, 3, 0"
})
void shouldCalculateSumCorrectly(int a, int b, int expected) {
// when
int result = calculator.add(a, b);

// then
assertEquals(expected, result);
}
}
```

```java
@ExtendWith(MockitoExtension.class)
class OrderServiceTest {

@Mock
private OrderRepository orderRepository;

@InjectMocks
private OrderService orderService;

@Test
void shouldThrowWhenOrderNotFound() {
// given
when(orderRepository.findById("123")).thenReturn(Optional.empty());

// when / then
assertThrows(OrderNotFoundException.class, () -> orderService.getOrder("123"));
}
}
```

## Code Review Etiquette

- **Be constructive and respectful.** Criticize the code, not the author. Phrase
suggestions as questions or ideas (e.g. "Have you considered...?" instead of
"This is wrong").
- **Praise good code.** If you see a particularly elegant solution, say so — reviews
are also a place to learn and to give positive feedback.
Loading
Loading