blob: 23454d9e3e5090bdc6653de2e3e187bdd23bdc0f [file] [log] [blame]
Ales Komarek3446a0a2016-03-08 10:21:00 +01001
OlgaGusarenkocb981942018-07-30 17:26:31 +03002=====
3Usage
4=====
Ales Komarek3446a0a2016-03-08 10:21:00 +01005
OlgaGusarenkocb981942018-07-30 17:26:31 +03006Gerrit provides web based code review and repository management for the Git
7version control system.
Ales Komarek3446a0a2016-03-08 10:21:00 +01008
9Sample pillars
10==============
11
Ales Komarek49a37292016-08-31 16:18:31 +020012Simple gerrit service
Ales Komarek3446a0a2016-03-08 10:21:00 +010013
14.. code-block:: yaml
15
16 gerrit:
17 server:
18 enabled: true
Ales Komarek7f93ce22016-08-29 23:27:47 +020019 source:
20 engine: http
21 address: https://gerrit-ci.gerritforge.com/job/Gerrit-stable-2.13/20/artifact/buck-out/gen/gerrit.war
22 hash: 2e17064b8742c4622815593ec496c571
Ales Komarek3446a0a2016-03-08 10:21:00 +010023
Ales Komarek49a37292016-08-31 16:18:31 +020024Full service setup
25
26.. code-block:: yaml
27
28 gerrit:
29 server:
Martin Polreich5ec9e542018-07-17 13:54:55 +020030 enabled: true
Ales Komarek49a37292016-08-31 16:18:31 +020031 canonical_web_url: http://10.10.10.148:8082/
32 email_private_key: ""
33 token_private_key: ""
34 initial_user:
35 full_name: John Doe
36 email: 'mail@jdoe.com'
37 username: jdoe
38 plugin:
39 download-commands:
40 engine: gerrit
41 # replication:
42 # engine: gerrit
43 reviewnotes:
44 engine: gerrit
45 singleusergroup:
46 engine: gerrit
47 ssh_rsa_key: |
48 -----BEGIN RSA PRIVATE KEY-----
49 MIIEowIBAAKCAQEAs0Y8mxS3dfs5zG8Du5vdBkfOCOng1IEUmFZIirJ8oBgJOd54
50 QgmkDFB7oP9eTCgz9k/rix1uJWhhVCMBzrWzH5IODO+tyy/tK66pv2BWtVfTDhBA
51 nShOLDNbSIBaV8E/NcrbnQN+b0alp4N7rQnavkOYl+JQncKjz1csmCodirscB9Oj
52 rdo6NG9olv9IQd/tDQxEeDyQkoW50aCEWcq7o+QaTzgnlrL+XZEzhzjdcvA9m8go
53 ...
54 jvMXms60iD/A5OpG33LWHNNzQBP486SxG75LB+Xs5sp5j2/b7VF5LJLhpGiJv9Mk
55 ydbuy8iuuvali2uF133kAlLqnrWfVTYQQI1OfW5glOv1L6kv94dU
56 -----END RSA PRIVATE KEY-----
57 ssh_rsa_key_pub: ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCzRjybFLd1+znMbwO7m90GR84I6eDUgRSYVkiKsnygGAk53nhCCaQMUHug/15MKDP2T+uLHW4laGFUIwHOtbMfkg4M763LL+0rrqm/YFa1V9MOEECdKE4sM1tIgFpXwT81ytudA35vRqWng3utCdq+Q5iX4lCdwqPPVyyYKh2KuxwH06Ot2jo0b2iW/0hB3+0NDER4PJCShbnRoIRZyruj5BpPOCeWsv5dkTOHON1y8D2byCgNGdCBIRx7x9Qb4dKK2F01r0/bfBGxELJzBdQ8XO14bQ7VOd3gTxrccTM4tVS7/uc/vtjiq7MKjnHGf/svbw9bTHAXbXcWXtOlRe51
58 email: mail@domain.com
59 auth:
60 engine: HTTP
61 source:
62 engine: http
63 address: https://gerrit-releases.storage.googleapis.com/gerrit-2.12.4.war
64 hash: sha256=45786a920a929c6258de6461bcf03ddec8925577bd485905f102ceb6e5e1e47c
Jakub Josef09765e12018-01-09 13:28:20 +010065 receive_timeout: 5min
66 sshd:
67 threads: 64
68 batch_threads: 16
69 max_connections_per_user: 64
Ales Komarek49a37292016-08-31 16:18:31 +020070 database:
71 engine: postgresql
72 host: localhost
73 port: 5432
74 name: gerrit
75 user: gerrit
76 password: ${_param:postgresql_gerrit_password}
Jakub Josef09765e12018-01-09 13:28:20 +010077 pool_limit: 250
Sergey Otpuschennikov584698f2018-08-24 18:29:16 +040078 pool_max_idle: 16
79
80
81Gerrit LDAP authentification
82
83.. code-block:: yaml
84
85 gerrit:
86 server:
87 auth:
88 engine: LDAP
89 ldap_server: ldap://ldap.mycompany.net
90 ldap_account_base: dc=company,dc=net
91 ldap_group_base: ou=Groups,dc=company,dc=net
Sergey Otpuschennikov9d8e8cc2018-11-06 14:08:19 +040092 ldap_account_pattern: uid=${username}
93 ldap_group_pattern: (cn=${groupname})
94 ldap_group_query: true
95 ldap_group_member_pattern: (memberUid=${username})
Sergey Otpuschennikov584698f2018-08-24 18:29:16 +040096
Jakub Josef09765e12018-01-09 13:28:20 +010097
98Gerrit change auto abandon
99
100.. code-block:: yaml
101
102 gerrit:
103 server:
104 change_cleanup:
105 abandon_after: 3months
Ales Komarek49a37292016-08-31 16:18:31 +0200106
Ales Komarek2fc39002016-09-14 11:43:56 +0200107
108Gerrit client enforcing groups
109
110.. code-block:: yaml
111
112 gerrit:
113 client:
114 group:
115 Admin001:
116 description: admin 01
117 Admin002:
118 description: admin 02
119
120
Ivan Berezovskiydfd5ac52019-05-17 16:04:46 +0400121Gerrit client enforcing users, install using pip. If gerrit is configured with LDAP
122it is required to set http_password as ldap user password to properly link ldap entry with gerrit account.
Ales Komarek2fc39002016-09-14 11:43:56 +0200123
124.. code-block:: yaml
125
126 gerrit:
127 client:
Filip Pytloun33d84dd2016-12-20 16:13:24 +0100128 source:
129 engine: pip
Ales Komarek2fc39002016-09-14 11:43:56 +0200130 user:
131 jdoe:
132 fullname: John Doe
133 email: "jdoe@domain.com"
134 ssh_key: ssh-rsa
135 http_password: password
136 groups:
137 - Admin001
138
139
Ales Komarek49a37292016-08-31 16:18:31 +0200140Gerrit client enforcing projects
141
142.. code-block:: yaml
143
144 gerrit:
145 client:
146 enabled: True
Pavel Cizinsky42dba5d2018-12-12 12:01:39 +0100147 server:
Ales Komarek49a37292016-08-31 16:18:31 +0200148 host: 10.10.10.148
149 user: newt
150 key: |
151 -----BEGIN RSA PRIVATE KEY-----
152 MIIEowIBAAKCAQEAs0Y8mxS3dfs5zG8Du5vdBkfOCOng1IEUmFZIirJ8oBgJOd54
153 QgmkDFB7oP9eTCgz9k/rix1uJWhhVCMBzrWzH5IODO+tyy/tK66pv2BWtVfTDhBA
154 ...
155 l1UrxQKBgEklBTuEiDRibKGXQBwlAYvK2He09hWpqtpt9/DVel6s4A1bbTWDHyoP
156 jvMXms60iD/A5OpG33LWHNNzQBP486SxG75LB+Xs5sp5j2/b7VF5LJLhpGiJv9Mk
157 ydbuy8iuuvali2uF133kAlLqnrWfVTYQQI1OfW5glOv1L6kv94dU
158 -----END RSA PRIVATE KEY-----
Ales Komarek50c558e2016-09-05 23:34:43 +0200159 email: "Project Creator <infra@lists.domain.com>"
Ales Komarek49a37292016-08-31 16:18:31 +0200160 project:
161 test_salt_project:
162 enabled: true
163
Ales Komarek50c558e2016-09-05 23:34:43 +0200164Gerrit client enforcing project, full project example
165
166.. code-block:: yaml
167
168 gerrit:
169 client:
170 enabled: True
171 project:
172 test_salt_project:
173 enabled: true
174 access:
Ivan Berezovskiy221add22019-06-24 16:50:17 +0400175 "refs/*":
176 - name: read
177 group: Anonymous Users
178 deny: true
Ales Komarek50c558e2016-09-05 23:34:43 +0200179 "refs/heads/*":
180 actions:
181 - name: abandon
182 group: openstack-salt-core
183 - name: create
184 group: openstack-salt-release
185 labels:
186 - name: Code-Review
187 group: openstack-salt-core
188 score: -2..+2
189 - name: Workflow
190 group: openstack-salt-core
191 score: -1..+1
192 "refs/tags/*":
193 actions:
194 - name: pushSignedTag
195 group: openstack-salt-release
Dmitry Burmistrov9efdff82018-03-21 15:07:05 +0400196 force: true
Alexander Noskov870359d2017-11-02 13:53:15 +0400197 inherit_access: All-Projects
Ales Komarek50c558e2016-09-05 23:34:43 +0200198 require_change_id: true
199 require_agreement: true
200 merge_content: true
Alexander Noskov338d3c72017-09-19 12:10:32 +0400201 action: "fast forward only"
Ales Komarek50c558e2016-09-05 23:34:43 +0200202
Ales Komarek1acb14d2016-09-09 15:14:12 +0200203.. code-block:: yaml
204
205 gerrit:
206 client:
207 enabled: True
208 group:
209 groupname:
210 enabled: true
211 members:
212 - username
213 account:
214 username:
215 enabled: true
Ivan Berezovskiy160305f2019-04-03 16:33:16 +0400216 full_name: User Name
Ales Komarek1acb14d2016-09-09 15:14:12 +0200217 email: mail@newt.cz
218 public_key: rsassh
219 http_password: passwd
220
Jiri Broulik90a79c62018-04-25 20:53:45 +0200221Gerrit client proxy
222
223.. code-block:: yaml
224
225 gerrit:
226 client:
227 proxy:
228 http_proxy: http://192.168.10.15:8000
229 https_proxy: http://192.168.10.15:8000
230 no_proxy: 192.168.10.90
Ales Komarek1acb14d2016-09-09 15:14:12 +0200231
Ales Komarek50c558e2016-09-05 23:34:43 +0200232Sample project access
233
234.. code-block:: yaml
235
236 [access "refs/*"]
237 read = group Administrators
238 read = group Anonymous Users
239 [access "refs/for/refs/*"]
240 push = group Registered Users
241 pushMerge = group Registered Users
242 [access "refs/heads/*"]
243 create = group Administrators
244 create = group Project Owners
245 forgeAuthor = group Registered Users
246 forgeCommitter = group Administrators
247 forgeCommitter = group Project Owners
248 push = group Administrators
249 push = group Project Owners
250 label-Code-Review = -2..+2 group Administrators
251 label-Code-Review = -2..+2 group Project Owners
252 label-Code-Review = -1..+1 group Registered Users
253 label-Verified = -1..+1 group Non-Interactive Users
254 submit = group Administrators
255 submit = group Project Owners
256 editTopicName = +force group Administrators
257 editTopicName = +force group Project Owners
258 [access "refs/meta/config"]
259 exclusiveGroupPermissions = read
260 read = group Administrators
261 read = group Project Owners
262 push = group Administrators
263 push = group Project Owners
264 label-Code-Review = -2..+2 group Administrators
265 label-Code-Review = -2..+2 group Project Owners
266 submit = group Administrators
267 submit = group Project Owners
268 [access "refs/tags/*"]
269 pushTag = group Administrators
270 pushTag = group Project Owners
Dmitry Burmistrov9efdff82018-03-21 15:07:05 +0400271 pushSignedTag = +force group Administrators
Ales Komarek50c558e2016-09-05 23:34:43 +0200272 pushSignedTag = group Project Owners
273 [label "Code-Review"]
274 function = MaxWithBlock
275 copyMinScore = true
276 value = -2 This shall not be merged
277 value = -1 I would prefer this is not merged as is
278 value = 0 No score
279 value = +1 Looks good to me, but someone else must approve
280 value = +2 Looks good to me, approved
281 [label "Verified"]
282 function = MaxWithBlock
283 copyMinScore = true
284 value = -1 Fails
285 value = 0 No score
286 value = +1 Verified
287
Sergey Otpuschennikov42ba1582018-08-20 15:47:09 +0400288Gerrit replication enable
289
290.. code-block:: yaml
291
292 gerrit:
293 server:
294 plugin:
295 replication:
296 engine: gerrit
297 replication:
298 gerrit2.localdomain:
299 remote_url: user@gerrit2.local.domain:/var/lib/gerrit
300 remote_port: 22
301 replication_user: gerrit2
302
303For creating ssh keys use openssh state
304
Sergey Otpuschennikovb3cca132018-10-05 20:24:44 +0400305Gerrit hide CI
306
307.. code-block:: yaml
308
309 gerrit:
310 server:
311 hideci:
312 ci_user_name: ci_user
313
Ales Komarek3446a0a2016-03-08 10:21:00 +0100314Read more
315=========
316
Ales Komarek7f93ce22016-08-29 23:27:47 +0200317* https://www.gerritcodereview.com/
Ales Komarekf93ac812016-08-31 19:37:43 +0200318* https://gerrit-review.googlesource.com/Documentation/
Ales Komarek7f93ce22016-08-29 23:27:47 +0200319* https://github.com/openstack-infra/puppet-gerrit/
320* https://gerrit-ci.gerritforge.com/
Ales Komarek10526762016-09-19 15:21:46 +0200321* https://github.com/morucci/exzuul