QualityGate agent is analyzing Java source code of QualityGate subscribers' systems.
2.8K
Where to get help: QualityGate helpdesk, the Docker Community Forums, the Docker Community Slack or Stack Overflow
Where to file issues: QualityGate helpdesk
Maintained by: FrontEndART Ltd.
Supported architectures: amd64 (Linux/Windows)
QualityGate is software that continuously measures and monitors the quality of the source code of your systems as-well-as the performance of the development team. Source code is analyzed onsite, by our static analyzer tools, without ever getting out of your infrastructure. Only the final results of the analysis (metrics, list of coding issues and duplications, etc.) are uploaded to our servers for having them evaluated against our benchmarks by using sophisticated quality models. You can browse and further analyze the results at any time on our dashboards.
Here you'll find the image of QualityGate agent, which is performing source code analysis onsite and uploading the results to the QualityGate server. No source code is ever uploaded to the server. The machine hosting the image should not be accessible from the outside world, but it is strongly advised. However, the agent to work must be able to reach QualityGate server at https://quality-gate.com/.
First, let's create the directory structure required by QualityGate agent on the host machine. Hereinafter we assume that /opt/QualityGate-agent folder is used as home directory:
$ mkdir -p /opt/QualityGate-agent/{config,workdir}
Make sure that the current user on the host machine can access the Git repository that contains the source code to be analyzed. Hereinafter we assume that the private key for accessing the Git repository is located in the ~/.ssh/id_rsa file.
To run the image, simply execute the following command:
$ docker run --restart always -d --name QualityGate-agent -p 8989:8989 -e QG_API_TOKEN=[your-QualityGate-api-token] -v ~/.ssh:/root/.ssh -v /opt/QualityGate-agent/workdir:/opt/QualityGate-agent-workdir -v /opt/QualityGate-agent/config:/opt/QualityGate-agent-configdir frontendart/qualitygate-agent:latest
For Windows, using WSL 2 backend is recommended for Docker Desktop.
Before starting the image on Linux, you should update the following host configuration:
sysctl -w vm.max_map_count=262144
sysctl -w fs.file-max=65536
The following table summarizes the environment variables that can be set with the -e flag when running the image:
| Variable name | Description | Default value |
|---|---|---|
| QG_API_TOKEN | Required: here you have to provide a valid API token for your QualityGate account. You can find this information under the instructions for setting up private analysis at https://quality-gate.com/account/home/private | - |
| QG_PARALLEL_EXECUTIONS | The maximal number of code analysis executions running in parallel | 2 |
| QG_AGENT_HOST | The advertised DNS name or IP address of the host machine. This needs to be an internal address or name and will be used to fetch the source code when looking at the results of the analysis. The source code will be fetched directly to the browser of the user and will not be proxied through QualityGate server. If no value is provided source code will not be visible on QualityGate dashboards. | https://localhost |
| QG_AGENT_PORT | The port number of the agent machine that will be advertised by the agent. When viewing the source code the browser will attempt to fetch the souce code from QG_AGENT_HOST machine using the QG_AGENT_PORT provided here. | 8989 |
| QG_LOG_LEVEL | The logging level of QualityGate agent. Possible values are: debug, info, warn, error | info |
| QG_AGENT_MEM | The heap memory allocated by QualityGate agent. Example values are "2048M", "1G", etc. | 2048M |
| QG_PKCS_KEYSTORE | The path to the PKCS12 keystore file containing the SSL certificate and private key used for validating the SSL connection when retrieving source files from the browser. Provided that QualityGate operates through https, and source files are retrieved from the agents directly, the browser requires using https connection here as well. The user can provide its own certificate through this variable. If this variable is left empty, the agent will generate a new certificate using the value provided in QG_AGENT_HOST as CN, and will have it signed by the QualityGate server. In this case you should trust the certificate of QualityGate that is used for signing the client keys. In order to do so, please download the certificate from the QualityGate server (https://quality-gate.com/backend/client/ca-cert) and import it into your browser as a Trusted Root CA certificate. | - |
| QG_KEYSTORE_PWD | The password required for accessing keys and certificates in the PKCS12 keystore. It is required only when using your own SSL certificate. | qg-agent |
| QG_KEY_ALIAS | The alias for the QualityGate agent key in the PKCS12 keystore. It is required only when using your own SSL certificate. | qg-agent |
If you would like to use your own SSL certificate, please copy the PKCS12 keystore file containing the certificate key into the /opt/QualityGate-agent/config directory, and provide the proper values for the following environment variables as follows:
QG_PKCS_KEYSTORE=/opt/QualityGate-agent-configdir/[keystore-file-name]
QG_KEYSTORE_PWD=[keystore-password]
QG_KEY_ALIAS=[key-alias]
Otherwise download QualityGate's signer certificate from https://quality-gate.com/backend/client/ca-cert and import it into your browser as a Trusted Root CA certificate.
QualityGate agent uses the following directories:
/opt/QualityGate-agent/workdir/projects - the source code of the analyzed systems, the results of the analysis and the project level log files are stored here. Except for the log files, you should not delete or change the data located here in any way./opt/QualityGate-agent/workdir/logs - the top-level log files are store here. This folder can be emptied from time to time./opt/QualityGate-agent/config - the unique identifier of the agent and the database storing meta-information is located here. Except for copying the keystore containing your SSL keys, you should not change the content of this folder in any way.The agent can be stopped by issuing the following command:
$ docker stop QualityGate-agent
The ongoing analysis will be terminated. When the agent is restarted, the last terminated versions will be analyzed again.
Except for stopping the agent, it can only be managed through the QualityGate account portal.
QualityGate agent is licensed by FrontEndART Ltd. For the terms of use for QualityGate and QualityGate agent, please refer to https://quality-gate.com/webpage/termsOfUse.
As with all Docker images, these likely also contain other software that may be under other licenses (such as Bash, etc from the base distribution, along with any direct or indirect dependencies of the primary software being contained).
As for any pre-built image usage, it is the image user's responsibility to ensure that any use of this image complies with any relevant licenses for all software contained within.
Content type
Image
Digest
sha256:bab6d2512…
Size
1.3 GB
Last updated
over 3 years ago
docker pull frontendart/qualitygate-agent