Sign inSign up

frontendart/qualitygate-agent

By frontendart

•Updated over 3 years ago

QualityGate agent is analyzing Java source code of QualityGate subscribers' systems.

Image
0

2.8K

frontendart/qualitygate-agent repository overview

⁠Quick reference

⁠What is QualityGate?

QualityGate is software that continuously measures and monitors the quality of the source code of your systems as-well-as the performance of the development team. Source code is analyzed onsite, by our static analyzer tools, without ever getting out of your infrastructure. Only the final results of the analysis (metrics, list of coding issues and duplications, etc.) are uploaded to our servers for having them evaluated against our benchmarks by using sophisticated quality models. You can browse and further analyze the results at any time on our dashboards.

⁠How to use this image

Here you'll find the image of QualityGate agent, which is performing source code analysis onsite and uploading the results to the QualityGate server. No source code is ever uploaded to the server. The machine hosting the image should not be accessible from the outside world, but it is strongly advised. However, the agent to work must be able to reach QualityGate server at https://quality-gate.com/⁠.

⁠Running the image

First, let's create the directory structure required by QualityGate agent on the host machine. Hereinafter we assume that /opt/QualityGate-agent folder is used as home directory:

$ mkdir -p /opt/QualityGate-agent/{config,workdir}

Make sure that the current user on the host machine can access the Git repository that contains the source code to be analyzed. Hereinafter we assume that the private key for accessing the Git repository is located in the ~/.ssh/id_rsa file.

To run the image, simply execute the following command:

$ docker run --restart always -d --name QualityGate-agent -p 8989:8989 -e QG_API_TOKEN=[your-QualityGate-api-token] -v ~/.ssh:/root/.ssh -v /opt/QualityGate-agent/workdir:/opt/QualityGate-agent-workdir -v /opt/QualityGate-agent/config:/opt/QualityGate-agent-configdir frontendart/qualitygate-agent:latest

For Windows, using WSL 2 backend⁠ is recommended for Docker Desktop.

⁠Configuration

Before starting the image on Linux, you should update the following host configuration:

sysctl -w vm.max_map_count=262144
sysctl -w fs.file-max=65536

The following table summarizes the environment variables that can be set with the -e flag when running the image:

Variable nameDescriptionDefault value
QG_API_TOKENRequired: here you have to provide a valid API token for your QualityGate account. You can find this information under the instructions for setting up private analysis at https://quality-gate.com/account/home/private⁠-
QG_PARALLEL_EXECUTIONSThe maximal number of code analysis executions running in parallel2
QG_AGENT_HOSTThe advertised DNS name or IP address of the host machine. This needs to be an internal address or name and will be used to fetch the source code when looking at the results of the analysis. The source code will be fetched directly to the browser of the user and will not be proxied through QualityGate server. If no value is provided source code will not be visible on QualityGate dashboards.https://localhost⁠
QG_AGENT_PORTThe port number of the agent machine that will be advertised by the agent. When viewing the source code the browser will attempt to fetch the souce code from QG_AGENT_HOST machine using the QG_AGENT_PORT provided here.8989
QG_LOG_LEVELThe logging level of QualityGate agent. Possible values are: debug, info, warn, errorinfo
QG_AGENT_MEMThe heap memory allocated by QualityGate agent. Example values are "2048M", "1G", etc.2048M
QG_PKCS_KEYSTOREThe path to the PKCS12 keystore file containing the SSL certificate and private key used for validating the SSL connection when retrieving source files from the browser. Provided that QualityGate operates through https, and source files are retrieved from the agents directly, the browser requires using https connection here as well. The user can provide its own certificate through this variable. If this variable is left empty, the agent will generate a new certificate using the value provided in QG_AGENT_HOST as CN, and will have it signed by the QualityGate server. In this case you should trust the certificate of QualityGate that is used for signing the client keys. In order to do so, please download the certificate from the QualityGate server (https://quality-gate.com/backend/client/ca-cert⁠) and import it into your browser as a Trusted Root CA certificate.-
QG_KEYSTORE_PWDThe password required for accessing keys and certificates in the PKCS12 keystore. It is required only when using your own SSL certificate.qg-agent
QG_KEY_ALIASThe alias for the QualityGate agent key in the PKCS12 keystore. It is required only when using your own SSL certificate.qg-agent

If you would like to use your own SSL certificate, please copy the PKCS12 keystore file containing the certificate key into the /opt/QualityGate-agent/config directory, and provide the proper values for the following environment variables as follows:

QG_PKCS_KEYSTORE=/opt/QualityGate-agent-configdir/[keystore-file-name]
QG_KEYSTORE_PWD=[keystore-password]
QG_KEY_ALIAS=[key-alias]

Otherwise download QualityGate's signer certificate from https://quality-gate.com/backend/client/ca-cert⁠ and import it into your browser as a Trusted Root CA certificate.

⁠Files and directories

QualityGate agent uses the following directories:

  • /opt/QualityGate-agent/workdir/projects - the source code of the analyzed systems, the results of the analysis and the project level log files are stored here. Except for the log files, you should not delete or change the data located here in any way.
  • /opt/QualityGate-agent/workdir/logs - the top-level log files are store here. This folder can be emptied from time to time.
  • /opt/QualityGate-agent/config - the unique identifier of the agent and the database storing meta-information is located here. Except for copying the keystore containing your SSL keys, you should not change the content of this folder in any way.

⁠Managing the agent

The agent can be stopped by issuing the following command:

$ docker stop QualityGate-agent

The ongoing analysis will be terminated. When the agent is restarted, the last terminated versions will be analyzed again.

Except for stopping the agent, it can only be managed through the QualityGate account portal⁠.

⁠License

QualityGate agent is licensed by FrontEndART Ltd⁠. For the terms of use for QualityGate⁠ and QualityGate agent, please refer to https://quality-gate.com/webpage/termsOfUse⁠.

As with all Docker images, these likely also contain other software that may be under other licenses (such as Bash, etc from the base distribution, along with any direct or indirect dependencies of the primary software being contained).

As for any pre-built image usage, it is the image user's responsibility to ensure that any use of this image complies with any relevant licenses for all software contained within.

Tag summary

Content type

Image

Digest

sha256:bab6d2512…

Size

1.3 GB

Last updated

over 3 years ago

docker pull frontendart/qualitygate-agent