Uploads new Gradle versions to an S3 bucket
Project description
Gradle Uploader
This CDK construct checks for new releases of the Gradle build software.
The new release will be made available as copy in an S3 bucket. An information about the new release can be sent via e-mail or via Slack.
Internally the construct uses
-
an S3 bucket for storing the Gradle software
-
a Lambda function and one Lambda layer to
- check for the latest Gradle release
- upload if required and notify users via SNS and e-Mail or alternatively Slack
-
a Cloudwatch event rule to trigger the Lambda function
Setup of the components
The S3 Bucket
By default, public access to the S3 bucket is disabled. Only the access from a specific IP address (the one I got from my ISP) is allowed and ensured via bucket policies.
const bucket = new Bucket(this, "bucket", {
blockPublicAccess: BlockPublicAccess.BLOCK_ALL,
encryption: BucketEncryption.S3_MANAGED,
publicReadAccess: false,
versioned: false,
removalPolicy: RemovalPolicy.DESTROY,
});
const bucketContentStatement = new PolicyStatement({
effect: Effect.ALLOW,
actions: ["s3:GetObject"],
resources: [bucket.bucketArn + "/*"],
principals: [new AnyPrincipal()],
});
bucketContentStatement.addCondition("IpAddress", {
"aws:SourceIp": "87.122.220.125/32",
});
const bucketStatement: PolicyStatement = new PolicyStatement({
effect: Effect.ALLOW,
actions: ["s3:ListBucket", "s3:GetBucketLocation"],
resources: [bucket.bucketArn],
principals: [new AnyPrincipal()],
});
bucketStatement.addCondition("IpAddress", {
"aws:SourceIp": "87.122.220.125/32",
});
const bucketPolicy = new BucketPolicy(this, "bucketPolicy", {
bucket: bucket,
});
The Lambda function
The Lambda function is written in Python (version 3.8). The execution time is limited to five minutes and the memory consumption to 512 MByte. Additionally the function gets read/ write access to the S3 bucket and has a log retention period is set to one week.
const fn = new Function(this, "fnUpload", {
runtime: Runtime.PYTHON_3_8,
description: "Download Gradle distribution to S3 bucket",
handler: "gradleUploader.main",
code: Code.fromAsset("./lambda/"),
timeout: Duration.minutes(5),
memorySize: 512,
logRetention: RetentionDays.ONE_WEEK,
layers: [layer],
environment: {
BUCKET_NAME: bucket.bucketName,
TOPIC_ARN: topic.topicArn,
},
});
bucket.grantReadWrite(fn);
If Slack is selected as notification channel, then also the WEBHOOK_URL
is part of the environment
.
In the additional layer modules like boto3 are included.
const layer = new LayerVersion(this, "GradleUploaderLayer", {
code: Code.fromAsset(path.join(__dirname, "../layer-code")),
compatibleRuntimes: [Runtime.PYTHON_3_8],
license: "Apache-2.0",
description: "A layer containing dependencies for thr Gradle Uploader",
});
The Cloudwatch event rule
Every first of a month the Lambda function fn
will be triggered automatically. That seems to be a reasonable period for the update check.
const target = new LambdaFunction(fn);
new Rule(this, "ScheduleRule", {
schedule: Schedule.cron({ minute: "0", hour: "0", day: "1", month: "*" }),
targets: [target],
});
Notifying about new releases
Whenever the release of a new Gradle version is detected, the stack will sent an e-mail to the list of subscriber using SNS.
private addSubscribers(topic: Topic, subscribers:Array<string>) {
for (var subscriber of subscribers) {
topic.addSubscription(new EmailSubscription(subscriber));
}
}
The forwarding of information to a Slack channel is done from within the Lambda function.
Testing the Python code
docker run --rm -v "$PWD":/var/task:ro,delegated -v /home/stefan/Private/programmieren/aws/cdk/gradle_uploader/layer-code:/opt:ro,delegated -e AWS_ACCESS_KEY_ID=XXXXXXXXXX -e AWS_SECRET_ACCESS_KEY=XXXXXXXXXX lambci/lambda:python3.8 gradleUploader.main
How to use the construct in a stack
Here is an example how to use the construct:
export class GradleUploaderStack extends Stack {
constructor(scope: Construct, id: string) {
super(scope, id);
new GradleUploader(this, 'TestStack', {
mailProperties: { subscribers: ['<e-mail address>'] },
slackProperties: {
webhook:
'https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX',
},
whitelist: ['CIDR_1', 'CIDR_2'],
});
}
}
const app = new App();
new GradleUploaderStack(app, 'TestApp');
app.synth();
Links
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file cdk_gradle_uploader-0.0.30.tar.gz
.
File metadata
- Download URL: cdk_gradle_uploader-0.0.30.tar.gz
- Upload date:
- Size: 119.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.12.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | ce6208a7bda61695c0998b4a93bb14c09658163324eb13c85100dbff93098ae3 |
|
MD5 | 9141a42d603bbe61e464c2a1495cc153 |
|
BLAKE2b-256 | 89c50ea0600d427b1a397bdc3bf65b44d86445d5a64e9a69bef11d0911b45e5b |
File details
Details for the file cdk_gradle_uploader-0.0.30-py3-none-any.whl
.
File metadata
- Download URL: cdk_gradle_uploader-0.0.30-py3-none-any.whl
- Upload date:
- Size: 118.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.12.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 8ba529b7405776e71e388ae4f37ec95f5acb7b8ee529a6625e9c65b2e702ec84 |
|
MD5 | 6b4265b743cfd52f53642d639332b4ce |
|
BLAKE2b-256 | 39ac74539c028cef55adbdcb6a56434aff196e290290bb0335eab6a3510bc652 |