SonarQube: mobile apps (spikersoft-ios / spikersoft-android) are never scanned #990

Closed
opened 2026-08-06 22:12:59 +00:00 by spikerj · 2 comments
Owner

The mobile repos don't appear in SonarQube because they were never wired into the scan infrastructure — no sonar-scan.yml workflow, no sonar-project.properties, no OpenBao CI AppRoles (provision-ci-approles.sh only covers backend/artpipe/angular/infrastructure), and no BAO_ROLE_ID/BAO_SECRET_ID Actions secrets on either repo.

Fix (three PRs):

  • spikersoft-infrastructure: ci-ios.hcl + ci-android.hcl policies, extend provision-ci-approles.sh with ios android, new provision-mobile-sonar-secrets.sh writing secret/ci/{ios,android}/sonar (token only — host stays pinned in workflows per the #632 lesson).
  • spikersoft-android: sonar-scan.yml (main-push + dispatch, no PR trigger per #632 rationale) + sonar-project.properties (projectKey spikersoft-android, Kotlin sources/tests split, non-blocking gate).
  • spikersoft-ios: same shape (projectKey spikersoft-ios, games.pck/audio excluded).

Runbook after merge (Joey):

  1. bash openbao/provision-ci-approles.sh → set BAO_ROLE_ID/BAO_SECRET_ID Actions secrets on BOTH mobile repos from its output.
  2. Mint a SonarQube Global Analysis Token (My Account → Security) and run bash openbao/provision-mobile-sonar-secrets.sh.
  3. Push to main (or workflow_dispatch) on each repo → projects appear.

⚠️ Swift caveat: official Swift analysis requires a commercial edition (Developer+). The stack image is tagged sonar-scanner-datacenter:2026.2.0, but the backend workflow (2026-07) observed Community-Edition behavior ("no branch/PR analysis") — check Administration → System for the actual edition. On CE the iOS project will appear but .swift files are skipped (only secrets/text/JSON rules run); options then are the community sonar-apple plugin (server-side install) or a commercial license. Kotlin/Android is fully supported on every edition.

The mobile repos don't appear in SonarQube because they were never wired into the scan infrastructure — no `sonar-scan.yml` workflow, no `sonar-project.properties`, no OpenBao CI AppRoles (`provision-ci-approles.sh` only covers backend/artpipe/angular/infrastructure), and no `BAO_ROLE_ID`/`BAO_SECRET_ID` Actions secrets on either repo. Fix (three PRs): - **spikersoft-infrastructure**: `ci-ios.hcl` + `ci-android.hcl` policies, extend `provision-ci-approles.sh` with `ios android`, new `provision-mobile-sonar-secrets.sh` writing `secret/ci/{ios,android}/sonar` (token only — host stays pinned in workflows per the #632 lesson). - **spikersoft-android**: `sonar-scan.yml` (main-push + dispatch, no PR trigger per #632 rationale) + `sonar-project.properties` (projectKey `spikersoft-android`, Kotlin sources/tests split, non-blocking gate). - **spikersoft-ios**: same shape (projectKey `spikersoft-ios`, games.pck/audio excluded). **Runbook after merge (Joey):** 1. `bash openbao/provision-ci-approles.sh` → set `BAO_ROLE_ID`/`BAO_SECRET_ID` Actions secrets on BOTH mobile repos from its output. 2. Mint a SonarQube **Global Analysis Token** (My Account → Security) and run `bash openbao/provision-mobile-sonar-secrets.sh`. 3. Push to main (or workflow_dispatch) on each repo → projects appear. **⚠️ Swift caveat**: official Swift analysis requires a commercial edition (Developer+). The stack image is tagged `sonar-scanner-datacenter:2026.2.0`, but the backend workflow (2026-07) observed Community-Edition behavior ("no branch/PR analysis") — check Administration → System for the actual edition. On CE the iOS project will appear but `.swift` files are skipped (only secrets/text/JSON rules run); options then are the community `sonar-apple` plugin (server-side install) or a commercial license. Kotlin/Android is fully supported on every edition.
Author
Owner

Edition question resolved: the server is Enterprise Edition (Joey, 2026-08-06). So:

  • The Swift caveat is moot — the official Swift analyzer will fully analyze spikersoft-ios out of the box. iOS PR #9 updated to drop the Community-Edition note.
  • The backend sonar-scan.yml comment claiming "Community Edition (no branch/PR analysis)" is wrong — worth knowing that the whole fleet-wide "no PR trigger" stance (here and in #632's aftermath) was built on that belief. Enterprise supports branch + PR analysis, so PR-event scans would create proper separate PR analyses instead of clobbering the main baseline. Filed as a separate enhancement: #991.

Remaining before the mobile projects appear: merge the three PRs (infra #161, android #7, ios #9) and run the provisioning runbook in #161's description.

Edition question resolved: the server is **Enterprise Edition** (Joey, 2026-08-06). So: - The Swift caveat is moot — the official Swift analyzer will fully analyze `spikersoft-ios` out of the box. iOS PR #9 updated to drop the Community-Edition note. - The backend `sonar-scan.yml` comment claiming "Community Edition (no branch/PR analysis)" is **wrong** — worth knowing that the whole fleet-wide "no PR trigger" stance (here and in #632's aftermath) was built on that belief. Enterprise supports branch + PR analysis, so PR-event scans would create proper separate PR analyses instead of clobbering the main baseline. Filed as a separate enhancement: #991. Remaining before the mobile projects appear: merge the three PRs (infra #161, android #7, ios #9) and run the provisioning runbook in #161's description.
Author
Owner

Verified complete 2026-08-07 — closing. All three PRs merged and the post-merge runbook was run: both mobile projects now exist in SonarQube with fresh analyses.

  • Code:
    • spikersoft-infrastructure@fa8a4af (PR #161) — ci-ios.hcl / ci-android.hcl, provision-ci-approles.sh extended, provision-mobile-sonar-secrets.sh.
    • spikersoft-android@caf3ddc (PR #7) — sonar-scan.yml + sonar-project.properties.
    • spikersoft-ios@72b8218 (PR #9) — same shape.
    • Follow-through since: Sonar findings cleanups (android PR #8, ios PR #10) and PR-event analysis on the Enterprise server (android PR #9, ios PR #11, per #991).
  • Live: GET https://sonarqube.spikersoft.com/api/projects/search →
    api.spikersoft.com     2026-08-07T11:09:34+0000
    learn.spikersoft.com   2026-08-07T11:55:15+0000
    spikersoft-android     2026-08-07T13:40:44+0000
    spikersoft-ios         2026-08-07T13:36:09+0000
    
    Both mobile projects exist and were analyzed today, which means the AppRoles, the BAO_ROLE_ID/BAO_SECRET_ID Actions secrets and the Sonar global analysis token were all provisioned — runbook steps 1–3 are done.
  • Swift caveat resolved: the server is Enterprise Edition (see the 2026-08-06 comment above), so .swift files are fully analyzed; the PR-analysis consequence was split out as #991.

Not migrated: nothing left to do.

— Opus 5 Agent

Verified complete 2026-08-07 — closing. All three PRs merged **and** the post-merge runbook was run: both mobile projects now exist in SonarQube with fresh analyses. - **Code:** - `spikersoft-infrastructure@fa8a4af` (PR #161) — `ci-ios.hcl` / `ci-android.hcl`, `provision-ci-approles.sh` extended, `provision-mobile-sonar-secrets.sh`. - `spikersoft-android@caf3ddc` (PR #7) — `sonar-scan.yml` + `sonar-project.properties`. - `spikersoft-ios@72b8218` (PR #9) — same shape. - Follow-through since: Sonar findings cleanups (android PR #8, ios PR #10) and PR-event analysis on the Enterprise server (android PR #9, ios PR #11, per #991). - **Live:** `GET https://sonarqube.spikersoft.com/api/projects/search` → ``` api.spikersoft.com 2026-08-07T11:09:34+0000 learn.spikersoft.com 2026-08-07T11:55:15+0000 spikersoft-android 2026-08-07T13:40:44+0000 spikersoft-ios 2026-08-07T13:36:09+0000 ``` Both mobile projects exist and were analyzed **today**, which means the AppRoles, the `BAO_ROLE_ID`/`BAO_SECRET_ID` Actions secrets and the Sonar global analysis token were all provisioned — runbook steps 1–3 are done. - **Swift caveat resolved:** the server is Enterprise Edition (see the 2026-08-06 comment above), so `.swift` files are fully analyzed; the PR-analysis consequence was split out as #991. Not migrated: nothing left to do. — Opus 5 Agent
Sign in to join this conversation.