universal-data-ingest/.woodpecker.yml

57 lines
1.6 KiB
YAML
Raw Normal View History

2023-12-04 14:22:16 +01:00
steps:
build:
image: plugins/kaniko
settings:
2024-02-07 22:35:15 +01:00
repo: ${FORGE_NAME}/${CI_REPO}
2023-12-04 14:22:16 +01:00
registry:
from_secret: container_registry
tags: latest,${CI_COMMIT_SHA},${CI_COMMIT_TAG}
username:
from_secret: container_registry_username
password:
from_secret: container_registry_password
dockerfile: Dockerfile
when:
- event: [push, tag]
2025-02-03 14:21:41 +01:00
scan:
image: quay.io/wollud1969/woodpecker-helper:0.5.1
environment:
TRIVY_TOKEN:
from_secret: trivy_token
TRIVY_URL:
from_secret: trivy_url
DTRACK_API_KEY:
from_secret: dtrack_api_key
DTRACK_API_URL:
from_secret: dtrack_api_url
commands:
- trivy fs --server $TRIVY_URL --token $TRIVY_TOKEN --format cyclonedx -o /tmp/sbom.xml .
- curl -X "POST" \
-H "Content-Type: multipart/form-data" \
-H "X-Api-Key: $DTRACK_API_KEY" \
-F "autoCreate=true" \
-F "projectName=$CI_REPO" \
-F "projectVersion=$CI_COMMIT_SHA" \
-F "bom=@/tmp/sbom.xml"\
"$DTRACK_API_URL/api/v1/bom"
when:
- event: [push, tag]
2023-12-04 14:22:16 +01:00
deploy:
2025-02-03 14:21:41 +01:00
image: quay.io/wollud1969/woodpecker-helper:0.5.1
environment:
KUBE_CONFIG_CONTENT:
from_secret: kube_config
ENCRYPTION_KEY:
from_secret: encryption_key
MD5_CHECKSUM:
from_secret: secrets_checksum
2023-12-04 14:22:16 +01:00
commands:
2023-12-18 21:35:36 +01:00
- export IMAGE_TAG=$CI_COMMIT_TAG
2023-12-04 14:22:16 +01:00
- printf "$KUBE_CONFIG_CONTENT" > /tmp/kubeconfig
- export KUBECONFIG=/tmp/kubeconfig
2023-12-18 21:35:36 +01:00
- ./deployment/deploy.sh
2023-12-04 14:22:16 +01:00
when:
- event: tag