2023-12-04 14:22:16 +01:00
|
|
|
steps:
|
|
|
|
build:
|
|
|
|
image: plugins/kaniko
|
|
|
|
settings:
|
2024-02-07 22:35:15 +01:00
|
|
|
repo: ${FORGE_NAME}/${CI_REPO}
|
2023-12-04 14:22:16 +01:00
|
|
|
registry:
|
|
|
|
from_secret: container_registry
|
|
|
|
tags: latest,${CI_COMMIT_SHA},${CI_COMMIT_TAG}
|
|
|
|
username:
|
|
|
|
from_secret: container_registry_username
|
|
|
|
password:
|
|
|
|
from_secret: container_registry_password
|
|
|
|
dockerfile: Dockerfile
|
|
|
|
when:
|
|
|
|
- event: [push, tag]
|
|
|
|
|
2025-02-03 17:14:11 +01:00
|
|
|
generate_sbom:
|
|
|
|
image: aquasec/trivy:latest
|
2025-02-03 14:21:41 +01:00
|
|
|
environment:
|
|
|
|
TRIVY_TOKEN:
|
|
|
|
from_secret: trivy_token
|
|
|
|
TRIVY_URL:
|
|
|
|
from_secret: trivy_url
|
2025-02-03 17:18:44 +01:00
|
|
|
commands:
|
2025-02-03 17:27:19 +01:00
|
|
|
- trivy fs --server $TRIVY_URL --token $TRIVY_TOKEN --format cyclonedx --scanners license --output /woodpecker/sbom.xml .
|
2025-02-03 17:14:11 +01:00
|
|
|
when:
|
|
|
|
- event: [push, tag]
|
|
|
|
|
|
|
|
upload_sbom:
|
|
|
|
image: quay.io/wollud1969/woodpecker-helper:0.5.1
|
|
|
|
environment:
|
2025-02-03 14:21:41 +01:00
|
|
|
DTRACK_API_KEY:
|
|
|
|
from_secret: dtrack_api_key
|
|
|
|
DTRACK_API_URL:
|
|
|
|
from_secret: dtrack_api_url
|
|
|
|
commands:
|
2025-02-03 17:30:05 +01:00
|
|
|
- cat /woodpecker/sbom.xml
|
2025-02-03 14:23:45 +01:00
|
|
|
- |
|
|
|
|
curl -X "POST" \
|
2025-02-03 14:21:41 +01:00
|
|
|
-H "Content-Type: multipart/form-data" \
|
|
|
|
-H "X-Api-Key: $DTRACK_API_KEY" \
|
|
|
|
-F "autoCreate=true" \
|
|
|
|
-F "projectName=$CI_REPO" \
|
|
|
|
-F "projectVersion=$CI_COMMIT_SHA" \
|
2025-02-03 17:27:19 +01:00
|
|
|
-F "bom=@/woodpecker/sbom.xml"\
|
2025-02-03 14:21:41 +01:00
|
|
|
"$DTRACK_API_URL/api/v1/bom"
|
|
|
|
when:
|
|
|
|
- event: [push, tag]
|
|
|
|
|
2023-12-04 14:22:16 +01:00
|
|
|
deploy:
|
2025-02-03 14:21:41 +01:00
|
|
|
image: quay.io/wollud1969/woodpecker-helper:0.5.1
|
|
|
|
environment:
|
|
|
|
KUBE_CONFIG_CONTENT:
|
|
|
|
from_secret: kube_config
|
|
|
|
ENCRYPTION_KEY:
|
|
|
|
from_secret: encryption_key
|
|
|
|
MD5_CHECKSUM:
|
|
|
|
from_secret: secrets_checksum
|
2023-12-04 14:22:16 +01:00
|
|
|
commands:
|
2023-12-18 21:35:36 +01:00
|
|
|
- export IMAGE_TAG=$CI_COMMIT_TAG
|
2023-12-04 14:22:16 +01:00
|
|
|
- printf "$KUBE_CONFIG_CONTENT" > /tmp/kubeconfig
|
|
|
|
- export KUBECONFIG=/tmp/kubeconfig
|
2023-12-18 21:35:36 +01:00
|
|
|
- ./deployment/deploy.sh
|
2023-12-04 14:22:16 +01:00
|
|
|
when:
|
|
|
|
- event: tag
|