sbom in ci
This commit is contained in:
parent
d4ee4c49de
commit
77c5df0697
@ -14,15 +14,39 @@ steps:
|
|||||||
when:
|
when:
|
||||||
- event: [push, tag]
|
- event: [push, tag]
|
||||||
|
|
||||||
|
scan:
|
||||||
|
image: quay.io/wollud1969/woodpecker-helper:0.5.1
|
||||||
|
environment:
|
||||||
|
TRIVY_TOKEN:
|
||||||
|
from_secret: trivy_token
|
||||||
|
TRIVY_URL:
|
||||||
|
from_secret: trivy_url
|
||||||
|
DTRACK_API_KEY:
|
||||||
|
from_secret: dtrack_api_key
|
||||||
|
DTRACK_API_URL:
|
||||||
|
from_secret: dtrack_api_url
|
||||||
|
commands:
|
||||||
|
- trivy fs --server $TRIVY_URL --token $TRIVY_TOKEN --format cyclonedx -o /tmp/sbom.xml .
|
||||||
|
- curl -X "POST" \
|
||||||
|
-H "Content-Type: multipart/form-data" \
|
||||||
|
-H "X-Api-Key: $DTRACK_API_KEY" \
|
||||||
|
-F "autoCreate=true" \
|
||||||
|
-F "projectName=$CI_REPO" \
|
||||||
|
-F "projectVersion=$CI_COMMIT_SHA" \
|
||||||
|
-F "bom=@/tmp/sbom.xml"\
|
||||||
|
"$DTRACK_API_URL/api/v1/bom"
|
||||||
|
when:
|
||||||
|
- event: [push, tag]
|
||||||
|
|
||||||
deploy:
|
deploy:
|
||||||
image: portainer/kubectl-shell:latest
|
image: quay.io/wollud1969/woodpecker-helper:0.5.1
|
||||||
secrets:
|
environment:
|
||||||
- source: kube_config
|
KUBE_CONFIG_CONTENT:
|
||||||
target: KUBE_CONFIG_CONTENT
|
from_secret: kube_config
|
||||||
- source: encryption_key
|
ENCRYPTION_KEY:
|
||||||
target: ENCRYPTION_KEY
|
from_secret: encryption_key
|
||||||
- source: secrets_checksum
|
MD5_CHECKSUM:
|
||||||
target: MD5_CHECKSUM
|
from_secret: secrets_checksum
|
||||||
commands:
|
commands:
|
||||||
- export IMAGE_TAG=$CI_COMMIT_TAG
|
- export IMAGE_TAG=$CI_COMMIT_TAG
|
||||||
- printf "$KUBE_CONFIG_CONTENT" > /tmp/kubeconfig
|
- printf "$KUBE_CONFIG_CONTENT" > /tmp/kubeconfig
|
||||||
|
@ -41,3 +41,4 @@ create or replace view cubecell_threeway_battery_v as
|
|||||||
from measurements
|
from measurements
|
||||||
where application = 'de-hottis-saerbeck-monitoring' and
|
where application = 'de-hottis-saerbeck-monitoring' and
|
||||||
device = 'eui-70b3d57ed0068fa4';
|
device = 'eui-70b3d57ed0068fa4';
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user