change Dockerfile, introduce separate build step
Some checks failed
ci/woodpecker/push/woodpecker Pipeline failed

This commit is contained in:
Wolfgang Hottgenroth 2025-02-04 15:01:49 +01:00
parent a2eb38b414
commit c40805b4cb
Signed by: wn
GPG Key ID: 18FDFA577A8871AD
2 changed files with 43 additions and 42 deletions

View File

@ -1,5 +1,46 @@
steps: steps:
build: build:
image: golang:1.22.5-alpine3.20
commands:
- cd src/udi
- go build -a -installsuffix nocgo -o udi main.go
- cp udi ../..
scan:
image: quay.io/wollud1969/woodpecker-helper:0.5.1
environment:
TRIVY_TOKEN:
from_secret: trivy_token
TRIVY_URL:
from_secret: trivy_url
DTRACK_API_KEY:
from_secret: dtrack_api_key
DTRACK_API_URL:
from_secret: dtrack_api_url
commands:
- HOME=/home/`id -nu`
- |
trivy fs \
--server $TRIVY_URL \
--token $TRIVY_TOKEN \
--format cyclonedx \
--scanners license \
--output sbom.xml \
.
- cat /tmp/sbom.xml
- |
curl -X "POST" \
-H "Content-Type: multipart/form-data" \
-H "X-Api-Key: $DTRACK_API_KEY" \
-F "autoCreate=true" \
-F "projectName=$CI_REPO" \
-F "projectVersion=$CI_COMMIT_SHA" \
-F "bom=@sbom.xml"\
"$DTRACK_API_URL/api/v1/bom"
when:
- event: [push, tag]
dockerize:
image: plugins/kaniko image: plugins/kaniko
settings: settings:
repo: ${FORGE_NAME}/${CI_REPO} repo: ${FORGE_NAME}/${CI_REPO}
@ -14,39 +55,6 @@ steps:
when: when:
- event: [push, tag] - event: [push, tag]
generate_sbom:
image: aquasec/trivy:latest
environment:
TRIVY_TOKEN:
from_secret: trivy_token
TRIVY_URL:
from_secret: trivy_url
commands:
- trivy fs --server $TRIVY_URL --token $TRIVY_TOKEN --format cyclonedx --scanners license --output /woodpecker/sbom.xml .
when:
- event: [push, tag]
upload_sbom:
image: quay.io/wollud1969/woodpecker-helper:0.5.1
environment:
DTRACK_API_KEY:
from_secret: dtrack_api_key
DTRACK_API_URL:
from_secret: dtrack_api_url
commands:
- cat /woodpecker/sbom.xml
- |
curl -X "POST" \
-H "Content-Type: multipart/form-data" \
-H "X-Api-Key: $DTRACK_API_KEY" \
-F "autoCreate=true" \
-F "projectName=$CI_REPO" \
-F "projectVersion=$CI_COMMIT_SHA" \
-F "bom=@/woodpecker/sbom.xml"\
"$DTRACK_API_URL/api/v1/bom"
when:
- event: [push, tag]
deploy: deploy:
image: quay.io/wollud1969/woodpecker-helper:0.5.1 image: quay.io/wollud1969/woodpecker-helper:0.5.1
environment: environment:

View File

@ -1,15 +1,8 @@
FROM golang:1.22.5-alpine3.20 as builder
RUN mkdir -p /go/src
COPY ./src/ /go/src
WORKDIR /go/src/udi
RUN go build -a -installsuffix nocgo -o udi main.go
FROM scratch FROM scratch
ENV UDI_CONF "" ENV UDI_CONF ""
COPY --from=builder /go/src/udi ./ COPY udi ./
ENTRYPOINT ["./udi"] ENTRYPOINT ["./udi"]