stages: - test - deploy # ----------------------------------------------------------------- # Global Notification Logic (Runs after every job execution) # ----------------------------------------------------------------- .notify_template: ¬ify_template after_script: - echo "Checking Telegram Variables..." - echo "Chat ID is set to: ${TELEGRAM_CHAT_ID}" - | curl -X POST "https://api.telegram.org/bot${TELEGRAM_BOT_TOKEN}/sendMessage" \ -d "chat_id=${TELEGRAM_CHAT_ID}" \ -d "parse_mode=Markdown" \ -d "text=Test notification from GitLab pipeline" # ----------------------------------------------------------------- # Stage 1: DevSecOps Vulnerability Scanning # ----------------------------------------------------------------- security_scan: stage: test image: name: aquasec/trivy:0.49.1 entrypoint: [""] script: # Scan the application docker image for High and Critical vulnerabilities - trivy image --severity HIGH,CRITICAL nginxdemos/hello:plain-text # ----------------------------------------------------------------- # Stage 2: Automated GitOps Deployment # ----------------------------------------------------------------- deploy_application: stage: deploy image: docker:24.0.7-cli script: - docker pull nginxdemos/hello:plain-text - docker compose -f ./stacks/hello-world/docker-compose.yml up -d # Added bonus: Re-running ansible safely in pipeline if configuration changes # - echo "$ANSIBLE_VAULT_PASSWORD" > .vault_pass # - ansible-playbook -i hosts.ini main.yml --vault-password-file .vault_pass