stages: - test - deploy # ----------------------------------------------------------------- # Stage 1: DevSecOps Vulnerability Scanning # ----------------------------------------------------------------- security_scan: stage: test image: name: aquasec/trivy:0.49.1 entrypoint: [""] script: # Scan the application docker image for High and Critical vulnerabilities - trivy image --severity HIGH,CRITICAL nginxdemos/hello:plain-text # ----------------------------------------------------------------- # Stage 2: Automated GitOps Deployment # ----------------------------------------------------------------- deploy_application: stage: deploy image: docker:24.0.7-cli script: - docker pull nginxdemos/hello:plain-text - docker compose -f ./stacks/hello-world/docker-compose.yml up -d # Added bonus: Re-running ansible safely in pipeline if configuration changes # - echo "$ANSIBLE_VAULT_PASSWORD" > .vault_pass # - ansible-playbook -i hosts.ini main.yml --vault-password-file .vault_pass