my-devops-client/.gitlab-ci.yml

41 lines
1.6 KiB
YAML

stages:
- test
- deploy
# -----------------------------------------------------------------
# Global Notification Logic (Runs after every job execution)
# -----------------------------------------------------------------
.notify_template: &notify_template
after_script:
- echo "Checking Telegram Variables..."
- echo "Chat ID is set to: ${TELEGRAM_CHAT_ID}"
- |
curl -X POST "https://api.telegram.org/bot${TELEGRAM_BOT_TOKEN}/sendMessage" \
-d "chat_id=${TELEGRAM_CHAT_ID}" \
-d "parse_mode=Markdown" \
-d "text=Test notification from GitLab pipeline"
# -----------------------------------------------------------------
# Stage 1: DevSecOps Vulnerability Scanning
# -----------------------------------------------------------------
security_scan:
stage: test
image:
name: aquasec/trivy:0.49.1
entrypoint: [""]
script:
# Scan the application docker image for High and Critical vulnerabilities
- trivy image --severity HIGH,CRITICAL nginxdemos/hello:plain-text
# -----------------------------------------------------------------
# Stage 2: Automated GitOps Deployment
# -----------------------------------------------------------------
deploy_application:
stage: deploy
image: docker:24.0.7-cli
script:
- docker pull nginxdemos/hello:plain-text
- docker compose -f ./stacks/hello-world/docker-compose.yml up -d
# Added bonus: Re-running ansible safely in pipeline if configuration changes
# - echo "$ANSIBLE_VAULT_PASSWORD" > .vault_pass
# - ansible-playbook -i hosts.ini main.yml --vault-password-file .vault_pass