Skip to content
Snippets Groups Projects
ci_dev.gitlab-ci.yml 1.58 KiB
Newer Older
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
stages:
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  - dev_pulling_repo
  - dev_secrets_in_repo
  - dev_linting_code
  - dev_linting_docker
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  - docker_login
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed

variables:
  GITLAB_API: "https://labs.etsi.org/api/v4"
  CI_JOB_TOKEN: $CI_JOB_TOKEN
  CI_DEBUG_TRACE: "false"
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
.dev_common: &dev_common
  tags:
    - shell

#dev_pulling_repo:
#  stage: dev_pulling_repo
#  script:
#    - git clone https://oauth2:${CI_JOB_TOKEN}@labs.etsi.org/rep/ocf/capif.git
#  <<: *dev_common
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
dev_secrets_in_repo:
  stage: dev_secrets_in_repo
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  script:
    - |
      pip install trufflehog
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
      cd ../
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
      ls -lrta 
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
      # trufflehog capif --exclude_paths cicd/exclusions --max_depth=5
#  needs: ["dev_pulling_repo"]
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  <<: *dev_common
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed

# define the process to do linting code: Sonarque, ruff?
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
dev_linting_code:
  stage: dev_linting_code
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  script:
    - echo "ruff checks"
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  needs: ["dev_secrets_in_repo"]
  <<: *dev_common
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
dev_linting_docker:
  stage: dev_linting_docker
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  image: hadolint/hadolint:latest-debian
  script:
   - find . -name 'capif/services/Dockerfile*' -exec hadolint --no-fail -f gitlab_codeclimate {} + > docker-lint.json
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
   - hadolint services/capif-client/Dockerfile
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
#    - hadolint services/nginx/Dockerfile
#    - hadolint services/register/Dockerfile
  artifacts:
    name: "$CI_JOB_NAME artifacts from $CI_PROJECT_NAME on $CI_COMMIT_REF_SLUG"
    when: always
    reports:
      codequality:
        - docker-lint.json
  interruptible: true    
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed
  needs: ["dev_linting_code"]
  <<: *dev_common
Andres Anaya Amariels's avatar
Andres Anaya Amariels committed

docker_login:
  stage: docker_login
  script:
   - >
    docker --version
    # echo "myusername:mypassword" | docker login --username myusername --password-stdin