nikola-docker/.drone.yml
Elia el Lazkani 413f3d6b86
All checks were successful
continuous-integration/drone/push Build is passing
chore(): Custom pipeline
The image is to be used in the pipeline only
to generate a static website. We accept the
risk of criticals in the image but we scan it anyway.
2023-07-06 00:25:36 +02:00

92 lines
1.8 KiB
YAML

---
kind: pipeline
name: container-check
steps:
- name: check-container
image: plugins/docker
settings:
registry: scm.project42.io
dockerfile: Dockerfile
username:
from_secret: registry_username
password:
from_secret: registry_password
repo: scm.project42.io/elia/nikola
dry_run: true
squash: true
tags:
- "${DRONE_COMMIT_SHA:0:8}"
- name: build-container
image: plugins/docker
settings:
registry: scm.project42.io
dockerfile: Dockerfile
username:
from_secret: registry_username
password:
from_secret: registry_password
repo: scm.project42.io/elia/nikola
dry_run: false
squash: true
tags:
- "${DRONE_COMMIT_SHA:0:8}"
depends_on:
- check-container
when:
event:
exclude:
- promote
- name: trivy-scan
image: scm.project42.io/elia/tricks:latest
environment:
REGISTRY_USERNAME:
from_secret: registry_username
REGISTRY_PASSWORD:
from_secret: registry_password
commands:
- trivy image --image-src remote --exit-code 0 "scm.project42.io/elia/nikola:${DRONE_COMMIT_SHA:0:8}"
depends_on:
- build-container
when:
event:
exclude:
- promote
trigger:
exclude:
event:
- promote
---
kind: pipeline
name: promote-to-production
steps:
- name: promote-container
image: scm.project42.io/elia/tricks:latest
environment:
REGISTRY_USERNAME:
from_secret: registry_username
REGISTRY_PASSWORD:
from_secret: registry_password
commands:
- oras tag --username "$REGISTRY_USERNAME" --password "$REGISTRY_PASSWORD" "scm.project42.io/elia/nikola:${DRONE_COMMIT_SHA:0:8}" latest
depends_on:
- trivy-scan
when:
event:
- promote
target:
- production
depends_on:
- container-check
trigger:
event:
- promote
target:
- production