91 lines
4.3 KiB
YAML
91 lines
4.3 KiB
YAML
# Auto DevOps
|
|
# This CI/CD configuration provides a standard pipeline for
|
|
# * building a Docker image (using a buildpack if necessary),
|
|
# * storing the image in the container registry,
|
|
# * running tests from a buildpack,
|
|
# * running code quality analysis,
|
|
# * creating a review app for each topic branch,
|
|
# * and continuous deployment to production
|
|
#
|
|
# Test jobs may be disabled by setting environment variables:
|
|
# * test: TEST_DISABLED
|
|
# * code_quality: CODE_QUALITY_DISABLED
|
|
# * license_management: LICENSE_MANAGEMENT_DISABLED
|
|
# * performance: PERFORMANCE_DISABLED
|
|
# * sast: SAST_DISABLED
|
|
# * dependency_scanning: DEPENDENCY_SCANNING_DISABLED
|
|
# * container_scanning: CONTAINER_SCANNING_DISABLED
|
|
# * dast: DAST_DISABLED
|
|
# * review: REVIEW_DISABLED
|
|
# * stop_review: REVIEW_DISABLED
|
|
#
|
|
# In order to deploy, you must have a Kubernetes cluster configured either
|
|
# via a project integration, or via group/project variables.
|
|
# KUBE_INGRESS_BASE_DOMAIN must also be set on the cluster settings,
|
|
# as a variable at the group or project level, or manually added below.
|
|
#
|
|
# Continuous deployment to production is enabled by default.
|
|
# If you want to deploy to staging first, set STAGING_ENABLED environment variable.
|
|
# If you want to enable incremental rollout, either manual or time based,
|
|
# set INCREMENTAL_ROLLOUT_MODE environment variable to "manual" or "timed".
|
|
# If you want to use canary deployments, set CANARY_ENABLED environment variable.
|
|
#
|
|
# If Auto DevOps fails to detect the proper buildpack, or if you want to
|
|
# specify a custom buildpack, set a project variable `BUILDPACK_URL` to the
|
|
# repository URL of the buildpack.
|
|
# e.g. BUILDPACK_URL=https://github.com/heroku/heroku-buildpack-ruby.git#v142
|
|
# If you need multiple buildpacks, add a file to your project called
|
|
# `.buildpacks` that contains the URLs, one on each line, in order.
|
|
# Note: Auto CI does not work with multiple buildpacks yet
|
|
|
|
image: alpine:latest
|
|
|
|
variables:
|
|
# KUBE_INGRESS_BASE_DOMAIN is the application deployment domain and should be set as a variable at the group or project level.
|
|
# KUBE_INGRESS_BASE_DOMAIN: domain.example.com
|
|
|
|
POSTGRES_USER: user
|
|
POSTGRES_PASSWORD: testing-password
|
|
POSTGRES_ENABLED: "true"
|
|
POSTGRES_DB: $CI_ENVIRONMENT_SLUG
|
|
POSTGRES_VERSION: 9.6.2
|
|
|
|
DOCKER_DRIVER: overlay2
|
|
|
|
ROLLOUT_RESOURCE_TYPE: deployment
|
|
|
|
DOCKER_TLS_CERTDIR: "" # https://gitlab.com/gitlab-org/gitlab-runner/issues/4501
|
|
|
|
stages:
|
|
- build
|
|
- test
|
|
- deploy # dummy stage to follow the template guidelines
|
|
- review
|
|
- dast
|
|
- staging
|
|
- canary
|
|
- production
|
|
- incremental rollout 10%
|
|
- incremental rollout 25%
|
|
- incremental rollout 50%
|
|
- incremental rollout 100%
|
|
- performance
|
|
- cleanup
|
|
|
|
include:
|
|
- template: Jobs/Build.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Jobs/Build.gitlab-ci.yml
|
|
- template: Jobs/Test.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Jobs/Test.gitlab-ci.yml
|
|
- template: Jobs/Code-Quality.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Jobs/Code-Quality.gitlab-ci.yml
|
|
- template: Jobs/Deploy.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Jobs/Deploy.gitlab-ci.yml
|
|
- template: Jobs/Browser-Performance-Testing.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Jobs/Browser-Performance-Testing.gitlab-ci.yml
|
|
- template: Security/DAST.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Security/DAST.gitlab-ci.yml
|
|
- template: Security/Container-Scanning.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Security/Container-Scanning.gitlab-ci.yml
|
|
- template: Security/Dependency-Scanning.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Security/Dependency-Scanning.gitlab-ci.yml
|
|
- template: Security/License-Management.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Security/License-Management.gitlab-ci.yml
|
|
- template: Security/SAST.gitlab-ci.yml # https://gitlab.com/gitlab-org/gitlab-ce/blob/master/lib/gitlab/ci/templates/Security/SAST.gitlab-ci.yml
|
|
|
|
# Override DAST job to exclude master branch
|
|
dast:
|
|
except:
|
|
refs:
|
|
- master
|