Add image signing, SBOM generation, and vulnerability scanning to CI/CD
- Add Trivy vulnerability scanning (fails on CRITICAL/HIGH) - Add Syft SBOM generation in SPDX format - Add Cosign image signing using digest - Attach SBOM attestation to image in Harbor - Add cosign.pub for signature verification
This commit is contained in:
61
.github/workflows/deploy.yml
vendored
61
.github/workflows/deploy.yml
vendored
@ -85,6 +85,7 @@ jobs:
|
|||||||
password: ${{ secrets.HARBOR_PASSWORD }}
|
password: ${{ secrets.HARBOR_PASSWORD }}
|
||||||
|
|
||||||
- name: Build and push Docker image
|
- name: Build and push Docker image
|
||||||
|
id: build-push
|
||||||
uses: docker/build-push-action@v5
|
uses: docker/build-push-action@v5
|
||||||
with:
|
with:
|
||||||
context: .
|
context: .
|
||||||
@ -93,6 +94,66 @@ jobs:
|
|||||||
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }}
|
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }}
|
||||||
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest
|
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# Vulnerability Scanning with Trivy
|
||||||
|
# ============================================================
|
||||||
|
- name: Run Trivy vulnerability scanner
|
||||||
|
uses: aquasecurity/trivy-action@master
|
||||||
|
with:
|
||||||
|
image-ref: ${{ steps.set-tag.outputs.full_image }}
|
||||||
|
format: 'table'
|
||||||
|
exit-code: '1'
|
||||||
|
ignore-unfixed: true
|
||||||
|
vuln-type: 'os,library'
|
||||||
|
severity: 'CRITICAL,HIGH'
|
||||||
|
|
||||||
|
- name: Run Trivy and output SARIF
|
||||||
|
uses: aquasecurity/trivy-action@master
|
||||||
|
if: always()
|
||||||
|
with:
|
||||||
|
image-ref: ${{ steps.set-tag.outputs.full_image }}
|
||||||
|
format: 'sarif'
|
||||||
|
output: 'trivy-results.sarif'
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# SBOM Generation with Syft
|
||||||
|
# ============================================================
|
||||||
|
- name: Generate SBOM with Syft
|
||||||
|
uses: anchore/sbom-action@v0
|
||||||
|
with:
|
||||||
|
image: ${{ steps.set-tag.outputs.full_image }}
|
||||||
|
format: spdx-json
|
||||||
|
output-file: sbom.spdx.json
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# Image Signing with Cosign
|
||||||
|
# ============================================================
|
||||||
|
- name: Install Cosign
|
||||||
|
uses: sigstore/cosign-installer@v3
|
||||||
|
|
||||||
|
- name: Sign image with Cosign
|
||||||
|
env:
|
||||||
|
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
|
||||||
|
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||||
|
run: |
|
||||||
|
cosign sign --key env://COSIGN_PRIVATE_KEY \
|
||||||
|
--yes \
|
||||||
|
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
|
||||||
|
|
||||||
|
# ============================================================
|
||||||
|
# Attach SBOM to image in Harbor
|
||||||
|
# ============================================================
|
||||||
|
- name: Attach SBOM to image
|
||||||
|
env:
|
||||||
|
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
|
||||||
|
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||||
|
run: |
|
||||||
|
cosign attest --key env://COSIGN_PRIVATE_KEY \
|
||||||
|
--type spdxjson \
|
||||||
|
--predicate sbom.spdx.json \
|
||||||
|
--yes \
|
||||||
|
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
|
||||||
|
|
||||||
# ============================================================
|
# ============================================================
|
||||||
# Deploy Job - Pull image and restart on production server
|
# Deploy Job - Pull image and restart on production server
|
||||||
# ============================================================
|
# ============================================================
|
||||||
|
|||||||
4
cosign.pub
Normal file
4
cosign.pub
Normal file
@ -0,0 +1,4 @@
|
|||||||
|
-----BEGIN PUBLIC KEY-----
|
||||||
|
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEBOFl4SHzoZVM59+668t2tecTyKM+
|
||||||
|
cE4zaOkbFO30u7d2+bjpwPnbYrTutKmAeehYzCAVW/OYea7ML0cW2YCSCQ==
|
||||||
|
-----END PUBLIC KEY-----
|
||||||
Reference in New Issue
Block a user