Add image signing, SBOM generation, and vulnerability scanning to CI/CD
- Add Trivy vulnerability scanning (fails on CRITICAL/HIGH) - Add Syft SBOM generation in SPDX format - Add Cosign image signing using digest - Attach SBOM attestation to image in Harbor - Add cosign.pub for signature verification
This commit is contained in:
61
.github/workflows/deploy.yml
vendored
61
.github/workflows/deploy.yml
vendored
@ -85,6 +85,7 @@ jobs:
|
||||
password: ${{ secrets.HARBOR_PASSWORD }}
|
||||
|
||||
- name: Build and push Docker image
|
||||
id: build-push
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
context: .
|
||||
@ -93,6 +94,66 @@ jobs:
|
||||
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:${{ steps.set-tag.outputs.tag }}
|
||||
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}:latest
|
||||
|
||||
# ============================================================
|
||||
# Vulnerability Scanning with Trivy
|
||||
# ============================================================
|
||||
- name: Run Trivy vulnerability scanner
|
||||
uses: aquasecurity/trivy-action@master
|
||||
with:
|
||||
image-ref: ${{ steps.set-tag.outputs.full_image }}
|
||||
format: 'table'
|
||||
exit-code: '1'
|
||||
ignore-unfixed: true
|
||||
vuln-type: 'os,library'
|
||||
severity: 'CRITICAL,HIGH'
|
||||
|
||||
- name: Run Trivy and output SARIF
|
||||
uses: aquasecurity/trivy-action@master
|
||||
if: always()
|
||||
with:
|
||||
image-ref: ${{ steps.set-tag.outputs.full_image }}
|
||||
format: 'sarif'
|
||||
output: 'trivy-results.sarif'
|
||||
|
||||
# ============================================================
|
||||
# SBOM Generation with Syft
|
||||
# ============================================================
|
||||
- name: Generate SBOM with Syft
|
||||
uses: anchore/sbom-action@v0
|
||||
with:
|
||||
image: ${{ steps.set-tag.outputs.full_image }}
|
||||
format: spdx-json
|
||||
output-file: sbom.spdx.json
|
||||
|
||||
# ============================================================
|
||||
# Image Signing with Cosign
|
||||
# ============================================================
|
||||
- name: Install Cosign
|
||||
uses: sigstore/cosign-installer@v3
|
||||
|
||||
- name: Sign image with Cosign
|
||||
env:
|
||||
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
|
||||
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||
run: |
|
||||
cosign sign --key env://COSIGN_PRIVATE_KEY \
|
||||
--yes \
|
||||
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
|
||||
|
||||
# ============================================================
|
||||
# Attach SBOM to image in Harbor
|
||||
# ============================================================
|
||||
- name: Attach SBOM to image
|
||||
env:
|
||||
COSIGN_PASSWORD: ${{ secrets.COSIGN_PASSWORD }}
|
||||
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||
run: |
|
||||
cosign attest --key env://COSIGN_PRIVATE_KEY \
|
||||
--type spdxjson \
|
||||
--predicate sbom.spdx.json \
|
||||
--yes \
|
||||
${{ secrets.HARBOR_REGISTRY }}/${{ secrets.HARBOR_PROJECT }}/${{ env.IMAGE_NAME }}@${{ steps.build-push.outputs.digest }}
|
||||
|
||||
# ============================================================
|
||||
# Deploy Job - Pull image and restart on production server
|
||||
# ============================================================
|
||||
|
||||
4
cosign.pub
Normal file
4
cosign.pub
Normal file
@ -0,0 +1,4 @@
|
||||
-----BEGIN PUBLIC KEY-----
|
||||
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEBOFl4SHzoZVM59+668t2tecTyKM+
|
||||
cE4zaOkbFO30u7d2+bjpwPnbYrTutKmAeehYzCAVW/OYea7ML0cW2YCSCQ==
|
||||
-----END PUBLIC KEY-----
|
||||
Reference in New Issue
Block a user