apiVersion: tekton.dev/v1 kind: Task metadata: name: maidn-git-clone namespace: tekton-pipelines spec: stepTemplate: env: - name: HOME value: /tekton/home securityContext: runAsNonRoot: true runAsUser: 1000 runAsGroup: 1000 allowPrivilegeEscalation: false capabilities: drop: - ALL seccompProfile: type: RuntimeDefault params: - name: url type: string - name: revision type: string workspaces: - name: source steps: - name: clone image: alpine/git:2.47.2 env: - name: REPOSITORY_URL value: $(params.url) - name: REVISION value: $(params.revision) - name: SOURCE_PATH value: $(workspaces.source.path) script: | #!/bin/sh set -eu case "$REPOSITORY_URL" in https://git.pingu.pw/*) ;; *) exit 1 ;; esac repository_path=${REPOSITORY_URL#https://git.pingu.pw/} case "$repository_path" in *.git) ;; *) exit 1 ;; esac case "$repository_path" in ''|*[!A-Za-z0-9._/-]*|/*|*//*|*..*) exit 1 ;; esac case "$REVISION" in [A-Za-z0-9]*) ;; *) exit 1 ;; esac case "$REVISION" in *[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac git clone "$REPOSITORY_URL" "$SOURCE_PATH" git config --global --add safe.directory "$SOURCE_PATH" git -C "$SOURCE_PATH" checkout "$REVISION" --- apiVersion: tekton.dev/v1 kind: Task metadata: name: maidn-node-static-build namespace: tekton-pipelines spec: stepTemplate: env: - name: HOME value: /tekton/home securityContext: runAsNonRoot: true runAsUser: 1000 runAsGroup: 1000 allowPrivilegeEscalation: false capabilities: drop: - ALL seccompProfile: type: RuntimeDefault params: - name: output-directory type: string - name: build-configuration type: string default: ci - name: target-directory type: string default: /www/target workspaces: - name: source steps: - name: build-layer image: node:22-alpine env: - name: OUTPUT_DIRECTORY value: $(params.output-directory) - name: SOURCE_PATH value: $(workspaces.source.path) - name: TARGET_DIRECTORY value: $(params.target-directory) - name: BUILD_CONFIGURATION value: $(params.build-configuration) - name: NODE_OPTIONS value: --max-old-space-size=384 resources: requests: memory: 256Mi limits: memory: 512Mi script: | #!/bin/sh set -eu case "$OUTPUT_DIRECTORY" in ''|/*|-*|*[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac case "$TARGET_DIRECTORY" in /*) ;; *) exit 1 ;; esac target_path=${TARGET_DIRECTORY#/} case "$target_path" in ''|-*|*[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac case "$BUILD_CONFIGURATION" in ''|-*|*[!A-Za-z0-9._-]*) exit 1 ;; esac build_dir=$(mktemp -d) cp -R "$SOURCE_PATH"/. "$build_dir" cd "$build_dir" # ponytail: no lockfile; skip install scripts and use npm ci when package-lock.json is committed. npm install --ignore-scripts --no-audit --no-fund --package-lock=false npm run build -- --configuration "$BUILD_CONFIGURATION" test -d "$OUTPUT_DIRECTORY" layer_dir=$(mktemp -d) trap 'rm -rf "$build_dir" "$layer_dir"' EXIT mkdir -p "$layer_dir/$target_path" cp -R "$OUTPUT_DIRECTORY"/. "$layer_dir/$target_path/" tar -C "$layer_dir" -cf "$SOURCE_PATH/layer.tar" "$target_path" for memory_peak_path in /sys/fs/cgroup/memory.peak /sys/fs/cgroup/memory/memory.max_usage_in_bytes; do if [ -r "$memory_peak_path" ] && memory_peak=$(cat "$memory_peak_path"); then case "$memory_peak" in ''|*[!0-9]*) ;; *) printf 'cgroup memory peak: %s\n' "$memory_peak"; break ;; esac fi done --- apiVersion: tekton.dev/v1 kind: Task metadata: name: maidn-node-static-push namespace: tekton-pipelines spec: stepTemplate: env: - name: HOME value: /tekton/home securityContext: runAsNonRoot: true runAsUser: 1000 runAsGroup: 1000 allowPrivilegeEscalation: false capabilities: drop: - ALL seccompProfile: type: RuntimeDefault params: - name: image type: string - name: revision type: string - name: base-image type: string default: nginx:1.27-alpine workspaces: - name: source volumes: - name: registry-credentials secret: secretName: forgejo-registry-credentials items: - key: .dockerconfigjson path: config.json steps: - name: validate-inputs image: alpine:3.21.3 env: - name: IMAGE value: $(params.image) - name: REVISION value: $(params.revision) - name: BASE_IMAGE value: $(params.base-image) script: | #!/bin/sh set -eu case "$IMAGE" in git.pingu.pw/*) ;; *) exit 1 ;; esac image_path=${IMAGE#git.pingu.pw/} case "$image_path" in ''|*[!A-Za-z0-9._/-]*|/*|*//*|*..*|*/) exit 1 ;; esac case "$REVISION" in [A-Za-z0-9]*) ;; *) exit 1 ;; esac case "$REVISION" in *[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac case "$BASE_IMAGE" in ''|-*|*[!A-Za-z0-9._/@:-]*|/*|*//*|*..*) exit 1 ;; esac - name: push image: gcr.io/go-containerregistry/crane:v0.21.7 args: - append - --base=$(params.base-image) - --new_layer=$(workspaces.source.path)/layer.tar - --new_tag=$(params.image):$(params.revision) volumeMounts: - name: registry-credentials mountPath: /tekton/home/.docker