tekton-pipelines/catalog/maidn-node-static-image.yaml
2026-09-08 15:39:31 +02:00

177 lines
5.1 KiB
YAML

apiVersion: tekton.dev/v1
kind: Task
metadata:
name: maidn-git-clone
namespace: tekton-pipelines
spec:
stepTemplate:
env:
- name: HOME
value: /tekton/home
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
params:
- name: url
type: string
- name: revision
type: string
workspaces:
- name: source
steps:
- name: clone
image: alpine/git:2.47.2
env:
- name: REPOSITORY_URL
value: $(params.url)
- name: REVISION
value: $(params.revision)
- name: SOURCE_PATH
value: $(workspaces.source.path)
script: |
#!/bin/sh
set -eu
case "$REPOSITORY_URL" in https://git.pingu.pw/*) ;; *) exit 1 ;; esac
repository_path=${REPOSITORY_URL#https://git.pingu.pw/}
case "$repository_path" in *.git) ;; *) exit 1 ;; esac
case "$repository_path" in ''|*[!A-Za-z0-9._/-]*|/*|*//*|*..*) exit 1 ;; esac
case "$REVISION" in [A-Za-z0-9]*) ;; *) exit 1 ;; esac
case "$REVISION" in *[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac
git clone "$REPOSITORY_URL" "$SOURCE_PATH"
git config --global --add safe.directory "$SOURCE_PATH"
git -C "$SOURCE_PATH" checkout "$REVISION"
---
apiVersion: tekton.dev/v1
kind: Task
metadata:
name: maidn-node-static-build
namespace: tekton-pipelines
spec:
stepTemplate:
env:
- name: HOME
value: /tekton/home
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
params:
- name: output-directory
type: string
- name: build-configuration
type: string
default: ci
- name: target-directory
type: string
default: /www/target
workspaces:
- name: source
steps:
- name: build-layer
image: node:22-alpine
workingDir: $(workspaces.source.path)
env:
- name: OUTPUT_DIRECTORY
value: $(params.output-directory)
- name: TARGET_DIRECTORY
value: $(params.target-directory)
- name: BUILD_CONFIGURATION
value: $(params.build-configuration)
script: |
#!/bin/sh
set -eu
case "$OUTPUT_DIRECTORY" in ''|/*|-*|*[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac
case "$TARGET_DIRECTORY" in /*) ;; *) exit 1 ;; esac
target_path=${TARGET_DIRECTORY#/}
case "$target_path" in ''|-*|*[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac
case "$BUILD_CONFIGURATION" in ''|-*|*[!A-Za-z0-9._-]*) exit 1 ;; esac
# ponytail: no lockfile; skip install scripts and use npm ci when package-lock.json is committed.
npm install --ignore-scripts --no-audit --no-fund --package-lock=false
npm run build -- --configuration "$BUILD_CONFIGURATION"
test -d "$OUTPUT_DIRECTORY"
layer_dir=$(mktemp -d)
trap 'rm -rf "$layer_dir"' EXIT
mkdir -p "$layer_dir/$target_path"
cp -R "$OUTPUT_DIRECTORY"/. "$layer_dir/$target_path/"
tar -C "$layer_dir" -cf layer.tar "$target_path"
---
apiVersion: tekton.dev/v1
kind: Task
metadata:
name: maidn-node-static-push
namespace: tekton-pipelines
spec:
stepTemplate:
env:
- name: HOME
value: /tekton/home
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
seccompProfile:
type: RuntimeDefault
params:
- name: image
type: string
- name: revision
type: string
- name: base-image
type: string
default: nginx:1.27-alpine
workspaces:
- name: source
volumes:
- name: registry-credentials
secret:
secretName: forgejo-registry-credentials
items:
- key: .dockerconfigjson
path: config.json
steps:
- name: validate-inputs
image: alpine:3.21.3
env:
- name: IMAGE
value: $(params.image)
- name: REVISION
value: $(params.revision)
- name: BASE_IMAGE
value: $(params.base-image)
script: |
#!/bin/sh
set -eu
case "$IMAGE" in git.pingu.pw/*) ;; *) exit 1 ;; esac
image_path=${IMAGE#git.pingu.pw/}
case "$image_path" in ''|*[!A-Za-z0-9._/-]*|/*|*//*|*..*|*/) exit 1 ;; esac
case "$REVISION" in [A-Za-z0-9]*) ;; *) exit 1 ;; esac
case "$REVISION" in *[!A-Za-z0-9._/-]*|*..*|*//*|*/) exit 1 ;; esac
case "$BASE_IMAGE" in ''|-*|*[!A-Za-z0-9._/@:-]*|/*|*//*|*..*) exit 1 ;; esac
- name: push
image: gcr.io/go-containerregistry/crane:v0.21.7
args:
- append
- --base=$(params.base-image)
- --new_layer=$(workspaces.source.path)/layer.tar
- --new_tag=$(params.image):$(params.revision)
volumeMounts:
- name: registry-credentials
mountPath: /tekton/home/.docker