Compare commits
43 Commits
48b884ae72
...
test
| Author | SHA1 | Date | |
|---|---|---|---|
| e26c79a9d7 | |||
| ae1440fce3 | |||
| b58b5777fd | |||
| 83dfdc2cc3 | |||
| bbdb27b116 | |||
| 1da1328870 | |||
| 3b5ca4f5b0 | |||
| 1526648d9a | |||
| d1f723c135 | |||
| 423281d071 | |||
| 44fbc613a3 | |||
| a922531f50 | |||
| 9acebb67fe | |||
| e140319a05 | |||
| 3752da6ebe | |||
| 1937d2eaa1 | |||
| c2a8b5c797 | |||
| c584d39270 | |||
| 81e93b0e4e | |||
| 89f619eefa | |||
| b46848dd56 | |||
| 30e0bc2b87 | |||
| 903c17e7f8 | |||
| bd3cba05cb | |||
| 007f606bb6 | |||
| ef6262282d | |||
| 502182a370 | |||
| c6799a146a | |||
| 6bd60452f2 | |||
| 52e24bb8f2 | |||
| a8ad599af2 | |||
| 5dff86c4fa | |||
| 6a29032748 | |||
| 634ad82d2c | |||
| 59c08d2314 | |||
| 496e6b653d | |||
| 4c86a810da | |||
| 1ee31554ce | |||
| 3d1e3f29df | |||
| c03dc29446 | |||
| 24e439558f | |||
| 1917a60867 | |||
| c43ce20bbe |
@@ -27,4 +27,6 @@ README.md
|
|||||||
!.git/config
|
!.git/config
|
||||||
!.git/packed-refs
|
!.git/packed-refs
|
||||||
!.git/refs/heads/**
|
!.git/refs/heads/**
|
||||||
|
# Ensure the build output is NOT ignored
|
||||||
|
!**/bin/Release/**/publish/
|
||||||
|
!**/publish/
|
||||||
|
|||||||
164
.drone.yml
164
.drone.yml
@@ -1,140 +1,68 @@
|
|||||||
---
|
---
|
||||||
kind: pipeline
|
kind: pipeline
|
||||||
type: docker
|
type: docker
|
||||||
name: build
|
name: build-and-package
|
||||||
trigger:
|
|
||||||
event:
|
|
||||||
exclude:
|
|
||||||
- promote
|
|
||||||
|
|
||||||
clone:
|
|
||||||
disable: true
|
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: checkout
|
- name: build-test-publish
|
||||||
image: alpine/git
|
image: nexus.khongisa.co.za/sdk:10.0
|
||||||
commands:
|
commands:
|
||||||
- git clone https://gitea.khongisa.co.za/MngomaLab/webapitest.git .
|
- dotnet restore --source https://nexus.khongisa.co.za/repository/nuget-group/index.json --no-cache
|
||||||
- git checkout ${DRONE_COMMIT}
|
- dotnet build --configuration Release --no-restore
|
||||||
|
- dotnet test --configuration Release --no-build
|
||||||
|
- dotnet publish --configuration Release --no-build
|
||||||
|
|
||||||
- name: dotnet build
|
- name: docker-build-and-push
|
||||||
image: mcr.microsoft.com/dotnet/sdk:10.0
|
image: plugins/docker
|
||||||
commands:
|
settings:
|
||||||
- dotnet build --configuration Release
|
registry: nexus.khongisa.co.za
|
||||||
|
repo: nexus.khongisa.co.za/webapitest
|
||||||
|
tags: [ "${DRONE_BUILD_NUMBER}", "latest" ]
|
||||||
|
username: { from_secret: docker_username }
|
||||||
|
password: { from_secret: docker_password }
|
||||||
|
|
||||||
- name: dotnet test
|
- name: vulnerability-scan
|
||||||
image: mcr.microsoft.com/dotnet/sdk:10.0
|
image: aquasec/trivy:0.50.1
|
||||||
commands:
|
|
||||||
- dotnet test --configuration Release
|
|
||||||
---
|
|
||||||
x-docker-auth: &docker-auth
|
|
||||||
DOCKER_AUTH_CONFIG: |
|
|
||||||
{
|
|
||||||
"auths": {
|
|
||||||
"https://index.docker.io/v1/": {
|
|
||||||
"auth": "a2h3ZXppOlBHM0FRM0VPMFg="
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
kind: pipeline
|
|
||||||
type: docker
|
|
||||||
name: package
|
|
||||||
depends_on:
|
|
||||||
- build
|
|
||||||
trigger:
|
|
||||||
event:
|
|
||||||
exclude:
|
|
||||||
- promote
|
|
||||||
|
|
||||||
clone:
|
|
||||||
disable: true
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: checkout
|
|
||||||
image: alpine/git
|
|
||||||
commands:
|
|
||||||
- git clone https://gitea.khongisa.co.za/MngomaLab/webapitest.git .
|
|
||||||
- git checkout ${DRONE_COMMIT}
|
|
||||||
|
|
||||||
- name: dotnet publish
|
|
||||||
image: mcr.microsoft.com/dotnet/sdk:10.0
|
|
||||||
commands:
|
|
||||||
- dotnet publish --configuration Release
|
|
||||||
|
|
||||||
|
|
||||||
- name: build and push
|
|
||||||
image: gcr.io/kaniko-project/executor:debug
|
|
||||||
environment:
|
environment:
|
||||||
<<: *docker-auth
|
TRIVY_USERNAME: { from_secret: docker_username }
|
||||||
|
TRIVY_PASSWORD: { from_secret: docker_password }
|
||||||
commands:
|
commands:
|
||||||
- mkdir -p /kaniko/.docker
|
- trivy image --image-src remote --exit-code 1 --severity CRITICAL nexus.khongisa.co.za/webapitest:${DRONE_BUILD_NUMBER}
|
||||||
- echo "$DOCKER_AUTH_CONFIG" > /kaniko/.docker/config.json
|
|
||||||
- /kaniko/executor
|
|
||||||
--verbosity=debug
|
|
||||||
--context=.
|
|
||||||
--dockerfile=Dockerfile
|
|
||||||
--destination=index.docker.io/khwezi/webapitest:latest
|
|
||||||
--destination=index.docker.io/khwezi/webapitest:${DRONE_BUILD_NUMBER}
|
|
||||||
|
|
||||||
- name: volnerability scan
|
|
||||||
image: aquasec/trivy
|
|
||||||
commands:
|
|
||||||
- trivy image --exit-code 1 --timeout 15m --severity CRITICAL khwezi/webapitest:${DRONE_BUILD_NUMBER}
|
|
||||||
---
|
|
||||||
kind: pipeline
|
|
||||||
type: docker
|
|
||||||
name: deploy
|
|
||||||
depends_on:
|
|
||||||
- package
|
|
||||||
trigger:
|
trigger:
|
||||||
|
branch:
|
||||||
|
- main
|
||||||
event:
|
event:
|
||||||
exclude:
|
exclude:
|
||||||
- promote
|
- promote
|
||||||
|
|
||||||
clone:
|
---
|
||||||
disable: true
|
kind: pipeline
|
||||||
|
type: docker
|
||||||
|
name: deploy-to-uat
|
||||||
|
|
||||||
|
depends_on:
|
||||||
|
- build-and-package
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: uat
|
- name: uat-deployment
|
||||||
image: appleboy/drone-ssh
|
image: appleboy/drone-ssh
|
||||||
settings:
|
settings:
|
||||||
host:
|
host: { from_secret: ssh_host }
|
||||||
from_secret: ssh_host
|
username: { from_secret: ssh_user }
|
||||||
username:
|
password: { from_secret: ssh_password }
|
||||||
from_secret: ssh_user
|
|
||||||
password:
|
|
||||||
from_secret: ssh_password
|
|
||||||
script:
|
script:
|
||||||
- docker pull khwezi/webapitest:latest
|
- echo $DOCKER_PASSWORD | docker login nexus.khongisa.co.za -u $DOCKER_USERNAME --password-stdin
|
||||||
- docker run -d --name webapi --restart unless-stopped -e ASPNETCORE_ENVIRONMENT=Development -p 4000:8081 khwezi/webapitest:latest
|
- docker pull nexus.khongisa.co.za/webapitest:latest
|
||||||
|
- docker stop webapi 2>/dev/null || true
|
||||||
---
|
- docker rm webapi 2>/dev/null || true
|
||||||
kind: pipeline
|
- docker run -d --name webapi --restart unless-stopped -e ASPNETCORE_ENVIRONMENT=Development -p 4000:8081 nexus.khongisa.co.za/webapitest:latest
|
||||||
type: docker
|
|
||||||
name: golive
|
|
||||||
depends_on:
|
|
||||||
- deploy
|
|
||||||
|
|
||||||
clone:
|
|
||||||
disable: true
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: prod
|
|
||||||
image: appleboy/drone-ssh
|
|
||||||
environment:
|
environment:
|
||||||
PLUGIN_USER:
|
DOCKER_USERNAME: { from_secret: docker_username }
|
||||||
from_secret: ssh_prod_user
|
DOCKER_PASSWORD: { from_secret: docker_password }
|
||||||
PLUGIN_PASSWORD:
|
|
||||||
from_secret: ssh_prod_password
|
trigger:
|
||||||
PLUGIN_HOST:
|
event:
|
||||||
from_secret: ssh_prod_host
|
- promote
|
||||||
settings:
|
target:
|
||||||
script:
|
- staging
|
||||||
- docker pull khwezi/webapitest:latest
|
|
||||||
- docker run -d --name webapi --restart unless-stopped -e ASPNETCORE_ENVIRONMENT=Production -p 4001:8081 khwezi/webapitest:latest
|
|
||||||
when:
|
|
||||||
event:
|
|
||||||
- promote
|
|
||||||
target:
|
|
||||||
- prod
|
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
FROM mcr.microsoft.com/dotnet/aspnet:10.0 AS final
|
FROM nexus.khongisa.co.za/aspnet:10.0 AS final
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
USER app
|
USER app
|
||||||
|
|||||||
@@ -9,8 +9,9 @@
|
|||||||
</PropertyGroup>
|
</PropertyGroup>
|
||||||
|
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<PackageReference Include="Microsoft.VisualStudio.Azure.Containers.Tools.Targets" Version="1.19.6" />
|
<PackageReference Include="Microsoft.VisualStudio.Azure.Containers.Tools.Targets" Version="1.23.0" />
|
||||||
<PackageReference Include="Swashbuckle.AspNetCore" Version="6.4.0" />
|
<PackageReference Include="Polly" Version="8.6.6" />
|
||||||
|
<PackageReference Include="Swashbuckle.AspNetCore" Version="10.1.7" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
</Project>
|
</Project>
|
||||||
|
|||||||
Reference in New Issue
Block a user