Setup the external secrets helm charts Convert hard coded secrets to external secrets Add BitWarden CLI for serving external secrets
37 lines
784 B
YAML
37 lines
784 B
YAML
stages:
|
|
- eval
|
|
- build
|
|
|
|
default:
|
|
tags:
|
|
- nix
|
|
|
|
"Evaluate for builds":
|
|
stage: eval
|
|
artifacts:
|
|
paths:
|
|
- gitlab-ci-continue.yml
|
|
script: nix run ".#gen-build" > gitlab-ci-continue.yml
|
|
|
|
"Trigger builds":
|
|
stage: build
|
|
trigger:
|
|
include:
|
|
- artifact: gitlab-ci-continue.yml
|
|
job: "Evaluate for builds"
|
|
variables:
|
|
PARENT_PIPELINE_ID: $CI_PIPELINE_ID
|
|
|
|
"Build image":
|
|
stage: build
|
|
parallel:
|
|
matrix:
|
|
- IMG:
|
|
- img-bitwarden
|
|
script:
|
|
- podman login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY"
|
|
- nix build ".#${IMG}"
|
|
- podman load -i result
|
|
- podman tag "localhost/${IMG}:latest" "$CI_REGISTRY/greg/ci-images/${IMG}:latest"
|
|
- podman push "$CI_REGISTRY/greg/ci-images/${IMG}:latest"
|