Files

17 lines
1.5 KiB
Markdown
Raw Permalink Normal View History

2026-09-28 11:12:02 +02:00
# repo2cicd2deploy
Proof of concept for separating build from deploy in our Docker CI/CD pipelines, using Woodpecker, a Zot registry, and SOPS-encrypted secrets. Ansible provisioning for the PoC infrastructure lives in this repo; the documents below cover the design, the proposal, and what was actually verified.
## Documents
- **[`PROPOSAL.md`](PROPOSAL.md)** — start here. A short, team-facing comparison of today's setup versus the proposed one, with diagrams, benefits, and honest downsides.
- **[`concept.md`](concept.md)** — the detailed architecture: components, workflow, trust boundaries, and the alternatives that were considered and dropped.
- **[`plan.md`](plan.md)** — the implementation plan the PoC followed, broken into tasks with test criteria.
- **[`POC-RESULTS.md`](POC-RESULTS.md)** — what was actually built and verified, every bug found along the way, and a security analysis of the working system.
- **[`fsfe-current-deployment.md`](fsfe-current-deployment.md)** — how FSFE deploys Docker services today (Drone + direct Docker socket access), for comparison.
## Other repositories used in the PoC
- **[dummy-service](https://src.mehl.mx/mxmehl/dummy-service)** — the example service repository: builds two containers, encrypts its secrets with SOPS, publishes to the registry, and triggers a deployment.
- **[poc-deployment](https://src.mehl.mx/mxmehl/poc-deployment)** — the central deployment repository: decrypts secrets, resolves the target host, and runs the deployment over SSH.