Files
repo2cicd2deploy/README.md
T

1.5 KiB

repo2cicd2deploy

Proof of concept for separating build from deploy in our Docker CI/CD pipelines, using Woodpecker, a Zot registry, and SOPS-encrypted secrets. Ansible provisioning for the PoC infrastructure lives in this repo; the documents below cover the design, the proposal, and what was actually verified.

Documents

  • PROPOSAL.md — start here. A short, team-facing comparison of today's setup versus the proposed one, with diagrams, benefits, and honest downsides.
  • concept.md — the detailed architecture: components, workflow, trust boundaries, and the alternatives that were considered and dropped.
  • plan.md — the implementation plan the PoC followed, broken into tasks with test criteria.
  • POC-RESULTS.md — what was actually built and verified, every bug found along the way, and a security analysis of the working system.
  • fsfe-current-deployment.md — how FSFE deploys Docker services today (Drone + direct Docker socket access), for comparison.

Other repositories used in the PoC

  • dummy-service — the example service repository: builds two containers, encrypts its secrets with SOPS, publishes to the registry, and triggers a deployment.
  • poc-deployment — the central deployment repository: decrypts secrets, resolves the target host, and runs the deployment over SSH.