1.5 KiB
1.5 KiB
repo2cicd2deploy
Proof of concept for separating build from deploy in our Docker CI/CD pipelines, using Woodpecker, a Zot registry, and SOPS-encrypted secrets. Ansible provisioning for the PoC infrastructure lives in this repo; the documents below cover the design, the proposal, and what was actually verified.
Documents
PROPOSAL.md— start here. A short, team-facing comparison of today's setup versus the proposed one, with diagrams, benefits, and honest downsides.concept.md— the detailed architecture: components, workflow, trust boundaries, and the alternatives that were considered and dropped.plan.md— the implementation plan the PoC followed, broken into tasks with test criteria.POC-RESULTS.md— what was actually built and verified, every bug found along the way, and a security analysis of the working system.fsfe-current-deployment.md— how FSFE deploys Docker services today (Drone + direct Docker socket access), for comparison.
Other repositories used in the PoC
- dummy-service — the example service repository: builds two containers, encrypts its secrets with SOPS, publishes to the registry, and triggers a deployment.
- poc-deployment — the central deployment repository: decrypts secrets, resolves the target host, and runs the deployment over SSH.