Objective
Implement a specialized, reusable GitHub Actions security gate for Dockerized environments, specifically hardened for the docker-compose-stacks fleet and the hands-on Docker hacking lab.
Scope
Static Analysis: Integrate hadolint for Dockerfile best practices and linting.
Vulnerability Scanning: Deploy trivy or grype to scan images for OS-level and dependency-level CVEs (critical for a hacking lab environment).
Compose Validation: Add docker-compose config --quiet to ensure configuration integrity before deployment.
Secrets Awareness: Implement a gate to prevent committing plaintext credentials or .env files, leveraging gitleaks specifically tuned for the lab's risk profile.
Temporary Workflow Constraint: Ensure workflows for the "hacking lab" are optimized to run only as needed (manual triggers or specific PR-path filters) to maintain lab environment isolation.
Technical Requirements
Reusable Action: Create a centralized docker-security-gate.yml in the github-actions-templates repo that can be called by other repos.
Input Parameters:
dockerfile-path: Path to the target Dockerfile.
compose-file-path: Path to the target docker-compose.yml.
fail-on-severity: Threshold (e.g., CRITICAL) for scanning tools.
Integration: Update the docker-compose-stacks repository to consume this reusable workflow.
Rollout Plan
Draft: Define the docker-security-gate.yml template in the shared templates repo.
Audit: Run a manual trivy audit against the current Docker hacking lab images to baseline current vulnerabilities.
Apply: Implement the workflow in the docker-compose-stacks repo.
Verify: Confirm that terminal output is free of "junk" (bracketed paste) artifacts by using clean env definitions in the Actions YAML.
Objective
Implement a specialized, reusable GitHub Actions security gate for Dockerized environments, specifically hardened for the docker-compose-stacks fleet and the hands-on Docker hacking lab.
Scope
Static Analysis: Integrate hadolint for Dockerfile best practices and linting.
Vulnerability Scanning: Deploy trivy or grype to scan images for OS-level and dependency-level CVEs (critical for a hacking lab environment).
Compose Validation: Add docker-compose config --quiet to ensure configuration integrity before deployment.
Secrets Awareness: Implement a gate to prevent committing plaintext credentials or .env files, leveraging gitleaks specifically tuned for the lab's risk profile.
Temporary Workflow Constraint: Ensure workflows for the "hacking lab" are optimized to run only as needed (manual triggers or specific PR-path filters) to maintain lab environment isolation.
Technical Requirements
Reusable Action: Create a centralized docker-security-gate.yml in the github-actions-templates repo that can be called by other repos.
Input Parameters:
dockerfile-path: Path to the target Dockerfile.
compose-file-path: Path to the target docker-compose.yml.
fail-on-severity: Threshold (e.g., CRITICAL) for scanning tools.
Integration: Update the docker-compose-stacks repository to consume this reusable workflow.
Rollout Plan
Draft: Define the docker-security-gate.yml template in the shared templates repo.
Audit: Run a manual trivy audit against the current Docker hacking lab images to baseline current vulnerabilities.
Apply: Implement the workflow in the docker-compose-stacks repo.
Verify: Confirm that terminal output is free of "junk" (bracketed paste) artifacts by using clean env definitions in the Actions YAML.