Skip to content

Objective #18

Description

@donny-devops

Objective
Implement a specialized, reusable GitHub Actions security gate for Dockerized environments, specifically hardened for the docker-compose-stacks fleet and the hands-on Docker hacking lab.

Scope
Static Analysis: Integrate hadolint for Dockerfile best practices and linting.

Vulnerability Scanning: Deploy trivy or grype to scan images for OS-level and dependency-level CVEs (critical for a hacking lab environment).

Compose Validation: Add docker-compose config --quiet to ensure configuration integrity before deployment.

Secrets Awareness: Implement a gate to prevent committing plaintext credentials or .env files, leveraging gitleaks specifically tuned for the lab's risk profile.

Temporary Workflow Constraint: Ensure workflows for the "hacking lab" are optimized to run only as needed (manual triggers or specific PR-path filters) to maintain lab environment isolation.

Technical Requirements
Reusable Action: Create a centralized docker-security-gate.yml in the github-actions-templates repo that can be called by other repos.

Input Parameters:

dockerfile-path: Path to the target Dockerfile.

compose-file-path: Path to the target docker-compose.yml.

fail-on-severity: Threshold (e.g., CRITICAL) for scanning tools.

Integration: Update the docker-compose-stacks repository to consume this reusable workflow.

Rollout Plan
Draft: Define the docker-security-gate.yml template in the shared templates repo.

Audit: Run a manual trivy audit against the current Docker hacking lab images to baseline current vulnerabilities.

Apply: Implement the workflow in the docker-compose-stacks repo.

Verify: Confirm that terminal output is free of "junk" (bracketed paste) artifacts by using clean env definitions in the Actions YAML.

Originally posted by @donny-devops in #14

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions