forgejo-mcp/.tekton/release-tools/tasks/verify-image-tools.yaml
Christoph Görn 5df98baca9
feat(ci): 🚀 add release-tools image build + publish Tekton pipelines (iteration 2)
Implements sections 3-4 of openspec/changes/release-tools-image/tasks.md.
Produces .tekton/release-tools/ containing:

PipelineRuns (PaC):
- on-pull-request-build.yaml — CEL gated to files.any.exists() under
  image/release-tools/ or .tekton/release-tools/. Builds + verifies +
  SBOM-scans the image; no push.
- on-tag-publish.yaml — triggered on refs/tags/release-tools/v* push.
  Pipeline shape (TOCTOU-safe per adversarial review L1):
    fetch-source → resolve-tag → build → verify-tools → syft-scan →
    push-by-digest → cosign-sign-by-digest → cosign-attach-sbom →
    promote-tag (only NOW does vMAJOR.MINOR.PATCH resolve).

Reusable Tasks:
- build-image.yaml — buildah build against image/release-tools/Containerfile
- verify-image-tools.yaml — runs built image, asserts every bundled
  tool's --version + the offline-npx + shell-present scenarios
- syft-scan-image.yaml — CycloneDX SBOM via syft (uses release-tools
  image itself — dogfooding)
- resolve-release-tools-tag.yaml — strips refs/tags/release-tools/ prefix
- push-image-by-digest.yaml — pushes manifest by digest only, no tag
- cosign-sign-image-by-digest.yaml — signs by digest with
  cosign-signing-key (optional: false, fail-closed per spec asymmetry)
- cosign-attach-sbom.yaml — attaches SBOM as cosign attestation
- promote-image-tag.yaml — crane/skopeo tag promotion AFTER sign

Defensive CEL:
- .tekton/on-tag-push-release.yaml — added negative-CEL annotation so a
  release-tools/vX.Y.Z tag push CANNOT accidentally fire the forgejo-mcp
  release pipeline (adversarial review A1).

Verifier T12 PASS: yaml syntax (all 11 files), pre-commit (gitleaks),
openspec validate release-tools-image — all green.

Registry path is TBD (working assumption quay.io/operate-first/release-tools)
— flagged in pipeline header comments; coordinate with op1st-emea-b4mad
maintainers before first tag-publish run.

Refs: forgejo-mcp-1b4
2026-05-25 18:53:49 +02:00

55 lines
1.6 KiB
YAML

apiVersion: tekton.dev/v1
kind: Task
metadata:
name: release-tools-verify-image-tools
annotations:
tekton.dev/displayName: "verify bundled tool versions in release-tools image"
spec:
params:
- name: IMAGE_REF
description: Full image reference to run (tag or tag@digest).
type: string
- name: STORAGE_DRIVER
description: buildah/podman storage driver.
type: string
default: vfs
steps:
- name: verify-tools
image: quay.io/buildah/stable:latest
securityContext:
privileged: true
script: |
#!/usr/bin/env bash
set -euo pipefail
IMAGE="$(params.IMAGE_REF)"
echo "Verifying tools in: ${IMAGE}"
run() {
buildah run \
--storage-driver="$(params.STORAGE_DRIVER)" \
--isolation=chroot \
"$(buildah from --storage-driver="$(params.STORAGE_DRIVER)" "${IMAGE}")" \
-- /bin/sh -c "$1"
}
# Verify each required tool reports a version (fails build if any missing).
buildah from --storage-driver="$(params.STORAGE_DRIVER)" --name verify-ctr "${IMAGE}"
check() {
echo "--- $1 ---"
buildah run --storage-driver="$(params.STORAGE_DRIVER)" verify-ctr -- /bin/sh -c "$1"
}
check "go version"
check "syft version"
check "goreleaser --version"
check "cosign version"
check "jq --version"
check "curl --version"
check "node --version"
check "npm --version"
check "/bin/sh -c 'echo shell-ok'"
buildah rm verify-ctr
echo "All tool checks passed."