40 lines
1.1 KiB
YAML
40 lines
1.1 KiB
YAML
{{- if .Values.pipeline.enabled }}
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: ClusterWorkflowTemplate
|
|
metadata:
|
|
name: amp-security-pipeline-v1.0.0
|
|
spec:
|
|
templates:
|
|
- name: scan-kics
|
|
metadata:
|
|
annotations:
|
|
secrets.infisical.com/auto-reload: "true"
|
|
initContainers:
|
|
- name: wait-for-infisical
|
|
image: alpine:3.20
|
|
command:
|
|
- sh
|
|
- -c
|
|
args:
|
|
- until [ -n "${KICS_TOKEN:-}" ]; do sleep 2; done
|
|
container:
|
|
image: checkmarx/kics:1.7.14
|
|
command:
|
|
- sh
|
|
- -c
|
|
args:
|
|
- |
|
|
set -eu
|
|
mkdir -p /workspace/reports
|
|
kics scan -p /workspace -o /workspace/reports --report-formats sarif,json --output-name kics || true
|
|
if [ -f /workspace/reports/kics.sarif ]; then
|
|
exit 0
|
|
fi
|
|
if [ -f /workspace/reports/kics.json ]; then
|
|
cp /workspace/reports/kics.json /workspace/reports/kics.sarif
|
|
fi
|
|
volumeMounts:
|
|
- name: workspace
|
|
mountPath: /workspace
|
|
{{- end }}
|