feat(decdn_node): opt-in host-side keystore generation + fix provisioning docs #56
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| # Least privilege by default; jobs widen only what they need. | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| # Third-party actions are pinned to a full commit SHA (a re-pointed tag can ship | |
| # malicious code — cf. the March 2026 KICS action compromise). The trailing | |
| # comment records the human-readable version; .github/dependabot.yml bumps them. | |
| jobs: | |
| # Detect whether ansible/ changed so the heavy Ansible jobs skip unrelated PRs. | |
| changes: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| outputs: | |
| ansible: ${{ steps.filter.outputs.ansible }} | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4.0.2 | |
| id: filter | |
| with: | |
| filters: | | |
| ansible: | |
| - 'ansible/**' | |
| # Ansible style + best-practice + the production-profile SECURITY rules, | |
| # plus a syntax-check of every playbook. Runs only when ansible/ changed. | |
| ansible-lint: | |
| needs: changes | |
| if: needs.changes.outputs.ansible == 'true' | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: ansible | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: '3.12' | |
| - name: Install Ansible tooling | |
| run: python -m pip install --upgrade ansible ansible-lint yamllint | |
| - name: Install Galaxy collections | |
| run: make deps # must precede lint/syntax-check | |
| - name: Lint (yamllint + ansible-lint) | |
| run: make lint | |
| - name: Syntax-check playbook | |
| # Dummy inventory: no real hosts.yml is committed upstream (only hosts.yml.example), | |
| # and --syntax-check only parses, it never connects. | |
| run: ansible-playbook playbooks/site.yml --syntax-check -i localhost, | |
| # Build the public `decdn.node` collection and run galaxy-importer's checks — | |
| # the same validation Galaxy runs on upload (metadata, license, README, embedded | |
| # ansible-lint). This is a readiness GATE only: it never publishes and needs no | |
| # token. Runs only when ansible/ changed. | |
| galaxy-build: | |
| needs: changes | |
| if: needs.changes.outputs.ansible == 'true' | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: ansible | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: '3.12' | |
| - name: Install build + import tooling | |
| run: python -m pip install --upgrade ansible-core ansible-lint galaxy-importer | |
| - name: Vendor collection dependencies | |
| # So galaxy-importer's embedded ansible-lint can resolve the roles' FQCNs | |
| # (devsec.hardening, ansible.posix). Installed under ansible/collections. | |
| run: make deps | |
| env: | |
| ANSIBLE_COLLECTIONS_PATH: collections | |
| - name: Build + validate the decdn.node collection | |
| run: make galaxy-check | |
| env: | |
| ANSIBLE_COLLECTIONS_PATH: collections | |
| - name: Upload collection artifact | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: decdn-node-collection | |
| path: ansible/build/decdn-node-*.tar.gz | |
| if-no-files-found: ignore | |
| # Dedicated IaC security scan of the Ansible tree via the official KICS action. | |
| # KICS severities are HIGH/MEDIUM/LOW/INFO (no "critical"); we gate on HIGH. | |
| # | |
| # SUPPLY-CHAIN NOTE: this action's git tags were hijacked in the March 2026 | |
| # TeamPCP attack (CISA KEV). It has since been remediated — tags restored to | |
| # their legitimate pre-hijack commits and explicit hardening applied (base | |
| # images digest-pinned, workflows SHA-pinned, StepSecurity best practices). We | |
| # pin to the post-remediation hardened HEAD by SHA; the `v2.1.20` *tag* points | |
| # at the older Mar-04 commit that predates the April base-image digest-pinning, | |
| # so we deliberately do NOT use the tag (and Dependabot is told not to bump it | |
| # — see .github/dependabot.yml). Re-verify the SHA before any change. | |
| kics: | |
| needs: changes | |
| if: needs.changes.outputs.ansible == 'true' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: KICS Ansible security scan (fail on HIGH) | |
| # master @ 2026-05-22 "[StepSecurity] Apply security best practices (#157)" | |
| uses: Checkmarx/kics-github-action@7117906d8779ecaf5180f34c4931a774f10d7625 | |
| with: | |
| path: ansible | |
| platform_type: Ansible | |
| exclude_paths: ansible/collections | |
| fail_on: high | |
| output_formats: json,sarif | |
| output_path: kics-results | |
| enable_jobs_summary: true | |
| - name: Upload KICS results | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: kics-results | |
| path: kics-results/ | |
| if-no-files-found: ignore | |
| # To surface KICS findings in the repo's Security tab, enable GitHub code | |
| # scanning (free on public repos) and un-comment the block below (add | |
| # `security-events: write` to this job's permissions): | |
| # - name: Upload SARIF to code scanning | |
| # if: always() | |
| # uses: github/codeql-action/upload-sarif@d77b13a0df3134d64a457ea9003f600b09fa1c8a # v3.36.1 | |
| # with: | |
| # sarif_file: kics-results/results.sarif | |
| # Lint the workflow files themselves. | |
| actionlint: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| checks: write | |
| steps: | |
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: reviewdog/action-actionlint@6fb7acc99f4a1008869fa8a0f09cfca740837d9d # v1.72.0 | |
| with: | |
| reporter: github-check | |
| fail_on_error: true |