GitLab - Build enterprise-grade IaC pipelines with GitLab DevSecOps](https://about.gitlab.com/blog/using-ansible-and-gitlab-as-infrastructure-for-code/)
GitLab Docs - Tutorial: Create a complex pipeline](https://docs.gitlab.com/ee/ci/quick_start/tutorial.html)
Reddit - IAC with Gitlab and Ansible: how to create a CI/CD ...](https://www.reddit.com/r/ansible/comments/ptf2in/iac_with_gitlab_and_ansible_how_to_create_a_cicd/)
https://www.google.com/search?q=googleusercontent.com - Using GitLab CI, Terraform, and Ansible to Automate ...](https://www.youtube.com/watch?v=zAe4Me43Kbc)
bookbaker.com - Integrating Ansible with CI/CD Pipelines](https://www.bookbaker.com/en/v/Mastering-Ansible-Advanced-System-Automation-Integrating-Ansible-with-CI-CD-Pipelines/8a7d5b28-01e2-4e4b-8f34-94e3752c799e/10)
Medium - Day 26: Integrating Ansible with CI/CD Pipelines](https://medium.com/@vinoji2005/day-26-integrating-ansible-with-ci-cd-pipelines-284637f83ba2)
stages: # Defines the execution order of jobs in your GitLab CI/CD pipeline
- build # This stage is for compiling and packaging your application.
- test-static # This stage focuses on static code analysis to identify potential issues without executing the code.
- test-dynamic # This stage involves running dynamic application security tests against a running instance of your application.
- infrastructure-hardening # This stage uses Ansible to automate the security configuration of your infrastructure [1](https://about.gitlab.com/blog/2019/07/01/using-ansible-and-gitlab-as-infrastructure-for-code/).
build: # This job belongs to the build stage.
stage: build # Explicitly declares the stage for this job.
script: # Contains the commands to execute.
- echo Building the application... # Prints a message.
- # Build application code and create artifacts # Executes commands to compile the application and generate necessary artifacts.
test-static: # This job belongs to the test-static stage.
stage: test-static # Explicitly declares the stage.
script: # Contains commands for static analysis.
- echo Running static code analysis... # Prints a message.
- # Run static analysis tools like SonarQube or linters # Executes static code analysis tools such as SonarQube or linters to identify code quality and security issues.
test-dynamic: # This job belongs to the test-dynamic stage.
stage: test-dynamic # Explicitly declares the stage.
script: # Contains commands for DAST.
- echo Running dynamic application security testing (DAST)... # Prints a message.
- # Execute DAST tools like OWASP ZAP against the deployed application # Executes dynamic application security testing tools, such as OWASP ZAP, against a running application to find vulnerabilities.
infrastructure-hardening: # This job belongs to the infrastructure-hardening stage.
stage: infrastructure-hardening # Explicitly declares the stage.
image: ansible/ansible # Specifies the Docker image to use, pre-loaded with Ansible.
script: # Contains Ansible commands.
- echo Running Ansible playbooks for infrastructure hardening... # Prints a message.
- ansible-playbook -i inventory.ini security_hardening.yml # Executes the Ansible playbook security_hardening.yml using the inventory file inventory.ini.
dependencies: # Specifies that this job will only run after the test-dynamic job has successfully completed.
- test-dynamic
The stages section defines the execution order of jobs in your GitLab CI/CD pipeline. Each item under stages represents a distinct phase.
- build: This stage is for compiling and packaging your application.
- test-static: This stage focuses on static code analysis to identify potential issues without executing the code.
- test-dynamic: This stage involves running dynamic application security tests against a running instance of your application.
- infrastructure-hardening: This stage uses Ansible to automate the security configuration of your infrastructure 1.
The subsequent sections define individual jobs within these stages.
build: This job belongs to the build stage.
stage: build: Explicitly declares the stage for this job.
script: Contains the commands to execute.
- echo Building the application...: Prints a message.
- # Build application code and create artifacts: Rewritten comment: Executes commands to compile the application and generate necessary artifacts.
test-static: This job belongs to the test-static stage.
stage: test-static: Explicitly declares the stage.
script: Contains commands for static analysis.
- echo Running static code analysis...: Prints a message.
- # Run static analysis tools like SonarQube or linters: Rewritten comment: Executes static code analysis tools such as SonarQube or linters to identify code quality and security issues.
test-dynamic: This job belongs to the test-dynamic stage.
stage: test-dynamic: Explicitly declares the stage.
script: Contains commands for DAST.
- echo Running dynamic application security testing (DAST)...: Prints a message.
- # Execute DAST tools like OWASP ZAP against the deployed application: Rewritten comment: Executes dynamic application security testing tools, such as OWASP ZAP, against a running application to find vulnerabilities.
infrastructure-hardening: This job belongs to the infrastructure-hardening stage.
stage: infrastructure-hardening: Explicitly declares the stage.
image: ansible/ansible: Specifies the Docker image to use, pre-loaded with Ansible.
script: Contains Ansible commands.
- echo Running Ansible playbooks for infrastructure hardening...: Prints a message.
- ansible-playbook -i inventory.ini security_hardening.yml: Executes the Ansible playbook security_hardening.yml using the inventory file inventory.ini.
dependencies: Specifies that this job will only run after the test-dynamic job has successfully completed.