feat(build): revamp app build pipeline (queue, Nixpacks, MinIO, Trivy, registry GC)
Rework the application build/deploy pipeline for scalability, reproducibility, and security: - Build queue: deploys run through a bounded-concurrency Bull queue (BUILD_CONCURRENCY, default 3) so concurrent user deploys can't flood the cluster with Kaniko jobs. Build state (progress / cancel / session) moves from in-memory Maps to Redis, so cancel + live logs work across backend replicas. - Nixpacks + BYO Dockerfile: code runtimes build via Nixpacks (or the user's own Dockerfile when present); the hand-written per-runtime Dockerfile generators and runtime auto-detection are removed. WordPress keeps its templated path. Build-time mirror env (NIXPACKS_BUILD_ENV) supports the Iran network. - Source upload to MinIO: archives stream to in-cluster MinIO; build pods pull via a presigned URL. Removes the PVC + helper pod + kubectl cp upload path. - Report-only Trivy scan after build; per-severity summary stored on the deployment and shown as a badge in the dashboard. Never gates a deploy. - Registry GC: a Redis-locked daily job keeps the newest N image tags per app (REGISTRY_KEEP_VERSIONS, default 3) and reclaims disk via garbage-collect. - Hardening: git tokens are delivered via a per-build Secret + git credential store instead of being embedded in the clone URL / Job manifest; build timeout is configurable. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -12,6 +12,7 @@ import { useLocalizedRouter } from '@/i18n/navigation';
|
||||
import { Hexagon, Rocket, Play, Square, RotateCw, Globe, Package, Server, Scale, CheckCircle, Clock, XCircle, AlertCircle, Link, GitBranch, KeyRound, FolderUp, BarChart3, ChevronDown, FileText, Monitor, Hammer, Settings, RefreshCw, Upload, Circle, Pin, Database, Eye, EyeOff, Copy, Check, History, Download, RotateCcw, Camera, Trash2, Archive, Zap, Wallet, CreditCard, AlertTriangle, ScrollText } from 'lucide-react';
|
||||
import { ServiceExternalAccessPanel } from '@/components/service-external-access-panel';
|
||||
import { WorkloadLogsPanel } from '@/components/workload-logs-panel';
|
||||
import { VulnerabilityBadge } from '@/components/vulnerability-badge';
|
||||
import { DeletingModal } from '@/components/deleting-modal';
|
||||
import { useApplicationDelete } from '@/lib/use-application-delete';
|
||||
import { isApplicationProduct, isManagedProduct } from '@/lib/product-type';
|
||||
@@ -1510,7 +1511,10 @@ export default function AppDetailPage() {
|
||||
{deployments.slice(0, 10).map((d) => (
|
||||
<div key={d.id} className="flex items-center justify-between p-3 bg-gray-50/80 rounded-xl">
|
||||
<div className="min-w-0 flex-1">
|
||||
<p className="text-sm font-medium text-gray-900 truncate">{d.version || d.imageTag}</p>
|
||||
<div className="flex items-center gap-2">
|
||||
<p className="text-sm font-medium text-gray-900 truncate">{d.version || d.imageTag}</p>
|
||||
<VulnerabilityBadge summary={d.vulnerabilitySummary} />
|
||||
</div>
|
||||
<p className="text-xs text-gray-500">
|
||||
{new Date(d.createdAt).toLocaleString(locale)}
|
||||
</p>
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
import { ShieldCheck, ShieldAlert } from 'lucide-react';
|
||||
import type { VulnerabilitySummary } from '@/types';
|
||||
|
||||
/**
|
||||
* Compact, report-only image-scan badge (Trivy). Renders nothing when there is
|
||||
* no scan data yet. Shows a green "clean" pill, or the count of the highest
|
||||
* severities found. Title carries the full per-severity breakdown.
|
||||
*/
|
||||
export function VulnerabilityBadge({ summary }: { summary?: VulnerabilitySummary | null }) {
|
||||
if (!summary) return null;
|
||||
|
||||
const { critical, high, medium, low, total } = summary;
|
||||
const breakdown = `Critical ${critical} · High ${high} · Medium ${medium} · Low ${low}`;
|
||||
|
||||
if (total === 0) {
|
||||
return (
|
||||
<span
|
||||
className="inline-flex items-center gap-1 text-[11px] font-medium text-green-700 bg-green-50 border border-green-200 rounded-full px-2 py-0.5"
|
||||
title={breakdown}
|
||||
>
|
||||
<ShieldCheck className="w-3 h-3" /> 0 CVE
|
||||
</span>
|
||||
);
|
||||
}
|
||||
|
||||
const severe = critical > 0 || high > 0;
|
||||
const cls = severe
|
||||
? 'text-red-700 bg-red-50 border-red-200'
|
||||
: 'text-amber-700 bg-amber-50 border-amber-200';
|
||||
const label = severe ? `${critical}C / ${high}H` : `${medium}M / ${low}L`;
|
||||
|
||||
return (
|
||||
<span
|
||||
className={`inline-flex items-center gap-1 text-[11px] font-medium border rounded-full px-2 py-0.5 ${cls}`}
|
||||
title={breakdown}
|
||||
>
|
||||
<ShieldAlert className="w-3 h-3" /> {label}
|
||||
</span>
|
||||
);
|
||||
}
|
||||
@@ -159,6 +159,17 @@ export interface Deployment {
|
||||
triggeredBy: string;
|
||||
createdAt: string;
|
||||
finishedAt?: string;
|
||||
vulnerabilitySummary?: VulnerabilitySummary | null;
|
||||
}
|
||||
|
||||
export interface VulnerabilitySummary {
|
||||
critical: number;
|
||||
high: number;
|
||||
medium: number;
|
||||
low: number;
|
||||
unknown: number;
|
||||
total: number;
|
||||
scannedAt: string;
|
||||
}
|
||||
|
||||
export type DeploymentStatus =
|
||||
|
||||
Reference in New Issue
Block a user