feat(build): revamp app build pipeline (queue, Nixpacks, MinIO, Trivy, registry GC)

Rework the application build/deploy pipeline for scalability, reproducibility,
and security:

- Build queue: deploys run through a bounded-concurrency Bull queue
  (BUILD_CONCURRENCY, default 3) so concurrent user deploys can't flood the
  cluster with Kaniko jobs. Build state (progress / cancel / session) moves from
  in-memory Maps to Redis, so cancel + live logs work across backend replicas.
- Nixpacks + BYO Dockerfile: code runtimes build via Nixpacks (or the user's own
  Dockerfile when present); the hand-written per-runtime Dockerfile generators
  and runtime auto-detection are removed. WordPress keeps its templated path.
  Build-time mirror env (NIXPACKS_BUILD_ENV) supports the Iran network.
- Source upload to MinIO: archives stream to in-cluster MinIO; build pods pull
  via a presigned URL. Removes the PVC + helper pod + kubectl cp upload path.
- Report-only Trivy scan after build; per-severity summary stored on the
  deployment and shown as a badge in the dashboard. Never gates a deploy.
- Registry GC: a Redis-locked daily job keeps the newest N image tags per app
  (REGISTRY_KEEP_VERSIONS, default 3) and reclaims disk via garbage-collect.
- Hardening: git tokens are delivered via a per-build Secret + git credential
  store instead of being embedded in the clone URL / Job manifest; build timeout
  is configurable.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
keyhan
2026-06-20 22:58:58 +03:30
parent 49726f1dfd
commit 3eff38f8d2
27 changed files with 1950 additions and 1295 deletions
@@ -0,0 +1,40 @@
import { ShieldCheck, ShieldAlert } from 'lucide-react';
import type { VulnerabilitySummary } from '@/types';
/**
* Compact, report-only image-scan badge (Trivy). Renders nothing when there is
* no scan data yet. Shows a green "clean" pill, or the count of the highest
* severities found. Title carries the full per-severity breakdown.
*/
export function VulnerabilityBadge({ summary }: { summary?: VulnerabilitySummary | null }) {
if (!summary) return null;
const { critical, high, medium, low, total } = summary;
const breakdown = `Critical ${critical} · High ${high} · Medium ${medium} · Low ${low}`;
if (total === 0) {
return (
<span
className="inline-flex items-center gap-1 text-[11px] font-medium text-green-700 bg-green-50 border border-green-200 rounded-full px-2 py-0.5"
title={breakdown}
>
<ShieldCheck className="w-3 h-3" /> 0 CVE
</span>
);
}
const severe = critical > 0 || high > 0;
const cls = severe
? 'text-red-700 bg-red-50 border-red-200'
: 'text-amber-700 bg-amber-50 border-amber-200';
const label = severe ? `${critical}C / ${high}H` : `${medium}M / ${low}L`;
return (
<span
className={`inline-flex items-center gap-1 text-[11px] font-medium border rounded-full px-2 py-0.5 ${cls}`}
title={breakdown}
>
<ShieldAlert className="w-3 h-3" /> {label}
</span>
);
}