r/docker • u/Mukul-nst • 2d ago
CI pipeline
I started learning CI/CD using github actions after containerising my application and I have created CI pipeline for django app that runs test, builds and pushes image to github container registry.
I am sharing my yaml file for CI pipeline. Please do share your thoughts and where can i improve.
name: Test Pipeline
on:
push:
jobs:
test-backend:
runs-on: ubuntu-latest
services:
postgres:
image: postgres:14
ports:
- 5432:5432
env:
POSTGRES_USER: test_user
POSTGRES_DB: erp
POSTGRES_PASSWORD: 123456
steps:
- name: Checkout repo
uses: actions/checkout@v4
- name: setup python
uses: actions/setup-python@v5
with:
python-version: "3.13.5"
- name: install dependencies
run: pip install -r Backend/requirement.txt
- name: run tests
env:
DATABASE_URL: postgresql://test_user:123456@localhost:5432/erp
DEBUG: 'True'
ALLOWED_HOST: '*'
run: |
cd Backend
python manage.py test
build-and-push-image:
needs: test-backend
permissions:
contents: read
packages: write
runs-on: ubuntu-latest
steps:
- name: login to ghcr
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: checkout repo
uses: actions/checkout@v4
- name: build image
run: docker build -t ghcr.io/namespace/erp:${{ github.sha }} ./Backend
- name: push image
run: docker push ghcr.io/namespace/erp:${{ github.sha }}
13
Upvotes
1
u/Quirky-Net-6436 2d ago
You should use the sha hash of the actions instead the released versions for improved security. In addition, do you really need to run the whole pipeline on every commit? What if you just changed a readme file or any other location? What about scanning the application on CVEs with for example trivy?
1
u/execmd 2d ago
Why you use so old postgress version? Actual version is 18