Skip to content

Docker & Compose Security Quality Gate for Hacking Lab #16

Description

@donny-devops

Create and wire a reusable GitHub Actions workflow to enforce a Docker security quality gate for hacking-lab workloads.

Scope

  • Add Dockerfile linting with hadolint
  • Add vulnerability scanning with trivy (or grype) for OS + dependency CVEs
  • Validate compose config with docker-compose config --quiet
  • Add secret detection with gitleaks (block plaintext creds / unsafe .env commits)
  • Restrict hacking-lab workflow triggers (manual and/or scoped path filters)

Requirements

  • Reusable workflow file in this repo: .github/workflows/docker-security-gate.yml
  • Inputs:
    • dockerfile-path
    • compose-file-path
    • fail-on-severity (example: CRITICAL)
  • Consumer integration in donny-devops/docker-compose-stacks

Acceptance Criteria

  • Workflow is reusable via workflow_call
  • Security checks fail pipeline at configured severity threshold
  • Compose validation fails on invalid config
  • Gitleaks blocks plaintext credentials in tracked files
  • Trigger strategy minimizes unnecessary runs for lab isolation
  • Actions logs are clean (no bracketed-paste/junk terminal artifacts)

Rollout

  1. Draft reusable template
  2. Run manual vulnerability baseline audit for current lab images
  3. Integrate in docker-compose-stacks
  4. Verify behavior + output cleanliness

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions