Create and wire a reusable GitHub Actions workflow to enforce a Docker security quality gate for hacking-lab workloads.
Scope
- Add Dockerfile linting with hadolint
- Add vulnerability scanning with trivy (or grype) for OS + dependency CVEs
- Validate compose config with
docker-compose config --quiet
- Add secret detection with gitleaks (block plaintext creds / unsafe
.env commits)
- Restrict hacking-lab workflow triggers (manual and/or scoped path filters)
Requirements
- Reusable workflow file in this repo:
.github/workflows/docker-security-gate.yml
- Inputs:
dockerfile-path
compose-file-path
fail-on-severity (example: CRITICAL)
- Consumer integration in
donny-devops/docker-compose-stacks
Acceptance Criteria
- Workflow is reusable via
workflow_call
- Security checks fail pipeline at configured severity threshold
- Compose validation fails on invalid config
- Gitleaks blocks plaintext credentials in tracked files
- Trigger strategy minimizes unnecessary runs for lab isolation
- Actions logs are clean (no bracketed-paste/junk terminal artifacts)
Rollout
- Draft reusable template
- Run manual vulnerability baseline audit for current lab images
- Integrate in
docker-compose-stacks
- Verify behavior + output cleanliness
Create and wire a reusable GitHub Actions workflow to enforce a Docker security quality gate for hacking-lab workloads.
Scope
docker-compose config --quiet.envcommits)Requirements
.github/workflows/docker-security-gate.ymldockerfile-pathcompose-file-pathfail-on-severity(example:CRITICAL)donny-devops/docker-compose-stacksAcceptance Criteria
workflow_callRollout
docker-compose-stacks