You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flask认证应用GitLab CI/CD YML配置求助:测试、SAST及部署阶段

完善Flask认证应用的GitLab CI/CD流水线配置

核心问题定位

SAST阶段的docker: command not found错误,是因为你使用的python:3.8-slim-buster镜像未预装Docker客户端,且在容器内嵌套运行Docker需要完整的Docker环境,这不是最优方案。下面分阶段给出修正后的配置:


1. Test 阶段完善

假设你的项目使用pytest作为测试框架,以下配置会安装依赖、缓存依赖以加速构建,并执行测试:

test:
  stage: test
  image: python:3.8-slim-buster
  cache:
    paths:
      - venv/
  before_script:
    - python -m venv venv
    - source venv/bin/activate
    - pip install -r requirements.txt
    # 若requirements.txt未包含pytest,需安装测试依赖
    - pip install pytest
  script:
    - echo "Running unit tests..."
    - pytest tests/ --cov=app --cov-report=term  # 替换为你的测试目录和参数
  artifacts:
    reports:
      junit: pytest.xml  # 生成测试报告,GitLab会在流水线页面展示

2. SAST(SonarQube检测)阶段修复

放弃在Python镜像里嵌套Docker的方式,直接使用SonarSource官方的sonar-scanner-cli镜像,更简洁且无需额外配置Docker:

sonarqube-check:
  stage: sast
  image: sonarsource/sonar-scanner-cli:latest
  cache:
    paths:
      - .sonar/cache  # 缓存SonarQube扫描数据,加速后续构建
  variables:
    SONAR_PROJECT_KEY: "${CI_PROJECT_NAME}"  # 用GitLab项目名作为SonarQube项目Key
    SONAR_PROJECT_NAME: "${CI_PROJECT_NAME}"
  script:
    - sonar-scanner
      -Dsonar.host.url=${SONAR_HOST_URL}
      -Dsonar.login=${SONAR_TOKEN}
      -Dsonar.projectKey=${SONAR_PROJECT_KEY}
      -Dsonar.projectName=${SONAR_PROJECT_NAME}
      -Dsonar.sources=.  # 指定要扫描的代码目录
      -Dsonar.python.version=3.8  # 指定项目使用的Python版本

注意:需确保SonarQube服务器与GitLab Runner处于同一网络(比如你的SONAR_HOST_URL配置http://sonarqube:9000,要确认Runner能访问这个地址)。


3. Deploy 阶段完善

Deploy阶段需要Docker和docker-compose,因此使用docker:latest镜像并配合docker:dind服务,同时安装docker-compose:

deploy:
  stage: deploy
  image: docker:latest
  services:
    - docker:dind
  before_script:
    # 安装docker-compose
    - apk add --no-cache docker-compose
    # 若需要拉取/推送私有镜像,可添加登录步骤
    # - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY
  script:
    - echo "Starting deployment with Docker Compose..."
    - docker-compose up -d
  only:
    - main  # 仅在main分支触发部署,可根据需求修改分支名

完整的修正后YAML配置

stages:
  - build
  - test
  - sast
  - deploy

variables:
  SONAR_TOKEN: "squ_1b804d297730d729fd6b7f90f019b33fdb2c2afe"
  SONAR_HOST_URL: "http://sonarqube:9000"  # 确认SonarQube与Runner网络连通

build:
  stage: build
  image: python:3.8-slim-buster
  cache:
    paths:
      - venv/
  script:
    - apt-get update -q -y
    - apt-get install -y python3-venv
    - python -m venv venv
    - source venv/bin/activate
    - pip install -r requirements.txt
    - echo "Build completed successfully"

test:
  stage: test
  image: python:3.8-slim-buster
  cache:
    paths:
      - venv/
  before_script:
    - source venv/bin/activate
    - pip install pytest  # 若requirements已包含可省略
  script:
    - pytest tests/ --cov=app --cov-report=term
  artifacts:
    reports:
      junit: pytest.xml

sonarqube-check:
  stage: sast
  image: sonarsource/sonar-scanner-cli:latest
  cache:
    paths:
      - .sonar/cache
  variables:
    SONAR_PROJECT_KEY: "${CI_PROJECT_NAME}"
    SONAR_PROJECT_NAME: "${CI_PROJECT_NAME}"
  script:
    - sonar-scanner
      -Dsonar.host.url=${SONAR_HOST_URL}
      -Dsonar.login=${SONAR_TOKEN}
      -Dsonar.projectKey=${SONAR_PROJECT_KEY}
      -Dsonar.projectName=${SONAR_PROJECT_NAME}
      -Dsonar.sources=.
      -Dsonar.python.version=3.8

deploy:
  stage: deploy
  image: docker:latest
  services:
    - docker:dind
  before_script:
    - apk add --no-cache docker-compose
  script:
    - docker-compose up -d
  only:
    - main

内容的提问来源于stack exchange,提问作者Carlos

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 16:28:13