Flask认证应用GitLab CI/CD YML配置求助:测试、SAST及部署阶段
完善Flask认证应用的GitLab CI/CD流水线配置
核心问题定位
SAST阶段的docker: command not found错误,是因为你使用的python:3.8-slim-buster镜像未预装Docker客户端,且在容器内嵌套运行Docker需要完整的Docker环境,这不是最优方案。下面分阶段给出修正后的配置:
1. Test 阶段完善
假设你的项目使用pytest作为测试框架,以下配置会安装依赖、缓存依赖以加速构建,并执行测试:
test: stage: test image: python:3.8-slim-buster cache: paths: - venv/ before_script: - python -m venv venv - source venv/bin/activate - pip install -r requirements.txt # 若requirements.txt未包含pytest,需安装测试依赖 - pip install pytest script: - echo "Running unit tests..." - pytest tests/ --cov=app --cov-report=term # 替换为你的测试目录和参数 artifacts: reports: junit: pytest.xml # 生成测试报告,GitLab会在流水线页面展示
2. SAST(SonarQube检测)阶段修复
放弃在Python镜像里嵌套Docker的方式,直接使用SonarSource官方的sonar-scanner-cli镜像,更简洁且无需额外配置Docker:
sonarqube-check: stage: sast image: sonarsource/sonar-scanner-cli:latest cache: paths: - .sonar/cache # 缓存SonarQube扫描数据,加速后续构建 variables: SONAR_PROJECT_KEY: "${CI_PROJECT_NAME}" # 用GitLab项目名作为SonarQube项目Key SONAR_PROJECT_NAME: "${CI_PROJECT_NAME}" script: - sonar-scanner -Dsonar.host.url=${SONAR_HOST_URL} -Dsonar.login=${SONAR_TOKEN} -Dsonar.projectKey=${SONAR_PROJECT_KEY} -Dsonar.projectName=${SONAR_PROJECT_NAME} -Dsonar.sources=. # 指定要扫描的代码目录 -Dsonar.python.version=3.8 # 指定项目使用的Python版本
注意:需确保SonarQube服务器与GitLab Runner处于同一网络(比如你的
SONAR_HOST_URL配置http://sonarqube:9000,要确认Runner能访问这个地址)。
3. Deploy 阶段完善
Deploy阶段需要Docker和docker-compose,因此使用docker:latest镜像并配合docker:dind服务,同时安装docker-compose:
deploy: stage: deploy image: docker:latest services: - docker:dind before_script: # 安装docker-compose - apk add --no-cache docker-compose # 若需要拉取/推送私有镜像,可添加登录步骤 # - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY script: - echo "Starting deployment with Docker Compose..." - docker-compose up -d only: - main # 仅在main分支触发部署,可根据需求修改分支名
完整的修正后YAML配置
stages: - build - test - sast - deploy variables: SONAR_TOKEN: "squ_1b804d297730d729fd6b7f90f019b33fdb2c2afe" SONAR_HOST_URL: "http://sonarqube:9000" # 确认SonarQube与Runner网络连通 build: stage: build image: python:3.8-slim-buster cache: paths: - venv/ script: - apt-get update -q -y - apt-get install -y python3-venv - python -m venv venv - source venv/bin/activate - pip install -r requirements.txt - echo "Build completed successfully" test: stage: test image: python:3.8-slim-buster cache: paths: - venv/ before_script: - source venv/bin/activate - pip install pytest # 若requirements已包含可省略 script: - pytest tests/ --cov=app --cov-report=term artifacts: reports: junit: pytest.xml sonarqube-check: stage: sast image: sonarsource/sonar-scanner-cli:latest cache: paths: - .sonar/cache variables: SONAR_PROJECT_KEY: "${CI_PROJECT_NAME}" SONAR_PROJECT_NAME: "${CI_PROJECT_NAME}" script: - sonar-scanner -Dsonar.host.url=${SONAR_HOST_URL} -Dsonar.login=${SONAR_TOKEN} -Dsonar.projectKey=${SONAR_PROJECT_KEY} -Dsonar.projectName=${SONAR_PROJECT_NAME} -Dsonar.sources=. -Dsonar.python.version=3.8 deploy: stage: deploy image: docker:latest services: - docker:dind before_script: - apk add --no-cache docker-compose script: - docker-compose up -d only: - main
内容的提问来源于stack exchange,提问作者Carlos
相关产品推荐
相关产品推荐

