Challengejenkins
Jenkins Pipeline: Build, Scan and Push an Image — Challenge
Take a commit to a scanned, tagged image in a registry, with a gate that blocks rather than reports.
- Time
- 27 min
- Level
- Intermediate
- Objectives
- 4 objectives
- Cost
- Free
Before you start
You will need
- Docker
- Jenkins with the Docker Pipeline plugin
- A registry account
You will be able to
- Build a container image from a pipeline without leaking credentials
- Fail a build on a vulnerability rather than logging one
- Tag images so a deployment can be traced to a commit
You are done when
0 of 4
The goal#
Achieve the same outcome as Jenkins Pipeline: Build, Scan and Push an Image, from an empty starting point, without the steps.
The pipeline builds an image and pushes it as latest. Nobody can say which commit is in production, the scan runs after the push, and the registry password is an environment variable in the job configuration.
What must be true when you are done#
- A push produces an image tagged with the short commit SHA in the registry.
- A HIGH or CRITICAL vulnerability fails the build — proven with a deliberately old base image.
- No credential appears in the build log.
- The
latesttag is not what gets deployed, and you can say why.
Rules#
- Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
- Documentation is allowed and encouraged.
- Verify every criterion with a command whose output you can read.
If you get stuck#
- What did you expect, exactly?
- What happened instead — the error text, not a paraphrase?
- Which layer is that error from?
- What is the smallest command that proves the layer below is fine?
The concept behind it
Next up
Lab 45 of 58 on the project path