Skip to content

Jenkins & Azure Pipelines

Jenkins (declarative)

Jenkinsfile
pipeline {
  agent { label 'linux && docker' }
  environment {
    PPEE_CLI = "docker run --rm -v ${env.WORKSPACE}:${env.WORKSPACE}:ro -w ${env.WORKSPACE} registry.example.com/ppee-cli:2.0.0"
  }
  stages {
    stage('Fetch artifacts') {
      steps { copyArtifacts projectName: 'myapp-windows-build', target: 'dist' }
    }
    stage('PE gate') {
      steps {
        sh './ci/ppee-policy.sh --require-signature --require-hardening --forbid-wx --report ppee-report.jsonl dist/*.exe dist/*.dll'
      }
    }
  }
  post {
    always { archiveArtifacts artifacts: 'ppee-report.jsonl', allowEmptyArchive: true }
  }
}

On a Windows agent, call ppee-cli.exe directly and use PowerShell with ConvertFrom-Json, as in the GitHub Actions Windows example.

Azure Pipelines

azure-pipelines.yml
trigger: [main]

stages:
  - stage: Inspect
    jobs:
      - job: PeGate
        pool: { vmImage: ubuntu-latest }
        steps:
          - download: current
            artifact: dist
          - bash: |
              export PPEE_CLI="docker run --rm -v $PWD:$PWD:ro -w $PWD myregistry.azurecr.io/ppee-cli:2.0.0"
              ./ci/ppee-policy.sh --require-hardening --forbid-wx \
                --report $(Build.ArtifactStagingDirectory)/ppee-report.jsonl \
                $(Pipeline.Workspace)/dist/*.exe
            displayName: PPEE policy gate
          - publish: $(Build.ArtifactStagingDirectory)/ppee-report.jsonl
            artifact: ppee-report
            condition: always()

      - job: VerifySignatures
        pool: { vmImage: windows-latest }
        steps:
          - download: current
            artifact: dist
          - pwsh: |
              Get-ChildItem "$(Pipeline.Workspace)/dist" -Include *.exe,*.dll -Recurse | ForEach-Object {
                $j = & "$(Build.SourcesDirectory)/tools/ppee-cli.exe" --no-update-check --no-similarity --json --security $_.FullName | ConvertFrom-Json
                if ($j.security.validity.result -ne 'SIGNED & VERIFIED') {
                  Write-Host "##vso[task.logissue type=error]$($_.Name): $($j.security.validity.result)"; $script:bad = 1 }
              }
              exit [int]$script:bad
            displayName: WinVerifyTrust check

The Docker job container on Azure and Jenkins

As with GitLab, the ppee-cli image's entry point is ppee-cli, so it doesn't suit a container job image. Use docker run from the agent (as above) or the helper image from GitLab Option A.

References