Jenkins & Azure Pipelines¶
Jenkins (declarative)¶
Jenkinsfile
pipeline {
agent { label 'linux && docker' }
environment {
PPEE_CLI = "docker run --rm -v ${env.WORKSPACE}:${env.WORKSPACE}:ro -w ${env.WORKSPACE} registry.example.com/ppee-cli:2.0.0"
}
stages {
stage('Fetch artifacts') {
steps { copyArtifacts projectName: 'myapp-windows-build', target: 'dist' }
}
stage('PE gate') {
steps {
sh './ci/ppee-policy.sh --require-signature --require-hardening --forbid-wx --report ppee-report.jsonl dist/*.exe dist/*.dll'
}
}
}
post {
always { archiveArtifacts artifacts: 'ppee-report.jsonl', allowEmptyArchive: true }
}
}
On a Windows agent, call ppee-cli.exe directly and use PowerShell with ConvertFrom-Json, as in the GitHub Actions Windows example.
Azure Pipelines¶
azure-pipelines.yml
trigger: [main]
stages:
- stage: Inspect
jobs:
- job: PeGate
pool: { vmImage: ubuntu-latest }
steps:
- download: current
artifact: dist
- bash: |
export PPEE_CLI="docker run --rm -v $PWD:$PWD:ro -w $PWD myregistry.azurecr.io/ppee-cli:2.0.0"
./ci/ppee-policy.sh --require-hardening --forbid-wx \
--report $(Build.ArtifactStagingDirectory)/ppee-report.jsonl \
$(Pipeline.Workspace)/dist/*.exe
displayName: PPEE policy gate
- publish: $(Build.ArtifactStagingDirectory)/ppee-report.jsonl
artifact: ppee-report
condition: always()
- job: VerifySignatures
pool: { vmImage: windows-latest }
steps:
- download: current
artifact: dist
- pwsh: |
Get-ChildItem "$(Pipeline.Workspace)/dist" -Include *.exe,*.dll -Recurse | ForEach-Object {
$j = & "$(Build.SourcesDirectory)/tools/ppee-cli.exe" --no-update-check --no-similarity --json --security $_.FullName | ConvertFrom-Json
if ($j.security.validity.result -ne 'SIGNED & VERIFIED') {
Write-Host "##vso[task.logissue type=error]$($_.Name): $($j.security.validity.result)"; $script:bad = 1 }
}
exit [int]$script:bad
displayName: WinVerifyTrust check
The Docker job container on Azure and Jenkins
As with GitLab, the ppee-cli image's entry point is ppee-cli, so it doesn't suit a container job image. Use docker run from the agent (as above) or the helper image from GitLab Option A.
References¶
- Pipeline (Jenkins): declarative and scripted Jenkinsfiles.
- YAML schema reference (Azure Pipelines): every key used in azure-pipelines.yml.