Skip to content

Merge pull request #3746 from bcgov/NDT-495-Delete-your-own-GCPE-report #10404

Merge pull request #3746 from bcgov/NDT-495-Delete-your-own-GCPE-report

Merge pull request #3746 from bcgov/NDT-495-Delete-your-own-GCPE-report #10404

Triggered via push January 2, 2025 21:02
Status Success
Total duration 53m 59s
Artifacts 5

main.yaml

on: push
Matrix: build / build-and-push-image
install-env  /  install-test-env
1m 4s
install-env / install-test-env
is-tagged-release
26s
is-tagged-release
test-checks  /  trivy-scan-code
31s
test-checks / trivy-scan-code
test-checks  /  cocogitto
28s
test-checks / cocogitto
test-checks  /  gitleaks
29s
test-checks / gitleaks
test-checks  /  check_immutable_sqitch_files
26s
test-checks / check_immutable_sqitch_files
test-checks  /  check_deleted_sqitch_tags
33s
test-checks / check_deleted_sqitch_tags
rebase-feature-pr
49s
rebase-feature-pr
Matrix: test-checks / codeql-scan
setup-s3-backup  /  deploy-s3-secret-to-dev
26s
setup-s3-backup / deploy-s3-secret-to-dev
setup-s3-backup  /  deploy-s3-secret-to-test
19s
setup-s3-backup / deploy-s3-secret-to-test
setup-s3-backup  /  deploy-s3-secret-to-prod
16s
setup-s3-backup / deploy-s3-secret-to-prod
has-merge-conflict  /  check_merge_conflicts
32s
has-merge-conflict / check_merge_conflicts
cleanup_feature  /  clean-feature-env
cleanup_feature / clean-feature-env
test-checks  /  lint-chart
21s
test-checks / lint-chart
deploy-feature  /  setup-feature-database
deploy-feature / setup-feature-database
test-containers  /  trivy-scan-app
1m 51s
test-containers / trivy-scan-app
test-containers  /  trivy-scan-db
31s
test-containers / trivy-scan-db
test-e2e  /  yarn-test-e2e-applicant
4m 44s
test-e2e / yarn-test-e2e-applicant
test-e2e  /  yarn-test-e2e-admin
3m 29s
test-e2e / yarn-test-e2e-admin
test-e2e  /  yarn-test-e2e-analyst
8m 57s
test-e2e / yarn-test-e2e-analyst
test-zap  /  zap-owasp-full
6m 20s
test-zap / zap-owasp-full
ensure-sqitch-plan-ends-with-tag
4s
ensure-sqitch-plan-ends-with-tag
deploy-feature  /  deploy-feature-to-openshift-development
deploy-feature / deploy-feature-to-openshift-development
test-containers  /  renovate
41s
test-containers / renovate
test-e2e  /  yarn-test-e2e-finalize
1m 15s
test-e2e / yarn-test-e2e-finalize
deploy-feature  /  update-jira-issue
deploy-feature / update-jira-issue
deploy  /  is-tagged-release
28s
deploy / is-tagged-release
deploy  /  deploy-to-openshift-development
30s
deploy / deploy-to-openshift-development
deploy  /  ensure-sqitch-plan-ends-with-tag
5s
deploy / ensure-sqitch-plan-ends-with-tag
deploy  /  ...  /  export-secrets
24s
deploy / backup-secrets-dev / export-secrets
deploy  /  deploy-to-openshift-test
5m 11s
deploy / deploy-to-openshift-test
deploy  /  deploy-to-openshift-production
2m 49s
deploy / deploy-to-openshift-production
deploy  /  ...  /  export-secrets
17s
deploy / backup-secrets-test / export-secrets
deploy  /  ...  /  export-secrets
23s
deploy / backup-secrets-prod / export-secrets
deploy  /  create-release
33s
deploy / create-release
deploy  /  ...  /  create_hotfix_branch
1m 7s
deploy / create_hotfix_branch / create_hotfix_branch
Fit to window
Zoom out
Zoom in

Deployment protection rules

Reviewers, timers, and other rules protecting deployments in this run
Event Environments Comment
MarsRomer
approved Jan 2, 2025
production
MarsRomer
approved Jan 2, 2025
production

Annotations

51 warnings
setup-s3-backup / deploy-s3-secret-to-prod
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
setup-s3-backup / deploy-s3-secret-to-test
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
test-checks / lint-chart
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / lint-chart
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
setup-s3-backup / deploy-s3-secret-to-dev
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
is-tagged-release
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / check_immutable_sqitch_files
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / cocogitto
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / gitleaks
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
build / db
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / trivy-scan-code
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
ensure-sqitch-plan-ends-with-tag
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / check_deleted_sqitch_tags
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
build / cron-shp
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
build / cron-sp
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
has-merge-conflict / check_merge_conflicts
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
rebase-feature-pr
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
install-env / install-test-env
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-code / eslint
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-code / schema
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-code / pgtap
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-checks / codeql-scan (javascript, linux)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-code / reverts
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
build / app
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Sensitive data should not be used in the ARG or ENV commands: app/Dockerfile#L20
SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "SENTRY_AUTH_TOKEN") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
Sensitive data should not be used in the ARG or ENV commands: app/Dockerfile#L21
SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "SENTRY_AUTH_TOKEN") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
SonarScanner
This action is deprecated and will be removed in a future release. Please use the sonarqube-scan-action action instead. The sonarqube-scan-action is a drop-in replacement for this action.
test-containers / trivy-scan-db
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-containers / trivy-scan-app
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-containers / renovate
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / is-tagged-release
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / deploy-to-openshift-development
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
deploy / deploy-to-openshift-development
Unexpected input(s) 'openshift_app_namespace', 'openshift_metabase_namespace', 'openshift_metabase_prod_namespace', 'next_public_growthbook_api_key', 'aws_s3_bucket', 'aws_s3_region', 'aws_s3_key', 'aws_s3_secret_key', 'aws_role_arn', 'aws_clam_s3_bucket', 'metabase_site_url', 'metabase_embed_secret', 'cert', 'cert_key', 'cert_ca', 'pgbackrest_s3_bucket', 'session_secret', valid inputs are ['openshift_server_url', 'openshift_token', 'openshift_username', 'openshift_password', 'insecure_skip_tls_verify', 'certificate_authority_data', 'namespace', 'reveal_cluster_name']
deploy / deploy-to-openshift-development
Unexpected input(s) 'keycloak_host', 'sa_client_secret', 'sa_client_id', 'pgbackrest_s3_key', 'pgbackrest_s3_key_secret', valid inputs are ['openshift_server_url', 'openshift_token', 'openshift_app_namespace', 'openshift_metabase_namespace', 'openshift_metabase_prod_namespace', 'tag', 'client_secret', 'secure_route', 'next_public_growthbook_api_key', 'aws_s3_bucket', 'aws_clam_s3_bucket', 'aws_s3_region', 'aws_s3_key', 'aws_s3_secret_key', 'aws_role_arn', 'certbot_email', 'certbot_server', 'environment', 'enable_load_test', 'metabase_site_url', 'metabase_embed_secret', 'cert', 'cert_key', 'cert_ca', 'sp_sa_user', 'sp_sa_password', 'sp_site', 'sp_doc_library', 'sp_ms_file_name', 'sp_list_name', 'ches_url', 'ches_client', 'ches_client_secret', 'ches_to', 'ches_keycloak_host', 'pgbackrest_s3_bucket', 'er_file', 'rd_file', 'coverages_file', 'session_secret']
deploy / ensure-sqitch-plan-ends-with-tag
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-e2e / yarn-test-e2e-admin
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / backup-secrets-dev / export-secrets
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-e2e / yarn-test-e2e-applicant
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-zap / zap-owasp-full
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / deploy-to-openshift-test
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
deploy / deploy-to-openshift-test
Unexpected input(s) 'openshift_app_namespace', 'openshift_metabase_namespace', 'openshift_metabase_prod_namespace', 'next_public_growthbook_api_key', 'aws_s3_bucket', 'aws_s3_region', 'aws_s3_key', 'aws_s3_secret_key', 'aws_role_arn', 'aws_clam_s3_bucket', 'metabase_site_url', 'metabase_embed_secret', 'cert', 'cert_key', 'cert_ca', 'pgbackrest_s3_bucket', 'session_secret', valid inputs are ['openshift_server_url', 'openshift_token', 'openshift_username', 'openshift_password', 'insecure_skip_tls_verify', 'certificate_authority_data', 'namespace', 'reveal_cluster_name']
deploy / deploy-to-openshift-test
Unexpected input(s) 'keycloak_host', 'sa_client_secret', 'sa_client_id', valid inputs are ['openshift_server_url', 'openshift_token', 'openshift_app_namespace', 'openshift_metabase_namespace', 'openshift_metabase_prod_namespace', 'tag', 'client_secret', 'secure_route', 'next_public_growthbook_api_key', 'aws_s3_bucket', 'aws_clam_s3_bucket', 'aws_s3_region', 'aws_s3_key', 'aws_s3_secret_key', 'aws_role_arn', 'certbot_email', 'certbot_server', 'environment', 'enable_load_test', 'metabase_site_url', 'metabase_embed_secret', 'cert', 'cert_key', 'cert_ca', 'sp_sa_user', 'sp_sa_password', 'sp_site', 'sp_doc_library', 'sp_ms_file_name', 'sp_list_name', 'ches_url', 'ches_client', 'ches_client_secret', 'ches_to', 'ches_keycloak_host', 'pgbackrest_s3_bucket', 'er_file', 'rd_file', 'coverages_file', 'session_secret']
test-e2e / yarn-test-e2e-analyst
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / backup-secrets-test / export-secrets
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
test-e2e / yarn-test-e2e-finalize
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / deploy-to-openshift-production
Multiple files were found for oc that matched the current OS and architecture: openshift-client-linux-4.17.10.tar.gz, openshift-client-linux-amd64-rhel8-4.17.10.tar.gz, openshift-client-linux-amd64-rhel9-4.17.10.tar.gz, openshift-client-linux-arm64-4.17.10.tar.gz, openshift-client-linux-arm64-rhel8-4.17.10.tar.gz, openshift-client-linux-arm64-rhel9-4.17.10.tar.gz, openshift-client-linux-ppc64le-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel8-4.17.10.tar.gz, openshift-client-linux-ppc64le-rhel9-4.17.10.tar.gz, openshift-client-linux-s390x-rhel8-4.17.10.tar.gz, openshift-client-linux-s390x-rhel9-4.17.10.tar.gz. Selecting the first one.
deploy / deploy-to-openshift-production
Unexpected input(s) 'openshift_app_namespace', 'openshift_metabase_namespace', 'openshift_metabase_prod_namespace', 'next_public_growthbook_api_key', 'aws_s3_bucket', 'aws_s3_region', 'aws_s3_key', 'aws_s3_secret_key', 'aws_role_arn', 'aws_clam_s3_bucket', 'metabase_site_url', 'metabase_embed_secret', 'cert', 'cert_key', 'cert_ca', 'pgbackrest_s3_bucket', 'session_secret', valid inputs are ['openshift_server_url', 'openshift_token', 'openshift_username', 'openshift_password', 'insecure_skip_tls_verify', 'certificate_authority_data', 'namespace', 'reveal_cluster_name']
deploy / deploy-to-openshift-production
Unexpected input(s) 'keycloak_host', 'sa_client_secret', 'sa_client_id', valid inputs are ['openshift_server_url', 'openshift_token', 'openshift_app_namespace', 'openshift_metabase_namespace', 'openshift_metabase_prod_namespace', 'tag', 'client_secret', 'secure_route', 'next_public_growthbook_api_key', 'aws_s3_bucket', 'aws_clam_s3_bucket', 'aws_s3_region', 'aws_s3_key', 'aws_s3_secret_key', 'aws_role_arn', 'certbot_email', 'certbot_server', 'environment', 'enable_load_test', 'metabase_site_url', 'metabase_embed_secret', 'cert', 'cert_key', 'cert_ca', 'sp_sa_user', 'sp_sa_password', 'sp_site', 'sp_doc_library', 'sp_ms_file_name', 'sp_list_name', 'ches_url', 'ches_client', 'ches_client_secret', 'ches_to', 'ches_keycloak_host', 'pgbackrest_s3_bucket', 'er_file', 'rd_file', 'coverages_file', 'session_secret']
deploy / create-release
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / create_hotfix_branch / create_hotfix_branch
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
deploy / backup-secrets-prod / export-secrets
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636

Artifacts

Produced during runtime
Name Size
bcgov~CONN-CCBC-portal~4PTPMR.dockerbuild
47.5 KB
bcgov~CONN-CCBC-portal~6ZUNQH.dockerbuild
65.1 KB
bcgov~CONN-CCBC-portal~8AX8AN.dockerbuild
104 KB
bcgov~CONN-CCBC-portal~A06N7A.dockerbuild
78.1 KB
zap_scan
362 KB