demo.obmka.xyz

SBOM Demo Console

Every service of the CI/CD and SBOM demo. The dot shows whether the service answers right now. Logins: run make creds in the sbom-demo repo.

Source and CI

Artifacts

Security

Delivery and alerts

Sample apps

Demo script

  1. Open an MR in claims/claim-service: tests, SAST, secret scan and the warn-only dependency scan run.
  2. Merge it. The main pipeline builds the image, uploads both SBOMs to Dependency-Track, signs the image and archives the evidence in Nexus.
  3. dev and int deploy on their own through ArgoCD.
  4. Run promote:uat, merge the MR in claim-service-devops, sync uat in ArgoCD.
  5. Run promote:prod: the gate fails on log4j-core CVE-2021-44228 (critical).
  6. Either bump log4j-core in a new MR, or record an analysis for the finding in Dependency-Track. Re-run promote:prod: it passes, copies the image to docker-prod and opens the prod MR.
  7. Merge the prod MR. ArgoCD deploys prod and tags the version deployed:prod in Dependency-Track.
  8. The alert mails are in Mailpit.