Gitlab Ci Patterns

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Build GitLab CI/CD pipelines with multi-stage workflows, caching, and distributed runners for scalable automation. Use when implementing GitLab CI/CD, optimizing pipeline performance, or setting up automated testing and deployment.

僅含說明DevOps & Cloud
AI 產生的概覽

提供 GitLab CI/CD 流程模式,涵蓋多階段建置、快取、部署與安全掃描。

功能
此技能提供建置 GitLab CI/CD 流程的參考模式與 YAML 範例。內容涵蓋多階段工作流程、Docker 建置與推送、多環境 Kubernetes 部署、Terraform 流程、安全掃描、快取策略以及動態子流程。它也列出流程組織與效能方面的最佳實務。
適用情境
適用於實作或最佳化 GitLab CI/CD、設定 GitLab Runner、建立自動化測試與部署,或採用 GitOps 工作流程時。也適合為現有流程加入安全掃描或快取。
執行需求
不包含指令碼,僅為說明與 YAML 範例。執行範例流程需要 GitLab 執行個體、GitLab Runner,以及 node、docker、kubectl、terraform、trivy 等容器映像。Kubernetes 部署範例需要 KUBE_URL、KUBE_CA_CERT_FILE 和 KUBE_TOKEN 等 CI 變數。

GitLab CI Patterns

Comprehensive GitLab CI/CD pipeline patterns for automated testing, building, and deployment.

Purpose

Create efficient GitLab CI pipelines with proper stage organization, caching, and deployment strategies.

When to Use

  • Automate GitLab-based CI/CD
  • Implement multi-stage pipelines
  • Configure GitLab Runners
  • Deploy to Kubernetes from GitLab
  • Implement GitOps workflows

Basic Pipeline Structure

yaml
stages:  - build  - test  - deploy
variables:  DOCKER_DRIVER: overlay2  DOCKER_TLS_CERTDIR: "/certs"
build:  stage: build  image: node:20  script:    - npm ci    - npm run build  artifacts:    paths:      - dist/    expire_in: 1 hour  cache:    key: ${CI_COMMIT_REF_SLUG}    paths:      - node_modules/
test:  stage: test  image: node:20  script:    - npm ci    - npm run lint    - npm test  coverage: '/Lines\s*:\s*(\d+\.\d+)%/'  artifacts:    reports:      coverage_report:        coverage_format: cobertura        path: coverage/cobertura-coverage.xml
deploy:  stage: deploy  image: bitnami/kubectl:1.31  script:    - kubectl apply -f k8s/    - kubectl rollout status deployment/my-app  only:    - main  environment:    name: production    url: https://app.example.com

Docker Build and Push

yaml
build-docker:  stage: build  image: docker:24  services:    - docker:24-dind  before_script:    - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY  script:    - docker build -t $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA .    - docker build -t $CI_REGISTRY_IMAGE:latest .    - docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA    - docker push $CI_REGISTRY_IMAGE:latest  only:    - main    - tags

Multi-Environment Deployment

Set KUBE_CA_CERT_FILE as a GitLab file variable containing the cluster CA certificate, and provide KUBE_TOKEN through a protected, masked CI variable. The file variable contains a path that kubectl uses to verify the API server certificate. Protect both develop and main so the deployment jobs can read the protected token.

yaml
.deploy_template: &deploy_template  image: bitnami/kubectl:1.31  before_script:    - kubectl config set-cluster k8s --server="$KUBE_URL" --certificate-authority="$KUBE_CA_CERT_FILE" --embed-certs=true    - kubectl config set-credentials admin --token="$KUBE_TOKEN"    - kubectl config set-context default --cluster=k8s --user=admin    - kubectl config use-context default
deploy:staging:  <<: *deploy_template  stage: deploy  script:    - kubectl apply -f k8s/ -n staging    - kubectl rollout status deployment/my-app -n staging  environment:    name: staging    url: https://staging.example.com  only:    - develop
deploy:production:  <<: *deploy_template  stage: deploy  script:    - kubectl apply -f k8s/ -n production    - kubectl rollout status deployment/my-app -n production  environment:    name: production    url: https://app.example.com  when: manual  only:    - main

Terraform Pipeline

yaml
stages:  - validate  - plan  - apply
variables:  TF_ROOT: ${CI_PROJECT_DIR}/terraform  TF_VERSION: "1.6.0"
before_script:  - cd ${TF_ROOT}  - terraform --version
validate:  stage: validate  image: hashicorp/terraform:${TF_VERSION}  script:    - terraform init -backend=false    - terraform validate    - terraform fmt -check
plan:  stage: plan  image: hashicorp/terraform:${TF_VERSION}  script:    - terraform init    - terraform plan -out=tfplan  artifacts:    paths:      - ${TF_ROOT}/tfplan    expire_in: 1 day
apply:  stage: apply  image: hashicorp/terraform:${TF_VERSION}  script:    - terraform init    - terraform apply -auto-approve tfplan  dependencies:    - plan  when: manual  only:    - main

Security Scanning

yaml
include:  - template: Security/SAST.gitlab-ci.yml  - template: Security/Dependency-Scanning.gitlab-ci.yml  - template: Security/Container-Scanning.gitlab-ci.yml
trivy-scan:  stage: test  image: aquasec/trivy:0.58.0  script:    - trivy image --exit-code 1 --severity HIGH,CRITICAL $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA  allow_failure: true

Caching Strategies

yaml
# Cache node_modulesbuild:  cache:    key: ${CI_COMMIT_REF_SLUG}    paths:      - node_modules/    policy: pull-push
# Global cachecache:  key: ${CI_COMMIT_REF_SLUG}  paths:    - .cache/    - vendor/
# Separate cache per jobjob1:  cache:    key: job1-cache    paths:      - build/
job2:  cache:    key: job2-cache    paths:      - dist/

Dynamic Child Pipelines

yaml
generate-pipeline:  stage: build  script:    - python generate_pipeline.py > child-pipeline.yml  artifacts:    paths:      - child-pipeline.yml
trigger-child:  stage: deploy  trigger:    include:      - artifact: child-pipeline.yml        job: generate-pipeline    strategy: depend

Best Practices

  1. Use specific image tags (node:20, not node:latest)
  2. Cache dependencies appropriately
  3. Use artifacts for build outputs
  4. Implement manual gates for production
  5. Use environments for deployment tracking
  6. Enable merge request pipelines
  7. Use pipeline schedules for recurring jobs
  8. Implement security scanning
  9. Use CI/CD variables for secrets
  10. Monitor pipeline performance

Related Skills

  • github-actions-templates - For GitHub Actions
  • deployment-pipeline-design - For architecture
  • secrets-management - For secrets handling

來源與署名

來源:wshobson/agents位於plugins/cicd-automation/skills/gitlab-ci-patterns提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架