This repository uses GitHub Actions to build, scan, and deploy containers.
- Push changes to GitHub.
- The workflow builds the image with
docker buildand scans it with Trivy. - If successful the image is pushed to the registry and Helm is upgraded in a test namespace.
- Workflows authenticate to the registry using OIDC and short‑lived tokens.
- Secrets are provided via External Secrets and not committed to the repo.
- The pipeline commits updated Helm chart values to a GitOps branch for ArgoCD.
- Image tags are signed with Cosign and SBOMs are generated via Syft.