GitLab Workflow

Pre-Requirements

CI/CD Variables 로 XEIZE_TOKEN 과 GitLab API 토큰이 필요합니다. GitLab API 토큰은 XEIZE_GITLAB_API_TOKEN 또는 GITLAB_API_TOKEN 이름으로 설정할 수 있습니다.

XEIZE Token

XEIZE_TOKEN 토큰을 발급 받아야 GitLab Workflow에 적용이 가능합니다.

GitLab PAT Token

XEIZE_GITLAB_API_TOKEN 또는 GITLAB_API_TOKEN으로 GitLab PAT Token이 comment를 달기위해 아래와 같은 권한으로 추가되어야합니다. 두 변수가 모두 설정되면 XEIZE_GITLAB_API_TOKEN을 사용하며, 이 값이 비어 있을 때만 GITLAB_API_TOKEN을 사용합니다.

  • api

토큰 사용자는 대상 프로젝트의 코드를 볼 수 있고 Merge Request에 댓글을 작성할 수 있는 프로젝트 멤버 권한도 가져야 합니다. read_api는 읽기 전용이므로 부족하며, write_repository는 REST API 인증 권한이 아닙니다. 자세한 내용은 GitLab의 access token scope와 프로젝트 권한을 참고하세요.

PAT 토큰 발급 방안 참고: https://docs.xeize.dev/integrations/xeize-onprem/gitlab-pat

스캔 결과 언어 설정

SAST, Secret, IaC가 Merge Request에 작성하는 취약점 결과와 댓글 언어는 variables에 LANG을 추가하여 설정합니다.

yaml
variables:
  LANG: "JP"

지원하는 값은 KO(한국어), EN(영어), JP(일본어)입니다. LANG을 설정하지 않으면 한국어가 기본값으로 사용됩니다.

예제

SAST 적용

yaml
image: alpine:3.24
stages:
  - sast
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
  LANG: "JP"
sast:
  stage: sast
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab ./xez_ci

Secret 적용

yaml
image: alpine:3.24
stages:
  - secret
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
  MODE: secret
  LANG: "JP"
secret:
  stage: secret
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab ./xez_ci

IaC 적용

yaml
image: alpine:3.24
stages:
  - iac
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
  MODE: iac
  LANG: "JP"
iac:
  stage: iac
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab ./xez_ci

LEVEL 설정을 통한 Merge Block

yaml
image: alpine:3.24
stages:
  - sast
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
sast:
  stage: sast
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab LEVEL=high ./xez_ci

AUDIT LEVEL 설정을 통한 취약점 필터

yaml
image: alpine:3.24
stages:
  - iac
before_script:
  - apk update && apk add --no-cache git curl
variables:
  GIT_STRATEGY: clone
  GIT_DEPTH: 0
iac:
  stage: iac
  script: |
    curl -L -o xez_ci "https://download.xeize.dev/ci/ci_linux_x64" -H "X-XEZ-TOKEN: $XEIZE_TOKEN"
    chmod +x xez_ci
    GIT_PLATFORM=gitlab MODE=iac LEVEL=high AUDIT_LEVEL=low ./xez_ci

MR 없는 push 파이프라인

develop 브랜치 push에서 MODE=all로 SAST, Secret, IaC를 검사하고, 성공하면 빌드·배포를 실행합니다. XEIZE_TOKEN을 CI/CD 변수에 등록하세요.

yaml
workflow:
  rules:
    - if: '$CI_PIPELINE_SOURCE == "push" && $CI_COMMIT_BRANCH == "develop"'

stages: [security, build, deploy]

security:
  stage: security
  image: alpine:3.24
  allow_failure: false
  variables:
    GIT_DEPTH: "0"
    MODE: all
    LEVEL: medium
  before_script:
    - apk add --no-cache git curl
  script: |
    curl -fsSL -H "X-XEZ-TOKEN: $XEIZE_TOKEN" https://download.xeize.dev/ci/ci_linux_x64 -o /tmp/xez_ci
    chmod +x /tmp/xez_ci
    GIT_PLATFORM=gitlab /tmp/xez_ci

build:
  stage: build
  needs: [security]
  script:
    - ./ci/build.sh

deploy:
  stage: deploy
  needs: [build]
  script:
    - ./ci/deploy.sh

빌드·배포 명령과 Runner 설정은 프로젝트에 맞게 교체하고, security → build → deploy 의존성을 유지하세요. 검사 범위와 오류 처리 방식은 공통 설정을 참고하세요.

관련 문서1