Speaker
Description
This presentation highlights the CI/CD and GitOps approach that is
applied in the deployment and operations of the ENVRI-Hub Next
applications and their underlying infrastructure. The GitLab CI/CD
pipelines perform automation of the build process, test, quality
assessments, security scan, and releases in staging and production
environments. Quality gates using tools such as SonarQube and SQAaaS,
and the rootless container builds with Trivy scans to identify known
vulnerabilities and configuration weaknesses before the release or
deployment of the images.
The deployments of the application are managed through version-
controlled Helm charts and Kubernetes manifests. The ArgoCD performs
constant reconciliation between the desired state that is specified
in the Git repository and the actual state of the Kubernetes clusters
with a capability to ensure repeatable deployments, traceability and
fast detection of the configuration drift. Such measures as Hashicorp
Vault, OIDC authentication provided by the GitLab, Kubernetes
isolation, runtime security and automatic backup mechanisms enhance
security and robustness of the platform. The centralised metrics and
logs increase visibility and help troubleshoot issues effectively.
This approach ensures a scalable and secure cloud-native environment
for ENVRI-Hub Next.