Add workflow usage csv overview

This commit is contained in:
Luke Engle
2022-09-20 14:26:28 -07:00
parent a4c13b43f5
commit 830c9084ef
5 changed files with 149 additions and 1 deletions
+30
View File
@@ -173,6 +173,36 @@ Each pipeline will have a variety of files written that include:
- The converted workflow.
- Stack traces that can used to troubleshoot a failed pipeline conversion
## Inspect the workflow usage csv file
1. Open the `tmp/audit/workflow_usage.csv` file in the file explorer.
2. This file contains a comma-separated list of all actions, secrets, and runners that are used by each successfully converted pipeline:
```csv
Pipeline,Action,File path
lab-test/pipelines/valet-pipeline2,actions/checkout@v2,/data/tmp/adoa/lab-test/pipelines/valet-pipeline2.yml
lab-test/pipelines/valet-pipeline1,actions/checkout@v2,/data/tmp/adoa/lab-test/pipelines/valet-pipeline1.yml
lab-test/pipelines/valet-custom-transformer-example,actions/checkout@v2,/data/tmp/adoa/lab-test/pipelines/valet-custom-transformer-example.yml
lab-test/pipelines/valet-custom-transformer-example,actions/setup-node@v2,/data/tmp/adoa/lab-test/pipelines/valet-custom-transformer-example.yml
Pipeline,Secret,File path
Pipeline,Runner,File path
lab-test/pipelines/valet-pipeline2,mechamachine,/data/tmp/adoa/lab-test/pipelines/valet-pipeline2.yml
lab-test/pipelines/valet-custom-transformer-example,mechamachine,/data/tmp/adoa/lab-test/pipelines/valet-custom-transformer-example.yml
```
### Review workflow usage csv file
#### Actions section
The actions section contains a list of all actions that are used by each converted pipeline. This will enable you to perform strict security reviews to know exactly which repo will need access to a third-party action.
#### Secrets and Runners sections
The secrets and runners sections contain a list of all secrets and runners that are used by each converted pipeline. This will enable you to have a holistic view of what secrets and runners are used across all of your pipelines.
### Next lab
[Forecast potential build runner usage](3-forecast.md)
+37
View File
@@ -191,6 +191,43 @@ Each pipeline will have a variety of files written that include:
- The converted workflow.
- Stack traces that can used to troubleshoot a failed pipeline conversion
## Inspect the workflow usage csv file
1. Open the `tmp/audit/workflow_usage.csv` file in the file explorer.
2. This file contains a comma-separated list of all actions, secrets, and runners that are used by each successfully converted pipeline:
```csv
Pipeline,Action,File path
valet-labs/circleci-hello-world,actions/checkout@v2,/data/tmp/audit/valet-labs/circleci-hello-world/say-hello-workflow.yml
valet-labs/circleci-command-example,./.github/actions/greeting,/data/tmp/audit/valet-labs/circleci-command-example/my-workflow.yml
valet-labs/circleci-node-example,actions/checkout@v2,/data/tmp/audit/valet-labs/circleci-node-example/sample.yml
valet-labs/circleci-node-example,actions/cache@v2,/data/tmp/audit/valet-labs/circleci-node-example/sample.yml
valet-labs/circleci-python-example,actions/checkout@v2,/data/tmp/audit/valet-labs/circleci-python-example/sample.yml
valet-labs/circleci-python-example,actions/cache@v2,/data/tmp/audit/valet-labs/circleci-python-example/sample.yml
valet-labs/circleci-demo-java-spring,actions/checkout@v2,/data/tmp/audit/valet-labs/circleci-demo-java-spring/workflow.yml
valet-labs/circleci-demo-java-spring,actions/cache@v2,/data/tmp/audit/valet-labs/circleci-demo-java-spring/workflow.yml
valet-labs/circleci-demo-java-spring,actions/upload-artifact@v2,/data/tmp/audit/valet-labs/circleci-demo-java-spring/workflow.yml
valet-labs/circleci-demo-java-spring,actions/download-artifact@v2,/data/tmp/audit/valet-labs/circleci-demo-java-spring/workflow.yml
valet-labs/circleci-demo-ruby-rails,ruby/setup-ruby@v1,/data/tmp/audit/valet-labs/circleci-demo-ruby-rails/build_and_test.yml
valet-labs/circleci-demo-ruby-rails,actions/checkout@v2,/data/tmp/audit/valet-labs/circleci-demo-ruby-rails/build_and_test.yml
valet-labs/circleci-demo-ruby-rails,actions/cache@v2,/data/tmp/audit/valet-labs/circleci-demo-ruby-rails/build_and_test.yml
Pipeline,Secret,File path
Pipeline,Runner,File path
```
### Review workflow usage csv file
#### Actions section
The actions section contains a list of all actions that are used by each converted pipeline. This will enable you to perform strict security reviews to know exactly which repo will need access to a third-party action.
#### Secrets and Runners sections
The secrets and runners sections contain a list of all secrets and runners that are used by each converted pipeline. This will enable you to have a holistic view of what secrets and runners are used across all of your pipelines.
### Next lab
[Forecast potential build runner usage](3-forecast.md)
+1 -1
View File
@@ -56,7 +56,7 @@ You will need to complete all of the setup instructions [here](./readme.md#confi
✔ Personal access token for GitHub: ***************
✔ Base url of the GitHub instance: https://github.com
✔ Private token for GitLab: ***************
✔ Base url of the GitLab instance: https://gitlab.com
✔ Base url of the GitLab instance: http://localhost
Environment variables successfully updated.
```
+45
View File
@@ -181,6 +181,51 @@ Each pipeline will have a variety of files written that include:
- The converted workflow.
- Stack traces that can be used to troubleshoot a failed pipeline conversion
## Inspect the workflow usage csv file
1. Open the `tmp/audit/workflow_usage.csv` file in the file explorer.
2. This file contains a comma-separated list of all actions, secrets, and runners that are used by each successfully converted pipeline:
```csv
Pipeline,Action,File path
valet/included-files-example,actions/checkout@v2,/data/tmp/audit/valet/included-files-example.yml
valet/terraform-example,actions/checkout@v2,/data/tmp/audit/valet/terraform-example.yml
valet/child-parent-example,actions/checkout@v2,/data/tmp/audit/valet/child-parent-example.yml
valet/child-parent-example,./.github/workflows/a-.gitlab-ci.yml,/data/tmp/audit/valet/child-parent-example.yml
valet/child-parent-example,./.github/workflows/b-.gitlab-ci.yml,/data/tmp/audit/valet/child-parent-example.yml
valet/include-file-example,actions/checkout@v2,/data/tmp/audit/valet/include-file-example.yml
valet/basic-pipeline-example,actions/checkout@v2,/data/tmp/audit/valet/basic-pipeline-example.yml
valet/gatsby-example,actions/checkout@v2,/data/tmp/audit/valet/gatsby-example.yml
valet/gatsby-example,actions/cache@v2,/data/tmp/audit/valet/gatsby-example.yml
valet/gatsby-example,actions/upload-artifact@v2,/data/tmp/audit/valet/gatsby-example.yml
valet/gatsby-example,actions/download-artifact@v2,/data/tmp/audit/valet/gatsby-example.yml
valet/gatsby-example,JamesIves/[email protected],/data/tmp/audit/valet/gatsby-example.yml
valet/android-example,actions/checkout@v2,/data/tmp/audit/valet/android-example.yml
valet/android-example,actions/upload-artifact@v2,/data/tmp/audit/valet/android-example.yml
valet/android-example,actions/download-artifact@v2,/data/tmp/audit/valet/android-example.yml
valet/dotnet-example,actions/checkout@v2,/data/tmp/audit/valet/dotnet-example.yml
valet/dotnet-example,actions/upload-artifact@v2,/data/tmp/audit/valet/dotnet-example.yml
valet/dotnet-example,actions/download-artifact@v2,/data/tmp/audit/valet/dotnet-example.yml
valet/node-example,actions/checkout@v2,/data/tmp/audit/valet/node-example.yml
valet/node-example,actions/cache@v2,/data/tmp/audit/valet/node-example.yml
valet/rails-example,actions/checkout@v2,/data/tmp/audit/valet/rails-example.yml
Pipeline,Secret,File path
valet/rails-example,${{ secrets.PASSWORD }},/data/tmp/audit/valet/rails-example.yml
Pipeline,Runner,File path
```
### Review workflow usage csv file
#### Actions section
The actions section contains a list of all actions that are used by each converted pipeline. This will enable you to perform strict security reviews to know exactly which repo will need access to a third-party action.
#### Secrets and Runners sections
The secrets and runners sections contain a list of all secrets and runners that are used by each converted pipeline. This will enable you to have a holistic view of what secrets and runners are used across all of your pipelines.
### Next lab
[Forecast potential build runner usage](3-forecast.md)
+36
View File
@@ -238,6 +238,42 @@ Each pipeline will have a variety of files written that include:
- The converted workflow.
- Stack traces that can used to troubleshoot a failed pipeline conversion
## Inspect the workflow usage csv file
1. Open the `tmp/audit/workflow_usage.csv` file in the file explorer.
2. This file contains a comma-separated list of all actions, secrets, and runners that are used by each successfully converted pipeline:
```csv
Pipeline,Action,File path
demo_pipeline,actions/checkout@v2,/data/tmp/audit/demo_pipeline.yml
demo_pipeline,actions/upload-artifact@v2,/data/tmp/audit/demo_pipeline.yml
demo_pipeline,EnricoMi/[email protected],/data/tmp/audit/demo_pipeline.yml
monas_dev_work/monas_freestyle,actions/checkout@v2,/data/tmp/audit/monas_dev_work/monas_freestyle.yml
monas_dev_work/monas_pipeline,actions/checkout@v2,/data/tmp/audit/monas_dev_work/monas_pipeline.yml
test_freestyle_project,actions/checkout@v2,/data/tmp/audit/test_freestyle_project.yml
test_pipeline,actions/checkout@v2,/data/tmp/audit/test_pipeline.yml
test_pipeline,EnricoMi/[email protected],/data/tmp/audit/test_pipeline.yml
Pipeline,Secret,File path
monas_dev_work/monas_freestyle,${{ secrets.SECRET_TEST_EXPRESSION_VAR }},/data/tmp/audit/monas_dev_work/monas_freestyle.yml
test_freestyle_project,${{ secrets.EXPRESSION_FIRST_VAR }},/data/tmp/audit/test_freestyle_project.yml
Pipeline,Runner,File path
demo_pipeline,TeamARunner,/data/tmp/audit/demo_pipeline.yml
test_freestyle_project,DemoRunner,/data/tmp/audit/test_freestyle_project.yml
test_pipeline,TeamARunner,/data/tmp/audit/test_pipeline.yml
```
### Review workflow usage csv file
#### Actions section
The actions section contains a list of all actions that are used by each converted pipeline. This will enable you to perform strict security reviews to know exactly which repo will need access to a third-party action.
#### Secrets and Runners sections
The secrets and runners sections contain a list of all secrets and runners that are used by each converted pipeline. This will enable you to have a holistic view of what secrets and runners are used across all of your successfully converted pipelines.
## Next lab
[Forecast potential build runner usage](3-forecast.md)