Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
151 commits
Select commit Hold shift + click to select a range
74b038e
Merge pull request #4788 from dell/pub/q2_upgrade
abhishek-sa1 Jun 24, 2026
d0356ac
PR1: Move playbooks/ and common/ to src/, update all paths
abhishek-sa1 Jun 24, 2026
b34a4ca
PR2: Move build_stream/ to src/build_stream/
abhishek-sa1 Jun 25, 2026
10c32e2
PR3: Move input/ and examples/ to src/, add q3_main to CI workflows
abhishek-sa1 Jun 25, 2026
019b7e2
Merge pull request #4789 from abhishek-sa1/feature/mono-pr1-playbooks…
sujit-jadhav Jun 25, 2026
ceffd1c
Merge pull request #4790 from abhishek-sa1/feature/mono-pr2-buildstre…
sujit-jadhav Jun 25, 2026
82215bb
Merge pull request #4791 from abhishek-sa1/feature/mono-pr3-input-exa…
sujit-jadhav Jun 25, 2026
e04ddc5
Feature/mono pr4 build and path fixes (#4795)
abhishek-sa1 Jun 29, 2026
53acb22
Sync omnia q2 fixes to q3_main (#4801)
abhishek-sa1 Jun 29, 2026
5ffe7be
Add SDD CI/CD checks to PR gate pipeline (#4815)
Rajeshkumar-s2 Jul 2, 2026
ba1c50a
feat: PR5 — RPM build separation, aarch64 image-builder, container & …
abhishek-sa1 Jul 3, 2026
93345bb
sync: Sync 16 staging commits (c2c09bdc..155b991f) to q3_main with sr…
abhishek-sa1 Jul 13, 2026
806f260
Merge pull request #4834 from abhishek-sa1/feature/sync-staging-16com…
abhishek-sa1 Jul 13, 2026
935771f
fix: disable Pulp pagination for distribution list commands (#4838)
j0hnL Jul 14, 2026
b9fb7d5
Revert "fix: disable Pulp pagination for distribution list commands (…
abhishek-sa1 Jul 14, 2026
4afacfe
Build manager restructure
abhishek-sa1 Jul 17, 2026
99a5f7f
Revert "Build manager restructure"
abhishek-sa1 Jul 17, 2026
ee86bf2
feat: Image Build Manager Refactoring (#4860)
abhishek-sa1 Jul 21, 2026
32bb181
Move discovery and orchestrator to independent multi-repo domains (#4…
sujit-jadhav Jul 21, 2026
a18ca46
image builder modular design update
abhishek-sa1 Jul 21, 2026
137c109
Update IMAGE_BUILDER_DESIGN.md
abhishek-sa1 Jul 22, 2026
d44d293
Move BuildStream Code as per Domain Segregation (#4869)
Rajeshkumar-s2 Jul 22, 2026
957f7bd
Merge branch 'dell:issue-4849-omnia-modernization' into issue-4849-om…
abhishek-sa1 Jul 22, 2026
98892cd
Update IMAGE_BUILDER_DESIGN.md
abhishek-sa1 Jul 22, 2026
12f5e9c
Merge pull request #4878 from abhishek-sa1/issue-4849-omnia-moderniza…
sujit-jadhav Jul 22, 2026
9a47b6f
Image Build Manager Refactoring & Enhancements (#4881)
abhishek-sa1 Jul 22, 2026
8053d40
telemetry repo with idrac and ldms telemetry support (#4879)
priti-parate Jul 23, 2026
377f00f
fix(omnia.sh): move admin NIC IP prompt earlier, fix stdin handling f…
balajikumaran-c-s Jul 24, 2026
816bc1b
Add repo_manager for local repository setup, Pulp deployment, and pac…
snarthan Jul 24, 2026
123c3fd
BuildStream domain segregation - credential utility, cleanup, and app…
Rajeshkumar-s2 Jul 27, 2026
5040253
feat(test): add main automation module for omnia.sh lifecycle validat…
balajikumaran-c-s Jul 27, 2026
1919cae
telemetry mulit-repo input validation and precheck (#4895)
Kratika-P Jul 27, 2026
1df51b5
Refactor repo_manager playbooks for improved maintainability (#4896)
snarthan Jul 27, 2026
130182d
refactor: make orchestrator and discovery domains fully self-containe…
sujit-jadhav Jul 27, 2026
be6aa03
Update SECURITY.md
abhishek-sa1 Jul 28, 2026
ec8b783
Update SECURITY.md
abhishek-sa1 Jul 28, 2026
cd79a6f
examples, input and utils update (#4899)
abhishek-sa1 Jul 28, 2026
9845398
Independent deployment for kafka, victroia metrics, victoria logs (#4…
Kratika-P Jul 29, 2026
3e99bb9
omnia telemetry modernization (#4897)
priti-parate Jul 29, 2026
6789540
feat(domain-architecture): add code style guides and Galaxy structure…
abhishek-sa1 Jul 29, 2026
766abfa
image build manager enhancements
abhishek-sa1 Jul 29, 2026
a19f457
ansible-lint and workflow fixes
abhishek-sa1 Jul 29, 2026
5618dc8
Merge pull request #4904 from abhishek-sa1/issue-4849-omnia-moderniza…
sujit-jadhav Jul 30, 2026
c95735d
galaxy readme updates
abhishek-sa1 Jul 30, 2026
e94485f
Update galaxy.yml
abhishek-sa1 Jul 30, 2026
7c9120b
Update ansible-lint.yml
abhishek-sa1 Jul 30, 2026
df4783c
feat: convert orchestrator and discovery domains to Ansible Galaxy co…
sujit-jadhav Jul 30, 2026
244ad7e
Merge pull request #77 from abhishek-sa1/issue-4849-omnia-modernization
abhishek-sa1 Jul 30, 2026
2528751
Merge pull request #79 from abhishek-sa1/main
abhishek-sa1 Jul 30, 2026
306042e
Merge pull request #4911 from abhishek-sa1/issue-4849
sujit-jadhav Jul 30, 2026
ce78085
Migrated to wolfi (#4889)
SAYUK09 Jul 30, 2026
e6a0b68
Refactor repo_manager to localhost execution with SSH removal and aut…
snarthan Jul 30, 2026
2553d6b
Fix unresolved merge conflict markers in build_stream Containerfile (…
SAYUK09 Jul 31, 2026
4e51ea0
feat(build_stream): standalone mode, no omnia_core dependency, and fl…
Rajeshkumar-s2 Jul 31, 2026
2a5d1e9
fix(image_build_manager): credential re-prompt, cleanup completeness,…
abhishek-sa1 Jul 31, 2026
67676e6
cleanup for telemetry and input plugin changes (#4910)
Kratika-P Jul 31, 2026
ed53955
Add repo_manager Galaxy collection for air-gapped repository manageme…
snarthan Aug 3, 2026
697a269
fix(repo_manager): runtime setup, dependencies, and playbook tag beha…
snarthan Aug 3, 2026
4b976af
feat(test): add image_build_manager FVT suite and omnia-auto shared p…
balajikumaran-c-s Aug 4, 2026
fe5ba00
fix(image_build_manager): empty compute_images_dict in catalog mode +…
abhishek-sa1 Aug 4, 2026
4c2b794
docs(domain-integration): flatten domain input file structure and upd…
abhishek-sa1 Aug 4, 2026
a49025e
refactor(build_stream): Align build_stream domain with Galaxy collect…
Rajeshkumar-s2 Aug 4, 2026
36a0cf4
Modify domain-init.sh to support flat input structure (#4938)
Rajeshkumar-s2 Aug 5, 2026
513f0c1
refactor(utils): restructure utils domain as Ansible collection (#4912)
jagadeeshnv Aug 5, 2026
3325a8c
Support for a repo manager catalog-based approach (#4936)
pullan1 Aug 5, 2026
ce75b43
catalog path updated
pullan1 Aug 5, 2026
692897b
Merge pull request #4942 from pullan1/catalog_issue
snarthan Aug 5, 2026
85b731a
feat(telemetry): modernize telemetry domain with standalone collectio…
priti-parate Aug 5, 2026
3d9931f
test(test/main): refactor test framework and simplify README (#4934)
abhishek-sa1 Aug 6, 2026
29ef857
removed url from slurm_custom repo (#4959)
pullan1 Aug 10, 2026
1027254
refactor(main): move dependency installation to domain-init.sh, repla…
abhishek-sa1 Aug 10, 2026
a9515ac
refactor(test): fix functional group naming, sanitize IPs, add build …
balajikumaran-c-s Aug 11, 2026
9fd36d3
repo_manager directory structure and cleanup fixes (#4967)
pullan1 Aug 11, 2026
421c4a6
feat(orchestrator): modernization phases 1-6 — v3.0.0 (#4923)
sujit-jadhav Aug 11, 2026
8e99038
Add test co-change rule and AI agent policy to code style docs (#4966)
abhishek-sa1 Aug 11, 2026
df414b0
Delete test/image_build_manager/fvt/test.md
abhishek-sa1 Aug 11, 2026
f108961
added dellemc.openmanage (#4976)
SujalS27 Aug 12, 2026
06ced4f
Merge pull request #80 from dell/issue-4849-omnia-modernization
abhishek-sa1 Aug 12, 2026
6e98331
gitleaks update
abhishek-sa1 Aug 12, 2026
b260f9d
Merge pull request #4985 from abhishek-sa1/issue-4849-v2
abhishek-sa1 Aug 13, 2026
e1a84ae
fix(omnia): deps-only global scope, copyright year, activation flow, …
abhishek-sa1 Aug 14, 2026
2509cbd
refactor(omnia): omnia modernization with dependency caching, new CLI…
abhishek-sa1 Aug 19, 2026
eef39e4
deploy ome, cluster invenotry, slurm_validation and telemetry status …
Kratika-P Aug 20, 2026
487081d
idrac upgrade temp playbook
Kratika-P Aug 20, 2026
4071364
Merge pull request #5013 from Kratika-P/issue-4849-omnia-modernization
abhishek-sa1 Aug 20, 2026
c54cd9a
refactor(telemetry,image_build_manager): reorganize playbooks structu…
abhishek-sa1 Aug 20, 2026
384967e
refactor(domain-segregation): remove centralized common and playbooks…
abhishek-sa1 Aug 20, 2026
85819ca
Update build status file output (#5016)
abhishek-sa1 Aug 20, 2026
9db1083
fix(telemetry): strip BOM, update VM versions, add pod verification, …
balajikumaran-c-s Aug 20, 2026
cd0ee64
feat(orchestrator): migrate OpenCHAMI to fabrica-based architecture (…
sujit-jadhav Aug 20, 2026
10628f5
feat: add telemetry FVT framework (#5018)
abhishek-sa1 Aug 20, 2026
2a08b06
feat(telemetry): cleanup improvements, karavi-observability integrati…
balajikumaran-c-s Aug 21, 2026
d853558
refactor(discovery): move discovery.yml into playbooks/ to match orch…
sujit-jadhav Aug 21, 2026
ca0942d
refactor(discovery): align directory structure and setup with orchest…
sujit-jadhav Aug 21, 2026
12f2233
refactor(discovery,orchestrator): replace FQCN with short role/module…
sujit-jadhav Aug 21, 2026
ada6ec2
Galaxy collection for the set_pxe_boot (#5022)
Venu-p1 Aug 24, 2026
7cb5432
fix(orchestrator): construct OpenCHAMI RPM URL from release tag_name
sujit-jadhav Aug 24, 2026
147be81
fix(orchestrator): generate OIM SSH key pair and use user-aware paths
sujit-jadhav Aug 24, 2026
bc8d67a
fix(orchestrator): initialize slurm_conf_dict for login_compiler_node…
sujit-jadhav Aug 24, 2026
a7b1853
idrac, ldms and 2.2 delta changes removing skyway and powevault (#5025)
Kratika-P Aug 24, 2026
49463fe
Merge pull request #5033 from dell/fix/orchestrator-playbook-runtime-…
sujit-jadhav Aug 24, 2026
44cfc8a
Migrated the Input Files to use according to design Structure for Col…
SujalS27 Aug 24, 2026
f2f73ae
fix: omnia modernization — cleanup_images, build verification, CLI en…
abhishek-sa1 Aug 24, 2026
9518185
This PR modernizes the Repo Manager with significant improvements to …
snarthan Aug 24, 2026
7184379
fix(orchestrator): add SMD database connection env vars to openchami.env
sujit-jadhav Aug 24, 2026
6aa7b27
OS Installation Utility to Modular Galaxy Structure (#5032)
Venu-p1 Aug 24, 2026
c45add2
fix(orchestrator): add pipefail to shell task for ansible-lint compli…
sujit-jadhav Aug 24, 2026
01a7b4f
Merge pull request #5034 from dell/fix/smd-db-connection-env-vars
sujit-jadhav Aug 24, 2026
1bb3243
feat(orchestrator): add dcgm_enabled flag to orchestrator_config (#5035)
sujit-jadhav Aug 24, 2026
c256b52
fix(main): standardize domain-init.sh scripts and fix repo_manager bug
abhishek-sa1 Aug 24, 2026
c53b594
Merge branch 'dell:issue-4849-omnia-modernization' into issue-4849-om…
abhishek-sa1 Aug 24, 2026
526a992
Merge pull request #5036 from abhishek-sa1/issue-4849-omnia-moderniza…
snarthan Aug 24, 2026
df4d7d6
feat(telemetry): consolidate cleanup roles into single role, improve …
balajikumaran-c-s Aug 24, 2026
69bda8a
feat: Add build_stream test automation framework with GitLab and BSM …
SOWJANYAJAGADISH123 Aug 25, 2026
8beafc6
Refactor Build Pipeline and APIs as per domain segregated structure. …
Rajeshkumar-s2 Aug 25, 2026
71cb4cf
fix(orchestrator): use chpasswd to reliably set root password (#5040)
sujit-jadhav Aug 25, 2026
7cde090
test automation for repo-manager (#5023)
Nagachandan-P Aug 25, 2026
2c0f4d0
refactor(main): comprehensive test infrastructure modernization with …
abhishek-sa1 Aug 25, 2026
f89867f
Fix omnia telemetry cleanup and create cleanup automation (#5043)
mithileshreddy04 Aug 25, 2026
b91a05b
Buildstream playbook was hanging at prompting username and re-prompti…
SOWJANYAJAGADISH123 Aug 25, 2026
269394b
fix(all domains): ansible.cfg path alignment in all domains (#5046)
abhishek-sa1 Aug 25, 2026
90aca36
Update repo_manager.yml
snarthan Aug 25, 2026
5024914
Retry of image builder in the build pipeline (#5050)
SOWJANYAJAGADISH123 Aug 25, 2026
6241d83
remove DCGM from telemetry domain (#5044)
priti-parate Aug 25, 2026
4dfae8f
feat(telemetry,test): test automation redesign — new source tests, Va…
balajikumaran-c-s Aug 25, 2026
eb7eed9
Update repo_manager.yml (#5049)
snarthan Aug 25, 2026
1c1a454
fix(orchestrator): fix OpenCHAMI deployment issues with RPM config bu…
sujit-jadhav Aug 25, 2026
e75a632
Move set_pxe_boot utility from utils to orchestrator domain
Venu-p1 Aug 24, 2026
5ad2308
Removing pxe from orchestrator playbook
Venu-p1 Aug 24, 2026
fab004a
Update .gitlab-ci-build.yml (#5053)
SOWJANYAJAGADISH123 Aug 25, 2026
433ed20
Orchestrator inventory with kube_vip details, and removed kube_invent…
priti-parate Aug 25, 2026
8b223fb
feat(main): add --skip and --dry-run options to omnia.sh for flexible…
abhishek-sa1 Aug 25, 2026
45445b3
fix(orchestrator): deliver oim_rsa via cloud-init for node-to-node pa…
SAYUK09 Aug 25, 2026
b71b51d
set_pxe_boot: orchestrator integration with CSV input and tags
Venu-p1 Aug 26, 2026
a8ce30f
fix(orchestrator): fix cloud-init syntax, Containerfile, and firewall…
sujit-jadhav Aug 26, 2026
510b91c
refactor(orchestrator): modernize test automation to match source cha…
sujit-jadhav Aug 26, 2026
108ccd3
fix(orchestrator): revert firewall-cmd to slurm_conf_dict in login/lo…
SAYUK09 Aug 26, 2026
363f9d4
Merge pull request #5057 from SAYUK09/fix/passwordless-ssh
sujit-jadhav Aug 26, 2026
a1cd79d
catalog with k8s and slurm support
snarthan Aug 26, 2026
ab7c2c8
Sync 2.2 BuildStream and update requirements.txt and few bug fixes (#…
Rajeshkumar-s2 Aug 26, 2026
f9d6fa3
iDRAC/LDMS modernization and legacy component removal (#5041)
Kratika-P Aug 26, 2026
10652fd
Delete src/main/samples/catalog_rhel_10_0.json
snarthan Aug 27, 2026
dd38393
Add files via upload
snarthan Aug 27, 2026
c40eb41
update telemetry and powerscale input validation (#5058)
priti-parate Aug 27, 2026
627ceca
install_os workflow: auto-mount NFS, SSH key validation, and duplicat…
Venu-p1 Aug 27, 2026
2a7fec2
feat(telemetry,test): status reporting redesign, external_victoria, S…
balajikumaran-c-s Aug 27, 2026
067dedf
Create test automation of nft and add cleanup fixes (#5064)
mithileshreddy04 Aug 27, 2026
6cc4a92
Test automation for Utils (#5061)
SujalS27 Aug 27, 2026
0be3dad
Merge pull request #5037 from Venu-p1/dev/move_pxe
sujit-jadhav Aug 27, 2026
8563197
feat(test/build_stream): add build pipeline automation and GitLab CI …
SOWJANYAJAGADISH123 Aug 27, 2026
7dea8aa
Merge pull request #5065 from snarthan/issue-4849-omnia-modernization
sujit-jadhav Aug 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
22 changes: 3 additions & 19 deletions .config/ansible-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,35 +2,19 @@
exclude_paths:
- .git/
- .github/
- accelerator/tests/
- network/tests/
- provision/tests/
- scheduler/tests/
- security/tests/
- storage/tests/
- test/
- utils/obsolete/
- docs/
- platforms/
- examples/
- input/
- .ansible-lint.yml
- .readthedocs.yaml
- prepare_oim/roles/configure_proxy/tasks/configure_proxy_rocky.yml
- upgrade/roles/upgrade_idrac_telemetry/tasks/filter_idrac.yml
- utils/server_spec_update/roles/os_update/tasks/kcmdline_update_rocky.yml
- utils/roles/oim_cleanup/vars/rocky.yml
- scheduler/roles/k8s_start_services/files/k8s_dashboard_admin.yaml
- scheduler/playbooks/k8s_add_node.yml
- "*ubuntu*"
- "*rocky*"
- .github/workflows/
- .github/workflows/ansible-lint.yml

skip_list:
- var-naming
- unresolved-module
- fqcn[canonical]
- internal-error
- role-name[path]
- galaxy[no-changelog]

verbosity: 1
profile: production
170 changes: 170 additions & 0 deletions .github/workflows/.gitleaks.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,170 @@
title = "Gitleaks config for Omnia"

# ---------------------------------------------------------------------------
# Extend the default gitleaks ruleset so AWS, GCP, private-key, JWT, and
# all other built-in detections remain active without manual maintenance.
# ---------------------------------------------------------------------------
[extend]
useDefault = true

# =========================== GLOBAL ALLOWLIST ============================
[allowlist]
description = "Ignore known false positives for Omnia infra repos"

paths = [
'''(^|/)\.git/''',
'''(^|/)vendor/''',
'''go\.sum$''',
'''package-lock\.json$''',
'''yarn\.lock$''',
'''poetry\.lock$''',
'''\.css\.map$''',
]

regexTarget = "match"

regexes = [
# ------------------------------------------------------------------
# 1. Test / example / demo / dummy credentials
# ------------------------------------------------------------------
'''(?i)(example|dummy|test|demo)[_-]?(password|secret|token|key)''',
'''(?i)(CHANGEME|changeme)''',
'''(?i)password:\s*dell\d+''',
'''(?i)PASSWORD\s*=\s*"?dell\d+''',
'''(?i)password:\s*"?slurmPassword"?''',
'''(?i)VAULT_PASSWORD.*omnia_test''',
'''(?i)PASSWORD\s*=\s*"omnia_test''',
'''(?i)password:\s*"?correct_password"''',

# ------------------------------------------------------------------
# 2. Ansible / Jinja2 variable references (never real secrets)
# ------------------------------------------------------------------
'''(?i)password:\s*"?\{\{.*\}\}"?''',
'''(?i)ansible_.*password.*\{\{''',
'''(?i)password:\s*"?hostvars''',
'''(?i)password:\s*\$\{''',
'''(?i)password:\s*\$[A-Z_]+''',

# ------------------------------------------------------------------
# 3. Variable names used as values (not actual secrets)
# ------------------------------------------------------------------
'''(?i)(token|secret|password)\s*=\s*[a-z_]+$''',
'''(?i)password:\s*[a-z_]+(password|secret|key|token)''',
'''(?i)secret:\s*[a-z_]+(password|secret|key|token)''',
'''(?i)token:\s*[a-z_]+(password|secret|key|token)''',
'''(?i)password:\s*\{\s*password:''',
'''(?i)docker_password_cipher''',
'''(?i)load_docker_credentials''',
'''(?i)password:\s*s3_secret_key''',
'''(?i)password:\s*minio_s3_password''',
'''(?i)password:\s*switch_snmp3_password''',
'''(?i)password:\s*"(mysql|grafana|switch|kerberos_admin|directory_manager)[_a-z]*_password"?''',
'''(?i)secret:\s*"grafana_''',
'''(?i)password:\s*aarch64_ssh_password''',
'''(?i)password:\s*"[a-z_]+_password"''',
'''(?i)[a-z_]+_password\s*=.*(OMNIA_SH_VARS|get\()''',
'''(?i)password\s*=\s*(OMNIA_SH_VARS|[a-z_]+\.get\()''',

# ------------------------------------------------------------------
# 4. Instructional / documentation / user-facing messages
# (the pattern that caused the original false positive)
# ------------------------------------------------------------------
'''(?i)user/password''',
'''(?i)set-password''',
'''(?i)setup_env\.sh''',
'''(?i)Verify.*password''',

# ------------------------------------------------------------------
# 5. Validation / success / failure messages
# ------------------------------------------------------------------
'''(?i)success_msg.*password.*validated''',
'''(?i)fail_msg.*password''',
'''(?i)_password.*validated''',
'''(?i)msg.*password.*valid''',

# ------------------------------------------------------------------
# 6. Database connection strings (localhost / templates)
# ------------------------------------------------------------------
'''(?i)postgresql://.*@(localhost|127\.0\.0\.1)''',
'''(?i)postgresql://user:pass@host''',
'''(?i)postgresql://.*%\([^)]+\)s''',
'''(?i)%\([^)]+\)s''',
'''(?i)(timescaledb_)?password:\s*postgres''',
'''(?i)PASSWORD:\s*postgres''',

# ------------------------------------------------------------------
# 7. Shell / hashing commands (not actual secrets)
# ------------------------------------------------------------------
'''(?i)passwd:\s*\$''',
'''(?i)passwd=?\$\(openssl''',
'''(?i)hashed_passwd=\$\(openssl''',
'''(?i)openssl passwd''',
'''(?i)passwd:key=''',

# ------------------------------------------------------------------
# 8. Config field descriptions / schema definitions (no real values)
# ------------------------------------------------------------------
'''(?i)password:\s*(Optional|Password|"?Password"?|"?Openldap|"?Registration|None)''',
'''(?i)password:\s*"?password"?''',
'''(?i)password\s*=\s*IntegrationTestConfig''',
'''(?i)password:.*description''',
'''(?i)password:.*request_args''',
'''(?i)password:.*database''',
'''(?i)password\s*=\s*AUTH_PASSWORD''',
'''(?i)password\s*=\s*\$MINIO_PASSWORD''',
'''(?i)password:\s*$''',
'''(?i)password:\s+(description|required|type:)''',
'''(?i)password=None''',

# ------------------------------------------------------------------
# 9. Documentation placeholder tokens
# ------------------------------------------------------------------
'''(?i)TOKEN=hf_x+''',
'''(?i)vault_password="x+''',
'''(?i)Password:\s*\d{8}''',
'''(?i)secret\s*=\s*"bld_s_[A-Za-z0-9_-]+"''',

# ------------------------------------------------------------------
# 10. Known test / example tokens
# ------------------------------------------------------------------
'''1c8572f630701e8792bede122ec9c417''',
'''(?i)(secretToken|cookieSecret).*1c8572f6''',

# ------------------------------------------------------------------
# 11. Certificate references (not secrets)
# ------------------------------------------------------------------
'''(?i)secret:.*-(cert|ca-cert)''',
]

# ========================== CUSTOM RULES =================================
# These supplement the default ruleset pulled in via [extend].
# Each rule uses secretGroup so only the VALUE is flagged, not the key name.
# ---------------------------------------------------------------------------

[[rules]]
id = "generic-password"
description = "Generic Password Detection"
regex = '''(?i)(password|passwd|pwd)\s*[:=]\s*["']?([A-Za-z0-9!@#$%^&*()_+=\-]{8,})["']?'''
secretGroup = 2
tags = ["password"]

[[rules]]
id = "credentials-in-url"
description = "Credentials in URL"
regex = '''(?i)\b\w+:\/\/[^:\s]+:([^@\s]+)@[^:\s]+'''
secretGroup = 1
tags = ["credentials", "url"]

[[rules]]
id = "generic-token"
description = "Generic Token/Secret"
regex = '''(?i)(secret|token|api[_-]?key)\s*[:=]\s*["']?([A-Za-z0-9_\-]{16,})["']?'''
secretGroup = 2
tags = ["token", "secret"]

[[rules]]
id = "ansible-secret"
description = "Ansible hardcoded secret"
regex = '''(?i)(ansible_.*password|vault_password)\s*[:=]\s*["']([^"']{6,})["']'''
secretGroup = 2
tags = ["ansible", "secret"]
114 changes: 114 additions & 0 deletions .github/workflows/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
# CI/CD Workflows -- omnia-bsm

All workflows run on pull requests targeting `main`, `staging`, `release_*`, `issue-*`, and `pub/**` branches.

## Workflow Summary

| # | Workflow | File | Jobs | Gate | Description |
|---|---------|------|------|------|-------------|
| 1 | **Ansible Lint** | `ansible-lint.yml` | 1 | Blocking | Runs `ansible-lint` with production profile (FQCN, named tasks, module-vs-shell) |
| 2 | **Bandit Security Scan** | `bandit.yml` | 1 | Blocking | Python SAST -- `bandit -r` to detect security issues in Python code |
| 3 | **Commit Hygiene** | `commit-hygiene.yml` | 3 | Blocking (Job 1) | Validates commit authors, messages, copyright headers, and test co-changes |
| 4 | **HPC Compliance Scanner** | `ansible-module-lint.yml` | 1 | Mixed | HPC anti-patterns + Checkmarx pre-scan (see below) |
| 5 | **Secret Leak Scan** | `gitleaks.yml` | 1 | Blocking | Scans for secrets and credentials using `gitleaks` with custom `.gitleaks.toml` |
| 6 | **Dependency Vulnerability Scan** | `pip-audit.yml` | 1 | Blocking | `pip-audit` scans Python dependencies for known CVEs |
| 7 | **Pylint** | `pylint.yml` | 1 | Blocking | Lint Python code -- minimum score >= 8.0 per file |
| 8 | **Unit Tests & Coverage** | `pytest.yml` | 1 | Blocking | Runs `pytest` with coverage reporting |
| 9 | **ShellCheck** | `shellcheck.yml` | 1 | Blocking | Static analysis of shell scripts |

**Total: 9 workflows, 11 jobs**

> **Note:** YAML linting is handled by `ansible-lint` (production profile). A separate `yamllint` workflow is not required.

---

## HPC Compliance Scanner Details

The `ansible-module-lint.yml` workflow enforces Omnia-specific HPC rules that `ansible-lint` does not cover.

### Ansible Checks (Advisory)

| Check | What It Detects | Style Guide Reference |
|-------|----------------|----------------------|
| `loop:` + `delegate_to:` | Potential serial fan-out across 1000 nodes -- manual review required | `ansible.md` §13.1 |
| `with_items:` + `delegate_to:` | Potential legacy serial fan-out pattern -- manual review required | `ansible.md` §13.1 |

### Python Checks -- Blocking (Errors)

| Check | What It Detects | Style Guide Reference |
|-------|----------------|----------------------|
| `shell=True` | OS Command Injection risk in subprocess | `python.md` §8.3 |
| `os.system()` | OS Command Injection | `python.md` §8.3 |
| `eval()` | Code Injection | `python.md` §8.3 |
| `exec()` | Dynamic code execution | `python.md` §8.3 |
| `yaml.load()` | Insecure YAML deserialization | `python.md` §8.3 |
| `yaml.full_load()` | Unsafe YAML loader | `python.md` §8.3 |
| `yaml.UnsafeLoader` / `yaml.FullLoader` | Unsafe YAML loader classes | `python.md` §8.3 |

### Python Checks -- Advisory (Warnings)

| Check | What It Detects | Note |
|-------|----------------|------|
| `pickle.loads()` | Potentially unsafe deserialization | May have valid internal uses |
| Hardcoded credentials | `password`, `secret`, `api_key`, `token`, `access_token`, `auth_token` patterns | Excludes `test/`, `examples/`, `docs/`, `build/` |

**Design principle:** This workflow only checks rules that `ansible-lint` cannot detect. All FQCN, module-vs-shell, named-task, and bare-variable checks are handled by `ansible-lint` with the production profile.

---

## Quality Gate Summary

### Code Quality

| Gate | Tool | Threshold | Reference |
|------|------|-----------|-----------|
| Ansible Lint | `ansible-lint` | Zero errors (production profile) | `ansible.md` §14.1 |
| Pylint | `pylint` | Score >= 8.0 per file | `python.md` §7.1 |
| ShellCheck | `shellcheck` | Zero errors | `ansible.md` §14 |

### Security

| Gate | Tool | Threshold | Reference |
|------|------|-----------|-----------|
| Python SAST | `bandit` | Zero High/Critical | `python.md` §7 |
| Secret Leak | `gitleaks` | Zero findings | `ansible.md` §14.4 |
| Dependency CVE | `pip-audit` | Zero known vulnerabilities | `python.md` §7 |
| Checkmarx Pre-scan | HPC Compliance Scanner | No `shell=True`, `os.system()`, `eval()`, `exec()`, unsafe `yaml.load()` | `python.md` §8.3 |

---

## Commit Hygiene Details

The `commit-hygiene.yml` workflow enforces the AI Agent Usage Policy from `docs/code-style/general.md`:

| Job | Check | Severity |
|-----|-------|----------|
| **Commit Validation** | Block commits authored by AI bots (Devin, Codex, Copilot, etc.) | ERROR |
| | Block commits from root user | ERROR |
| | Validate `<type>(<scope>): <description>` format | WARN |
| | Block trivially short commit messages (<10 chars) | ERROR |
| | Detect LLM-style language in commit messages | WARN |
| **Copyright Header** | Check Dell Apache 2.0 copyright header in new/changed source files | WARN (advisory) |
| **Test Co-Change** | Warn when `src/` changes without `test/` updates | WARN (advisory) |

**Note:** `Co-Authored-By` trailers are acceptable. The check validates the primary Author and Committer fields, not trailers.

---

## Security Scanning

| Scanner | Tool | What It Checks |
|---------|------|----------------|
| SAST | `bandit` | Python security anti-patterns (hardcoded passwords, SQL injection, etc.) |
| Checkmarx Pre-scan | HPC Compliance Scanner | `shell=True`, `os.system()`, `eval()`, `exec()`, `yaml.load()`, hardcoded credentials |
| Secrets | `gitleaks` | Leaked credentials, API keys, tokens in code and history |
| Dependencies | `pip-audit` | Known CVEs in Python package dependencies |

---

## Adding a New Workflow

1. Create the workflow file in `.github/workflows/`
2. Use the standard branch triggers: `main`, `staging`, `release_*`, `issue-*`, `pub/**`
3. Update this README with the new workflow details
4. Ensure the workflow follows the commit format: `ci(workflows): <description>`
Loading
Loading