本文へ移動
cccskills
無料GitHub で公開

gitlab-ci-validator

Validate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs.

インストール方法を見る

含まれるファイル(21)

  • SKILL.md6.3 KB
  • .gitignore143 B
  • docs/best-practices.md12.4 KB
  • docs/common-issues.md15.0 KB
  • docs/gitlab-ci-reference.md12.7 KB
  • examples/.gitlab-ci-local/expanded-gitlab-ci.yml7.9 KB
  • examples/.gitlab-ci-local/includes/gitlab.com/gitlab-org/gitlab/-/raw/HEAD/lib/gitlab/ci/templates/Jobs/Dependency-Scanning.gitlab-ci.yml10.6 KB
  • examples/.gitlab-ci-local/includes/gitlab.com/gitlab-org/gitlab/-/raw/HEAD/lib/gitlab/ci/templates/Jobs/SAST.gitlab-ci.yml17.4 KB
  • examples/.gitlab-ci-local/includes/gitlab.com/gitlab-org/gitlab/-/raw/HEAD/lib/gitlab/ci/templates/Jobs/Secret-Detection.gitlab-ci.yml2.2 KB
  • examples/basic-pipeline.gitlab-ci.yml2.3 KB
  • examples/complex-workflow.gitlab-ci.yml12.2 KB
  • examples/component-pipeline.gitlab-ci.yml4.6 KB
  • examples/docker-build.gitlab-ci.yml3.6 KB
  • examples/multi-stage.gitlab-ci.yml7.6 KB
  • scripts/check_best_practices.py31.6 KB
  • scripts/check_security.py36.6 KB
  • scripts/install_tools.sh8.1 KB
  • scripts/python_wrapper.sh1.1 KB
  • scripts/validate_gitlab_ci.sh15.6 KB
  • scripts/validate_syntax.py56.8 KB
  • tests/test_validators.py22.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

GitLab CI/CD Validator

Comprehensive toolkit for validating, linting, testing, and securing .gitlab-ci.yml configurations.

Trigger Phrases

Use this skill when requests include intent like:

  • "Validate this .gitlab-ci.yml"
  • "Why is this GitLab pipeline failing?"
  • "Run a security review for our GitLab CI"
  • "Check pipeline best practices"
  • "Lint GitLab CI config before merge"

Setup And Prerequisites (Run First)

All commands below assume repository root as current working directory.

# Ensure validator scripts are executable
chmod +x devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.py

# Required runtime
python3 --version

Use one canonical command path for orchestration:

VALIDATOR="bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/validate_gitlab_ci.sh"

Optional local execution tooling (for --test-only):

bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/install_tools.sh

Quick Start Commands

# 1) Full validation (syntax + best practices + security)
$VALIDATOR .gitlab-ci.yml

# 2) Syntax and schema only (required first gate)
$VALIDATOR .gitlab-ci.yml --syntax-only

# 3) Best-practices only (recommended)
$VALIDATOR .gitlab-ci.yml --best-practices

# 4) Security only (required before merge)
$VALIDATOR .gitlab-ci.yml --security-only

# 5) Optional local pipeline structure test (needs gitlab-ci-local + Docker)
$VALIDATOR .gitlab-ci.yml --test-only

# 6) Strict mode (treat best-practice warnings as failure)
$VALIDATOR .gitlab-ci.yml --strict

Deterministic Validation Workflow

Follow these gates in order:

  1. Run Quick Start command 2 (--syntax-only).
  2. If syntax fails, stop and fix errors before continuing.
  3. Run Quick Start command 3 (--best-practices) and apply relevant improvements.
  4. Run Quick Start command 4 (--security-only) and fix all critical/high findings before merge.
  5. Optionally run Quick Start command 5 (--test-only) for local execution checks.
  6. Run Quick Start command 6 (--strict) for final merge gate.

Required gates: syntax + security. Recommended gate: best practices. Optional gate: local execution test.

Rule Severity Rationale And Documentation Links

Severity Model

  • critical: Direct credential/secret exposure or high-confidence compromise path. Block merge.
  • high: Exploitable unsafe behavior or strong security regression. Fix before merge.
  • medium: Security hardening gap with realistic risk. Track and fix soon.
  • low/suggestion: Optimization or maintainability improvement.

Rule Classes And Why They Matter

  • Syntax rules (yaml-syntax, job-stage-undefined, dependencies-undefined-job): prevent pipeline parse and dependency failures.
  • Best-practice rules (cache-missing, artifact-no-expiration, dag-optimization): reduce runtime cost and improve pipeline throughput.
  • Security rules (hardcoded-password, curl-pipe-bash, include-remote-unverified): reduce credential leaks and supply-chain risk.

References

Fallbacks For Tool Or Environment Constraints

  • Missing python3:
    • Behavior: validator cannot run.
    • Fallback: install Python 3 and rerun.
  • Missing PyYAML:
    • Behavior: python_wrapper.sh auto-creates .venv and installs pyyaml when possible.
    • Fallback in restricted/offline environments: pre-install pyyaml from an internal mirror, then rerun.
  • Missing gitlab-ci-local, node, or docker:
    • Behavior: --test-only reports warning/failure.
    • Fallback: skip local execution testing and continue with syntax/best-practice/security gates.
  • No execute permission on scripts:
    • Behavior: shell permission errors.
    • Fallback: rerun the setup chmod command from the Setup section.

Examples

Example 1: New Pipeline Validation

$VALIDATOR examples/basic-pipeline.gitlab-ci.yml --syntax-only
$VALIDATOR examples/basic-pipeline.gitlab-ci.yml --security-only

Example 2: Pre-Merge Hard Gate

$VALIDATOR .gitlab-ci.yml --strict

Example 3: CI Integration

stages:
  - validate

validate_gitlab_ci:
  stage: validate
  script:
    - chmod +x devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.sh devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.py
    - bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/validate_gitlab_ci.sh .gitlab-ci.yml --strict

Individual Validators (Advanced)

# Syntax validator (via wrapper for PyYAML fallback)
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/python_wrapper.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/validate_syntax.py .gitlab-ci.yml

# Best-practices validator
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/python_wrapper.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/check_best_practices.py .gitlab-ci.yml

# Security validator
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/python_wrapper.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/check_security.py .gitlab-ci.yml

Done Criteria

  • Frontmatter name and description unchanged.
  • One canonical orchestrator path is used consistently.
  • Setup and chmod prerequisites appear before workflow/use examples.
  • Quick-start and workflow are non-duplicative (workflow references quick-start gates).
  • Severity rationale and rule-to-doc references are explicit.
  • Fallback behavior is documented for missing tools and constrained environments.
  • Examples are executable from repository root.

Notes

  • This skill validates configuration and static patterns; it does not execute production pipelines.
  • Use gitlab-ci-local or GitLab CI Lint for runtime behavior confirmation.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Generate, create, or scaffold Ansible playbooks, roles, tasks, handlers, inventory, vars.

日本語の概要は準備中です。原文の説明を表示しています。

akin-ozer/cc-devops-skills3212026年7月27日 更新

Validate, lint, audit, or debug Ansible playbooks, roles, inventories, FQCN, tasks.

日本語の概要は準備中です。原文の説明を表示しています。

akin-ozer/cc-devops-skills3212026年7月27日 更新

Generate/create/scaffold azure-pipelines.yml, stages, jobs, steps, or reusable templates.

日本語の概要は準備中です。原文の説明を表示しています。

akin-ozer/cc-devops-skills3212026年7月27日 更新

Validate, lint, audit, or review azure-pipelines.yml — syntax, security, best practices.

日本語の概要は準備中です。原文の説明を表示しています。

akin-ozer/cc-devops-skills3212026年7月27日 更新

Create, generate, write, or scaffold bash/shell scripts (.sh), automation, or CLI tools.

日本語の概要は準備中です。原文の説明を表示しています。

akin-ozer/cc-devops-skills3212026年7月27日 更新

Validate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck.

日本語の概要は準備中です。原文の説明を表示しています。

akin-ozer/cc-devops-skills3212026年7月27日 更新

akin-ozer のスキルをすべて見る

このスキルの問題を報告する