Skip to main content

odoo-image-supply-chain

Close container image supply-chain gap with automated ACR builds, vulnerability scanning, and image signing

소스 정보

저장소
Insightpulseai/odoo
최근 소스 활동
2026년 4월 12일 11:56
감지된 SKILL.md 언어
영어
스타
6
포크
2

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
2 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
odoo-image-supply-chain
description
Close container image supply-chain gap with automated ACR builds, vulnerability scanning, and image signing
version
1.0
compatibility
{"hosts":["github-copilot","claude-code","codex-cli","cursor","gemini-cli"]}
tags
["security","odoo","governance","aca"]
# odoo-image-supply-chain **Impact tier**: P1 -- Operational Readiness ## Purpose Close the container image supply-chain gap. The benchmark audit found: no ACR build pipeline, no vulnerability scanning on container images, no image signing, and no provenance trail from Dockerfile to deployed image. The Odoo container image is built locally or ad-hoc and pushed to ACR without automated gates. ## When to Use - Setting up automated container image builds for Odoo. - Adding vulnerability scanning to the container pipeline. - Implementing image signing for supply-chain integrity. - Preparing for a security review of the deployment pipeline. ## Required Evidence (inspect these repo paths first) | Path | What to look for | |------|-----------------| | `infra/azure/main.bicep` | ACR resource definition | | `infra/ssot/azure/resources.yaml` | ACR entries (`cripaidev`, `ipaiodoodevacr`) | | `infra/ssot/azure/service-matrix.yaml` | Odoo service -- image reference | | `docs/runbooks/ODOO18_GO_LIVE_CHECKLIST.md` | Image build/scan line items | | `docs/audits/ODOO_AZURE_ENTERPRISE_BENCHMARK.md` | Supply chain gap row | | Docker files in repo root or `docker/` | Dockerfile(s) for Odoo image | ## Microsoft Learn MCP Usage Run at least these three queries: 1. `microsoft_docs_search("Azure Container Registry ACR Tasks automated build")` -- retrieves ACR Tasks for automated image builds on git push. 2. `microsoft_docs_search("Azure Container Registry vulnerability scanning Defender")` -- retrieves Microsoft Defender for Containers image scanning. 3. `microsoft_docs_search("Azure Container Registry image signing notation")` -- retrieves Notation (CNCF) image signing with ACR. Optional: 4. `microsoft_code_sample_search("ACR task build push yaml", language="yaml")` 5. `microsoft_docs_fetch("https://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-build-task")` ## Workflow 1. **Inspect repo** -- Locate all Dockerfiles. Check ACR Bicep definitions. Determine current build process (manual `docker build` + `az acr login` + `docker push`, or ACR Tasks, or CI pipeline). 2. **Query MCP** -- Run the three searches. Capture ACR Tasks YAML syntax, Defender scanning enablement, Notation signing workflow. 3. **Compare** -- Identify: (a) Is there an automated build trigger? (b) Is scanning enabled on ACR? (c) Is image signing in place? (d) Is there a provenance record linking git SHA to image tag? 4. **Patch** -- Create or update: - ACR Task definition (YAML or Bicep) that builds on push to `main`. - Enable Defender for Containers on the ACR (Bicep property or CLI). - Add image tag convention: `<acr>.azurecr.io/odoo:19.0-<git-sha-short>`. - Document the build-scan-sign-deploy pipeline in a runbook. 5. **Verify** -- ACR Task definition is syntactically valid. Defender scanning property is set. Image tag convention is documented. Runbook exists. ## Outputs | File | Change | |------|--------| | `infra/azure/modules/acr.bicep` | ACR with Defender scanning enabled | | `infra/azure/acr-task.yaml` | ACR Task for automated builds (new) | | `docs/runbooks/ODOO_IMAGE_BUILD_PIPELINE.md` | Build-scan-deploy procedure (new) | | `docs/runbooks/ODOO18_GO_LIVE_CHECKLIST.md` | Image supply chain line items | | `infra/ssot/azure/resources.yaml` | ACR entries updated with scanning metadata | | `docs/evidence/<stamp>/odoo-image-supply-chain/` | ACR Task def, MCP excerpts | ## Completion Criteria - [ ] ACR Task or CI pipeline exists that builds Odoo image on push to `main`. - [ ] Image tags include the git SHA (e.g., `19.0-abc1234`). - [ ] Defender for Containers is enabled on at least one ACR. - [ ] A runbook documents the full build-scan-deploy pipeline. - [ ] Go-live checklist includes image scanning verification. - [ ] Evidence directory contains the ACR Task definition and MCP excerpts.
GitHub에서 보기