Skip to content

Commit d5dcb39

Browse files
docs: document CI runner Alpine Docker image for GitLab CI (#187)
Adds a "CI runner image (Alpine)" subsection to the GitLab tab in `integrations/ci_cd.md`, covering the new `Dockerfile.alpine` shipped in `kosli-dev/cli` (v2.13.2 changelog). Includes: - What the image is and how it differs from the default `ghcr.io/kosli-dev/cli` entrypoint image - How to build and push it pinned to a specific CLI version - A `.gitlab-ci.yml` example using it as a job image - Notes on the non-root `kosli` user, `/workspace` workdir, and `KOSLI_ORG` / `KOSLI_HOST` / `KOSLI_API_TOKEN` env vars Follow-up to the [March 30, 2026 changelog entry](https://docs.kosli.com/changelog#march-30-2026). Co-authored-by: mintlify[bot] <109931778+mintlify[bot]@users.noreply.github.com>
1 parent 8924ba9 commit d5dcb39

1 file changed

Lines changed: 36 additions & 0 deletions

File tree

‎integrations/ci_cd.md‎

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -86,6 +86,42 @@ description: Use Kosli in CI Systems like GitHub Actions, GitLab CI, and more.
8686

8787
For a complete example of a Gitlab pipeline using Kosli, please check [this cyber-dojo pipeline](https://gitlab.com/cyber-dojo/creator/-/blob/main/.gitlab/workflows/main.yml).
8888

89+
### CI runner image (Alpine)
90+
91+
The Kosli CLI repository ships an Alpine-based [`Dockerfile.alpine`](https://github.com/kosli-dev/cli/blob/main/Dockerfile.alpine) intended for use as a CI runner image. Unlike the default `ghcr.io/kosli-dev/cli` image (which has the `kosli` binary as its entrypoint), the Alpine variant has no entrypoint and bundles `git`, `curl`, and `ca-certificates` alongside the CLI — so it can be used as a general-purpose job image where you also need to clone repos, hit HTTP APIs, or run other shell tooling next to `kosli`.
92+
93+
Build and push it to your own registry, pinning the CLI version you want:
94+
95+
```bash
96+
# Clone or copy Dockerfile.alpine from https://github.com/kosli-dev/cli
97+
docker build \
98+
--build-arg KOSLI_VERSION=2.13.2 \
99+
-f Dockerfile.alpine \
100+
-t registry.example.com/ci/kosli-runner:2.13.2 .
101+
docker push registry.example.com/ci/kosli-runner:2.13.2
102+
```
103+
104+
Then use it as the job image in `.gitlab-ci.yml`:
105+
106+
```yaml
107+
variables:
108+
KOSLI_ORG: my-org
109+
KOSLI_HOST: https://app.kosli.com
110+
111+
attest:
112+
image: registry.example.com/ci/kosli-runner:2.13.2
113+
script:
114+
- kosli version
115+
- kosli attest generic
116+
--flow my-flow
117+
--trail "$CI_COMMIT_SHA"
118+
--name build
119+
--compliant=true
120+
# KOSLI_API_TOKEN should be set as a masked GitLab CI/CD variable
121+
```
122+
123+
The image runs as the non-root `kosli` user with `/workspace` as the working directory. `KOSLI_ORG` and `KOSLI_HOST` are exposed as environment variables so they can be overridden in your CI configuration; `KOSLI_API_TOKEN` should be supplied via a masked CI variable rather than baked into the image.
124+
89125
</Tab>
90126
<Tab title="Azure DevOps">
91127
View defaulted Kosli command flags in Azure DevOps.

0 commit comments

Comments
 (0)