CI/CD

GitHub Actions workflows, self-hosted runners, Docker build pipelines, and container registry configuration.

All TACO repositories use GitHub Actions for continuous integration and deployment. Workflows run on self-hosted runners deployed on the TACO server.

Self-Hosted Runners

RunnerNameLabels
Runner 1taco-platform-runnerself-hosted, linux, taco-platform
Runner 2taco-platform-runner-2self-hosted, linux, taco-platform
Runner 3taco-platform-runner-3self-hosted, linux, taco-platform
Runner 4taco-platform-runner-4self-hosted, linux, taco-platform

All runners are:

  • Scoped to the tacosec GitHub organization
  • Running in ephemeral mode (clean state per job)
  • Docker containers with the Docker socket mounted
  • Authenticated with GITHUB_RUNNER_PAT

Go Services Workflow

Most Go services (taco-api, taco-inbound, taco-auth, taco-store, taco-scanner, taco-alert, taco-secrets, taco-enricher, taco-fetcher, taco-vulndb, taco-lib) follow this CI pattern:

CI (test + lint on push)

yamlon:
  push:
    branches: [main]
  pull_request:
    branches: [main]

Steps:

  1. Checkout code
  2. Set up Go
  3. Run go vet ./...
  4. Run go test ./...

Docker Build + Publish

yamlon:
  push:
    branches: [main]
  release:
    types: [published]

Three-job pipeline:

  1. Build -- Build Docker image, save as artifact
  2. Test -- Load image, start container, verify health endpoint returns 200, check for "taco" in response body, verify no errors in logs
  3. Push -- Log in to GHCR, build and push with tags:
    • sha-<commit> (always)
    • latest (on main push or release)
    • <version> (on semver release tag)
    • <major>.<minor> (on semver release tag)

Concurrency

All workflows use concurrency groups to cancel in-progress runs:

yamlconcurrency:
  group: docker-build-${{ github.ref }}
  cancel-in-progress: true

Container Registry

All images are published to GitHub Container Registry (GHCR) under the tacosec organization:

ghcr.io/tacosec/taco-api:latest
ghcr.io/tacosec/taco-inbound:latest
ghcr.io/tacosec/taco-auth:latest
ghcr.io/tacosec/taco-store:latest
ghcr.io/tacosec/taco-scanner:latest
ghcr.io/tacosec/taco-alert:latest
ghcr.io/tacosec/taco-secrets:latest
ghcr.io/tacosec/taco-enricher:latest
ghcr.io/tacosec/taco-fetcher:latest
ghcr.io/tacosec/taco-nextjs:latest
ghcr.io/tacosec/taco-corp:latest
ghcr.io/tacosec/taco-documentation:latest
ghcr.io/tacosec/taco-internal-documentation:latest
ghcr.io/tacosec/taco-support-bot:latest

Deploy Flow

  1. Developer pushes to main or creates a release tag.
  2. GitHub Actions builds, tests, and pushes the Docker image to GHCR.
  3. On the server, run docker compose pull <service> && docker compose up -d <service> to deploy.

There is no automated deployment from CI to production. Deployment is triggered manually on the server.

Documentation Sites Workflow

The documentation services (taco-documentation, taco-internal-documentation) use Next.js for static site generation. Their Docker build:

  1. Node.js builder stage: installs dependencies and runs npm run build
  2. Nginx stage: copies built static files to Nginx webroot
  3. Same three-job pipeline (build, test, push) as Go services