CI/CD
GitHub Actions workflows, self-hosted runners, Docker build pipelines, and container registry configuration.
All TACO repositories use GitHub Actions for continuous integration and deployment. Workflows run on self-hosted runners deployed on the TACO server.
Self-Hosted Runners
| Runner | Name | Labels |
|---|---|---|
| Runner 1 | taco-platform-runner | self-hosted, linux, taco-platform |
| Runner 2 | taco-platform-runner-2 | self-hosted, linux, taco-platform |
| Runner 3 | taco-platform-runner-3 | self-hosted, linux, taco-platform |
| Runner 4 | taco-platform-runner-4 | self-hosted, linux, taco-platform |
All runners are:
- Scoped to the
tacosecGitHub organization - Running in ephemeral mode (clean state per job)
- Docker containers with the Docker socket mounted
- Authenticated with
GITHUB_RUNNER_PAT
Go Services Workflow
Most Go services (taco-api, taco-inbound, taco-auth, taco-store, taco-scanner, taco-alert, taco-secrets, taco-enricher, taco-fetcher, taco-vulndb, taco-lib) follow this CI pattern:
CI (test + lint on push)
yamlon:
push:
branches: [main]
pull_request:
branches: [main]
Steps:
- Checkout code
- Set up Go
- Run
go vet ./... - Run
go test ./...
Docker Build + Publish
yamlon:
push:
branches: [main]
release:
types: [published]
Three-job pipeline:
- Build -- Build Docker image, save as artifact
- Test -- Load image, start container, verify health endpoint returns 200, check for "taco" in response body, verify no errors in logs
- Push -- Log in to GHCR, build and push with tags:
sha-<commit>(always)latest(on main push or release)<version>(on semver release tag)<major>.<minor>(on semver release tag)
Concurrency
All workflows use concurrency groups to cancel in-progress runs:
yamlconcurrency:
group: docker-build-${{ github.ref }}
cancel-in-progress: true
Container Registry
All images are published to GitHub Container Registry (GHCR) under the tacosec organization:
ghcr.io/tacosec/taco-api:latest
ghcr.io/tacosec/taco-inbound:latest
ghcr.io/tacosec/taco-auth:latest
ghcr.io/tacosec/taco-store:latest
ghcr.io/tacosec/taco-scanner:latest
ghcr.io/tacosec/taco-alert:latest
ghcr.io/tacosec/taco-secrets:latest
ghcr.io/tacosec/taco-enricher:latest
ghcr.io/tacosec/taco-fetcher:latest
ghcr.io/tacosec/taco-nextjs:latest
ghcr.io/tacosec/taco-corp:latest
ghcr.io/tacosec/taco-documentation:latest
ghcr.io/tacosec/taco-internal-documentation:latest
ghcr.io/tacosec/taco-support-bot:latest
Deploy Flow
- Developer pushes to
mainor creates a release tag. - GitHub Actions builds, tests, and pushes the Docker image to GHCR.
- On the server, run
docker compose pull <service> && docker compose up -d <service>to deploy.
There is no automated deployment from CI to production. Deployment is triggered manually on the server.
Documentation Sites Workflow
The documentation services (taco-documentation, taco-internal-documentation) use Next.js for static site generation. Their Docker build:
- Node.js builder stage: installs dependencies and runs
npm run build - Nginx stage: copies built static files to Nginx webroot
- Same three-job pipeline (build, test, push) as Go services