Configure Pipeline Script
We provide you with a pipeline script that you can use in the repository.
To install the WAS Integration with Gitlab application, you need to create two configuration files:
Create docker-compose.yml
Perform the following steps:
- Create a new docker-compose.yml file to the root directory of your project.
- Paste the following .yml code into the newly created file and save it.
docker-compose.yml
version:"3"services:myapp:image: qualys/qwas_integration_cli:latestnetwork_mode: "host"volumes:- ./outputs:/home/app/outputs:rwenvironment:- PLATFORM=${PLATFORM:-}- QUALYS_USERNAME=${QUALYS_USERNAME:-}- QUALYS_PASSWORD=${QUALYS_PASSWORD:-}- WEBAPP_ID=${WEBAPP_ID:-}- SCAN_NAME=${SCAN_NAME:-}- SCAN_TYPE=${SCAN_TYPE:-}- AUTH_RECORD=${AUTH_RECORD:-none}- AUTH_RECORD_ID=${AUTH_RECORD_ID:-""}- OPTION_PROFILE=${OPTION_PROFILE:-useDefault}- OPTION_PROFILE_ID=${OPTION_PROFILE_ID:-""}- CANCEL_OPTION=${CANCEL_OPTION:-false}- CANCEL_HOURS=${CANCEL_HOURS:-0}- SEVERITY_CHECK=${SEVERITY_CHECK:-false}- SEVERITY_LEVEL=${SEVERITY_LEVEL:-0}- FAIL_ON_SCAN_ERROR=${FAIL_ON_SCAN_ERROR:-false}- WAIT_FOR_RESULT=${WAIT_FOR_RESULT:-true}- INTERVAL=${INTERVAL:-5}- EXCLUDE=${EXCLUDE:-0}- TIMEOUT=${TIMEOUT:-350}- FILE_TYPE=${FILE_TYPE:-PDF}- CLIENT_ID=${CLIENT_ID:-}- CLIENT_SECRET=${CLIENT_SECRET:-}- AUTH_TYPE=${AUTH_TYPE}- IDP_TOKEN_URL=${IDP_TOKEN_URL:-}- IDP_SCOPE=${IDP_SCOPE:-}- IDP_AUDIENCE=${IDP_AUDIENCE:-}ports:-"8080:8080"
Create .gitlab-ci.yml
You can use the Qualys template for WAS scans that are added to GitLab.
To use the template, perform the following steps:
- Create a new .gitlab-ci.yml file in the root directory of your project.
- Paste the following .yml code into the newly created file and save it.
.gitlab-ci.yml
stages:- test- setup- deploy- check_statusvariables:PLATFORM: ${PLATFORM:-}QUALYS_USERNAME: ${QUALYS_USERNAME:-}QUALYS_PASSWORD: ${QUALYS_PASSWORD:-}WEBAPP_ID: ${WEBAPP_ID:-}SCAN_NAME: ${SCAN_NAME:-}SCAN_TYPE: ${SCAN_TYPE:-}AUTH_RECORD: ${AUTH_RECORD:-none}AUTH_RECORD_ID: ${AUTH_RECORD_ID:-""}OPTION_PROFILE: ${OPTION_PROFILE:-useDefault}OPTION_PROFILE_ID: ${OPTION_PROFILE_ID:-""}CANCEL_OPTION: ${CANCEL_OPTION:-false}CANCEL_HOURS: ${CANCEL_HOURS:-0}SEVERITY_CHECK: ${SEVERITY_CHECK:-false}SEVERITY_LEVEL: ${SEVERITY_LEVEL:-0}FAIL_ON_SCAN_ERROR: ${FAIL_ON_SCAN_ERROR:-false}WAIT_FOR_RESULT: ${WAIT_FOR_RESULT:-true}INTERVAL: ${INTERVAL:-5}EXCLUDE: ${EXCLUDE:-0}TIMEOUT: ${TIMEOUT:-350}FILE_TYPE: ${FILE_TYPE:-PDF}CLIENT_ID: ${CLIENT_ID:-}CLIENT_SECRET: ${CLIENT_SECRET:-}AUTH_TYPE: ${AUTH_TYPE:-}IDP_TOKEN_URL: ${IDP_TOKEN_URL:-}IDP_SCOPE: ${IDP_SCOPE:-}IDP_AUDIENCE: ${IDP_AUDIENCE:-}include:- template: Security/SAST.gitlab-ci.ymlsetup_env:stage: setupscript:- echo"Setting up environment..."- mkdir -p outputs- chmod -R777outputsartifacts:paths:- outputsexpire_in:240houronly:- merge_requests- maindeploy_app:stage: deployimage: docker:latestservices:- docker:dindbefore_script:- apk add --no-cache docker-composescript:- echo"Starting Docker Compose..."- docker-compose uponly:- merge_requests- mainallow_failure:trueartifacts:paths:- outputs/reports:sast: outputs/Qualys-WAS-SAST-Report.jsonexpire_in:240hourssast:stage: testcheck_status:stage: check_statusscript:- |echo"Checking if outputs/exitCode.txt exists..."if[ -f outputs/exitCode.txt ]; thenstored_exit_code=$(head -n1outputs/exitCode.txt)failure_reason=$(tail -n +2outputs/exitCode.txt)echo"Stored exit code is: $stored_exit_code"if["$stored_exit_code"-eq1]; thenecho"Job failed. Reason:"echo"$failure_reason"exit1elseecho"Exit code is fine. Proceeding..."if[ -n"$failure_reason"]; thenecho"Additional Info:"echo"$failure_reason"fifielseecho"exitCode.txt not found. Assuming success or skipping check."# Uncomment to enforce strict failureiffile is missing# exit1fi