Skip to content

GitLab CI Sprawl Report

Repository: PROJECTS/ossa-studio File: .gitlab-ci.yml Length: 531 lines

Sprawl Findings

The app repository is heavily abusing the CI/CD pipeline definition by maintaining 500+ lines of custom execution logic rather than consuming components.

Critical Violations: 1. Hardcoded Docker Building: The build:docker job manually defines Docker TLS, builds images, and pushes to staging registries. 2. Custom Agent Exports: builder:export runs ossa init and ossa export directly in an inline shell script block, completely breaking reusability for other agent projects. 3. Environment Hardcoding: URLs like blueflynas.tailcf98b3.ts.net:8081 and staging.openstandardagents.org are hardcoded in the pipeline variables instead of being injected via IaC/Component inputs. 4. Toolchain Redundancy: Node.js caching and Playwright setup are manually configured instead of utilizing standard gitlab_components.

Remediation

Shrink to < 10 lines using include: - component: from PROJECTS/gitlab_components.