2026-09-22 00:00:45 +02:00
|
|
|
# Environment-Specific Secrets
|
|
|
|
|
|
|
|
|
|
GitLab CI/CD variables are the secret source of record. `assets.yml` contains
|
|
|
|
|
only non-secret project, host, and test-profile data.
|
|
|
|
|
|
|
|
|
|
## Environment Selection
|
|
|
|
|
|
|
|
|
|
Start a pipeline with `TARGET_ENVIRONMENT` set to the intended GitLab
|
|
|
|
|
environment scope, for example `test`, `acceptance`, or `production`. The value
|
|
|
|
|
must exactly match `all.vars.test_project.environment` in `assets.yml`.
|
|
|
|
|
|
|
|
|
|
Tool jobs declare:
|
|
|
|
|
|
|
|
|
|
```yaml
|
|
|
|
|
environment:
|
|
|
|
|
name: "$TARGET_ENVIRONMENT"
|
|
|
|
|
action: verify
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
GitLab therefore injects variables matching that environment scope only into
|
|
|
|
|
tool jobs. Validation and report jobs do not declare an environment and should
|
|
|
|
|
not receive these credentials.
|
|
|
|
|
|
|
|
|
|
Configure each secret under **Settings > CI/CD > Variables** with:
|
|
|
|
|
|
|
|
|
|
- an exact environment scope such as `test` or `production`;
|
|
|
|
|
- **Protected** enabled for protected environments;
|
|
|
|
|
- **Masked** or **Masked and hidden** where the value format permits it;
|
|
|
|
|
- **File** type for keys, certificates, and structured variable files.
|
|
|
|
|
|
|
|
|
|
Do not enable `CI_DEBUG_TRACE` in pipelines that receive secrets.
|
|
|
|
|
|
|
|
|
|
## Ansible Variables
|
|
|
|
|
|
2026-09-23 12:47:05 +02:00
|
|
|
Define credentials as individual environment-scoped **Variable** entries (not a
|
|
|
|
|
single File variable), under **Settings > CI/CD > Variables**:
|
2026-09-22 00:00:45 +02:00
|
|
|
|
2026-09-23 12:47:05 +02:00
|
|
|
| GitLab variable | Ansible variable | Purpose |
|
|
|
|
|
| --- | --- | --- |
|
|
|
|
|
| `ANSIBLE_USER` | `ansible_user` | Login account |
|
|
|
|
|
| `ANSIBLE_PASSWORD` | `ansible_password` | Login password |
|
|
|
|
|
| `ANSIBLE_BECOME_PASSWORD` | `ansible_become_password` | Sudo / enable password |
|
|
|
|
|
| `VCENTER_HOSTNAME` | `vcenter_hostname` | vCenter appliance address |
|
|
|
|
|
| `VCENTER_USERNAME` | `vcenter_username` | vCenter account |
|
|
|
|
|
| `VCENTER_PASSWORD` | `vcenter_password` | vCenter password |
|
2026-09-22 00:00:45 +02:00
|
|
|
|
2026-09-23 12:47:05 +02:00
|
|
|
Set only those required by the target types declared in `assets.yml`. Values
|
|
|
|
|
containing spaces or special characters (for example a Windows `DOMAIN\user`
|
|
|
|
|
password) must use **Masked and hidden** (GitLab 15.10+); standard **Masked**
|
|
|
|
|
rejects such formats.
|
2026-09-22 00:00:45 +02:00
|
|
|
|
2026-09-23 12:47:05 +02:00
|
|
|
The `test:ansible` job runs `methodologies/ansible/scripts/build-secrets.py`,
|
|
|
|
|
which maps these variables to their Ansible names and writes a temporary YAML
|
|
|
|
|
vars file. `run.sh` passes that file with `--extra-vars @<file>` without
|
|
|
|
|
printing the contents or putting values in the process command line. The
|
|
|
|
|
temporary files live under `$CI_PROJECT_DIR/.run/secrets/` and are removed when
|
|
|
|
|
the job pod ends; they are never stored in artifacts.
|
|
|
|
|
|
|
|
|
|
For SSH key authentication, add `ANSIBLE_PRIVATE_KEY` as a separate
|
|
|
|
|
environment-scoped **File** variable. The job writes its contents to a `0600`
|
|
|
|
|
temporary key file and passes that path through `--private-key` when present.
|
2026-09-22 00:00:45 +02:00
|
|
|
|
|
|
|
|
The current job assumes one credential set per test environment. Environments
|
|
|
|
|
with distinct Windows, Linux, network, or hypervisor credentials should be split
|
2026-09-23 12:47:05 +02:00
|
|
|
into separate tool jobs, each referencing its own environment-scoped variables.
|
2026-09-22 00:00:45 +02:00
|
|
|
|
|
|
|
|
## ZAP Variables
|
|
|
|
|
|
|
|
|
|
ZAP authentication will use individually masked variables referenced by its
|
|
|
|
|
Automation Framework plan, such as `ZAP_USERNAME`, `ZAP_PASSWORD`, or
|
|
|
|
|
`ZAP_AUTH_HEADER_VALUE`. Define only those required by the selected application.
|
|
|
|
|
The ZAP adapter and authentication plan are intentionally not enabled yet.
|
|
|
|
|
|
|
|
|
|
## Rotation
|
|
|
|
|
|
|
|
|
|
Rotate a secret by replacing the value in each GitLab environment scope. No
|
|
|
|
|
repository change is required. Existing artifacts contain normalized findings,
|
|
|
|
|
not the GitLab variable files, and the pipeline never uploads secret paths.
|