Goal
Record deployments in Tracker without adding a job to every CI pipeline: Tracker receives the events the deployment tooling already emits.
Two sources, one event model:
| Deployment path |
Source |
Where the real result is known |
Ansible, Terraform, Docker Compose, Helm... jobs that declare environment: (all to-be-continuous deploy templates do) |
GitLab webhook, Deployment events |
the GitLab job |
| GitOps with Flux |
Flux notification-controller (Provider type generic-hmac + Alert) |
the cluster |
| anything else |
existing POST /api/v1alpha1/event |
unchanged |
Proposal
GitLab: POST /api/v1alpha1/integrations/gitlab/webhook
- secret checked from
X-Gitlab-Token (constant-time); non deployment events ignored;
- environment mapped from the first segment of the GitLab environment name, following the to-be-continuous convention (
review/*, integration, staging, production, optional namespace suffix); configurable, default production -> production, staging -> preproduction, others ignored;
- one Tracker event per GitLab deployment: created on
running, updated on success / failed / canceled, duplicates ignored (external id = deployment id);
- service resolved from the catalog by repository URL, falling back to the project path; links to the job and commit.
Flux: POST /api/v1alpha1/integrations/flux/webhook
- HMAC signature (
X-Signature) checked;
- environment taken from the Alert
eventMetadata, same mapping;
- one Tracker event per object and revision (
Kustomization, HelmRelease): progressing -> start, succeeded -> success, failed / health check failed -> failure.
Both endpoints go through the authorization layer from #200 and are disabled until configured.
Out of scope for the first iteration
Pipeline and job events (drift jobs), merge request enrichment, polling the GitLab API for instances that cannot reach Tracker.
Related: #196 (authentication, the endpoints reuse its authorization layer).
Goal
Record deployments in Tracker without adding a job to every CI pipeline: Tracker receives the events the deployment tooling already emits.
Two sources, one event model:
environment:(all to-be-continuous deploy templates do)notification-controller(Providertypegeneric-hmac+Alert)POST /api/v1alpha1/eventProposal
GitLab:
POST /api/v1alpha1/integrations/gitlab/webhookX-Gitlab-Token(constant-time); non deployment events ignored;review/*,integration,staging,production, optional namespace suffix); configurable, defaultproduction->production,staging->preproduction, others ignored;running, updated onsuccess/failed/canceled, duplicates ignored (external id = deployment id);Flux:
POST /api/v1alpha1/integrations/flux/webhookX-Signature) checked;eventMetadata, same mapping;Kustomization,HelmRelease): progressing ->start, succeeded ->success, failed / health check failed ->failure.Both endpoints go through the authorization layer from #200 and are disabled until configured.
Out of scope for the first iteration
Pipeline and job events (drift jobs), merge request enrichment, polling the GitLab API for instances that cannot reach Tracker.
Related: #196 (authentication, the endpoints reuse its authorization layer).