This folder contains Jenkins pipeline files for 6 repos that don't have CI/CD set up yet. Created by Adin — hand off to DevOps to deploy.
jenkins-pipelines/
├── zoop-customer-platform/
│ ├── dev/Jenkinsfile
│ ├── sandbox/Jenkinsfile
│ ├── stage/Jenkinsfile
│ └── prod/Jenkinsfile
├── stack/
├── face-liveliness/
├── face-liveliness-frontend/
├── digilocker/
└── zoop-digilocker-v1/
Each repo has 4 environment files. DevOps copies each Jenkinsfile into the matching repo under jenkins/<env>/Jenkinsfile.
| Stage | What it does |
|---|---|
| Clone & Setup | Clones the app repo + marine-ford infra repo, merges .env.secrets + .env.vars |
| SonarQube Analysis | Runs code quality scan against https://sonarqube.zoop.tools/ |
| Trivy Filesystem Scan | Scans source code for known CVEs (HIGH + CRITICAL) |
| Trivy IaC Scan | Scans Terraform/K8s/Dockerfile configs for misconfigurations |
| Build | Builds Docker image, pushes to Google Artifact Registry |
| Deploy | Deploys to GKE using kubectl apply |
Note: SonarQube + Trivy scans only run when
RUN_TESTS = trueis checked at build time. This keeps normal deploys fast.
| Env file | Agent | GCP Project | GKE Cluster | Namespace | Default Branch |
|---|---|---|---|---|---|
dev/Jenkinsfile |
dev-agent | zoop-one-development | development-k8s-cluster | develop | develop |
sandbox/Jenkinsfile |
prod-agent | zoop-production | zoop-one-production-cluster | sandbox | sandbox |
stage/Jenkinsfile |
dev-agent | zoop-one-development | development-k8s-cluster | staging | main |
prod/Jenkinsfile |
prod-agent | zoop-production | zoop-one-production-cluster | production | stable |
These are the project keys used in each Jenkinsfile. They must exist in SonarQube before the scan will work.
| Repo | SonarQube Project Key | Status |
|---|---|---|
zoop-customer-platform |
zoop-customer-platform |
❌ Needs to be created |
stack |
stack |
✅ Already exists |
face-liveliness |
face-liveliness |
❌ Needs to be created |
face-liveliness-frontend |
face-liveliness-frontend |
❌ Needs to be created |
digilocker |
digilocker |
❌ Needs to be created |
zoop-digilocker-v1 |
zoop-digilocker-v1 |
❌ Needs to be created |
- Go to
https://sonarqube.zoop.tools - Click Projects → Create Project → Manually
- Set Project Key exactly as shown in the table above
- Set Display Name same as the key
- Click Set Up
- Go to My Account → Security → Generate Tokens
- Generate one token, name it
jenkins-scanner - Copy the token → give to DevOps → he adds it to Jenkins as a credential named
SONARQUBE_TOKEN
Search for TODO in any Jenkinsfile — there are 2 things per file:
GAR_REPO = 'TODO_GAR_REPO'
Replace with the correct GAR repo for each service. Examples from existing pipelines:
dev-zoopsign(dev)uat-zoopsign(stage)prod-zoopsign(sandbox + prod)
Ask DevOps what the equivalent repo names are for these 6 services.
INFRA_FOLDER_NAME = 'REPO_NAME' // must match folder in marine-ford/k8s/
GKE_DEPLOYMENT_NAME = 'REPO_NAME-deploy' // must match K8s deployment name
DevOps needs to:
- Create the K8s deployment YAMLs in
marine-ford/k8s/<repo-name>/<env>/deployment.yaml - Confirm the deployment name matches what's in the YAML
The pipeline will NOT fail if vulnerabilities are found — it just reports them. This is intentional so existing code doesn't block all deployments on day one.
Once DevOps + engineering have reviewed the first scan results and fixed critical issues, change to:
sh "trivy fs --exit-code 1 --severity HIGH,CRITICAL ..."This will make the pipeline block on HIGH/CRITICAL vulnerabilities — the right long-term behavior.
DevOps needs to confirm Trivy is installed on both dev-agent and prod-agent.
Install command (Ubuntu): apt-get install trivy or via the Trivy install script.
DevOps steps per repo:
- Clone the target repo (e.g.
git clone https://github.com/zoop/digilocker) - Create the
jenkins/folder:mkdir -p jenkins/{dev,sandbox,stage,prod} - Copy the Jenkinsfiles from this folder into the repo
- Commit and push:
git add jenkins/ && git commit -m "add jenkins pipeline" && git push - In Jenkins: create a new Pipeline job, point it to the repo +
jenkins/<env>/Jenkinsfile - Run once with
RUN_TESTS = falseto verify build + deploy works - Then run with
RUN_TESTS = trueto test SonarQube + Trivy scans
These repos already have working pipelines — use them as reference:
zoop/kaido-payment-sdk→jenkins/dev/Jenkinsfilezoop/zsp-admin-portal→jenkins/dev/Jenkinsfilezoop/zou→jenkins/dev/Jenkinsfile
Those pipelines currently use
snyk testinstead of Trivy. DevOps can update those too by replacing the Security Scan stage with the Trivy stages from this folder.
- Raise with DevOps team
- SonarQube admin access: Adin is requesting it (pending as of July 2026)
- SonarQube URL:
https://sonarqube.zoop.tools