# GitLab CI/CD pipeline # # Required CI/CD variables (Settings -> CI/CD -> Variables): # HF_USER - Hugging Face username or org that owns the Space # HF_SPACE - Name of the Hugging Face Space (repo name) # HF_TOKEN - HF access token with write scope (mark masked + protected) stages: - test - secret-detection - deploy include: - template: Security/SAST.gitlab-ci.yml - template: Security/Secret-Detection.gitlab-ci.yml variables: SECRET_DETECTION_ENABLED: 'true' sast: stage: test when : manual secret_detection: stage: secret-detection when : manual # Manual deploy to Hugging Face Space (Docker SDK). # Copies the repo into a staging dir, filtering out anything listed in # .hfignore (tests, secrets, CI config, etc.), then force-pushes to HF. deploy_huggingface: stage: deploy image: alpine:latest rules: - if: '$CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH' when: manual before_script: - apk add --no-cache git git-lfs rsync - git lfs install - git config --global user.email "$GITLAB_USER_EMAIL" - git config --global user.name "$GITLAB_USER_NAME" script: - STAGE_DIR="$(mktemp -d)" - GIT_LFS_SKIP_SMUDGE=1 git clone "https://${HF_USER}:${HF_TOKEN}@huggingface.co/spaces/${HF_USER}/${HF_SPACE}" "$STAGE_DIR" - rsync -a --delete --exclude='.git' --exclude-from=.hfignore ./ "$STAGE_DIR/" - cd "$STAGE_DIR" - git add -A - git diff --cached --quiet || git commit -m "Deploy from GitLab ${CI_COMMIT_SHORT_SHA}" - git push origin main