Notes

Chain the builds, or split and bind?

Build pipelines for a Keycloak with several custom plugins.

GitLab builds can be chained so that each one feeds into the next. It works. For a Keycloak with several custom plugins and high security standards, it's usually the wrong shape: building and testing everything can take hours, and in a chain every change waits for all of it.

What holds up better is to split and bind:

  • Each plugin builds and tests in its own pipeline, in parallel with the others.
  • Plugin releases are pinned by version.
  • A "tested in version" list, updated as tests run, records which versions have been tested together.

The release then binds pinned versions that are on those lists, instead of rebuilding the whole chain.