New to Kestra?
Use blueprints to kickstart your first workflows.
Automate SonarQube code quality scans, verify Quality Gate pass/fail conditions, generate AI code fix advice with Gemini, and alert via GitHub & Slack.
Ensure software maintainability, security, and test coverage by integrating SonarQube static code analysis into your deployment pipeline. This blueprint clones a target repository, runs sonar-scanner in a Docker container, queries the SonarQube REST API for Quality Gate metrics (security hotspots, code smells, duplication, and coverage breaches), and uses Google Gemini AI to generate refactoring advice posted directly to GitHub and Slack when a Quality Gate fails.
on_code_push_webhook (io.kestra.plugin.core.trigger.Webhook): Triggers execution when commits or PRs are pushed to GitHub.workspace (io.kestra.plugin.core.flow.WorkingDirectory): Sets up a shared directory for repo checkout and scanner output.clone_repository (io.kestra.plugin.git.Clone): Clones the project branch.run_sonar_scanner (io.kestra.plugin.scripts.shell.Commands via io.kestra.plugin.scripts.runner.docker.Docker): Executes sonarsource/sonar-scanner-cli to inspect code and upload metrics to your SonarQube server.fetch_quality_gate_status (io.kestra.plugin.scripts.python.Script): Fetches project status from SonarQube's /api/qualitygates/project_status REST endpoint.evaluate_quality_gate (io.kestra.plugin.core.flow.If): Evaluates whether any Quality Gate conditions failed.ai_code_quality_triage (io.kestra.plugin.ai.agent.AIAgent): Asks Google Gemini for actionable refactoring steps to fix failed conditions.post_github_quality_issue (io.kestra.plugin.github.issues.Create) & notify_slack_quality_failure (io.kestra.plugin.slack.notifications.SlackIncomingWebhook): File a GitHub issue with AI guidance and ping Slack.SonarQube provides metrics, but does not provide end-to-end workflow orchestration, automated issue management, or AI-driven code refactoring. Kestra links SonarScanner container execution, REST API polling, conditional workflow branching (If), AI remediation (AIAgent), and developer notifications (GitHub/Slack) into a single reproducible YAML flow.
GITHUB_TOKEN).GEMINI_API_KEY).SLACK_WEBHOOK_URL).SONAR_HOST_URL: Base URL of your SonarQube instance (e.g., https://sonarcloud.io or http://sonar.internal).SONAR_TOKEN: Authentication token for SonarQube analysis.GITHUB_TOKEN: GitHub personal access token.GEMINI_API_KEY: API key for Google Gemini AI agent.SLACK_WEBHOOK_URL: Slack channel incoming webhook.SONARQUBE_WEBHOOK_KEY: Secret key guarding the flow webhook trigger.SONAR_HOST_URL and SONAR_TOKEN secrets in Kestra.