Webhook icon
WorkingDirectory icon
Clone icon
Commands icon
Docker icon
Script icon
Process icon
If icon
AIAgent icon
GoogleGemini icon
Create icon
SlackIncomingWebhook icon
Log icon

SonarQube Quality Gate Audit and AI Code Triage

Automate SonarQube code quality scans, verify Quality Gate pass/fail conditions, generate AI code fix advice with Gemini, and alert via GitHub & Slack.

Categories
Infrastructure

Ensure software maintainability, security, and test coverage by integrating SonarQube static code analysis into your deployment pipeline. This blueprint clones a target repository, runs sonar-scanner in a Docker container, queries the SonarQube REST API for Quality Gate metrics (security hotspots, code smells, duplication, and coverage breaches), and uses Google Gemini AI to generate refactoring advice posted directly to GitHub and Slack when a Quality Gate fails.

How it works

  1. on_code_push_webhook (io.kestra.plugin.core.trigger.Webhook): Triggers execution when commits or PRs are pushed to GitHub.
  2. workspace (io.kestra.plugin.core.flow.WorkingDirectory): Sets up a shared directory for repo checkout and scanner output.
  3. clone_repository (io.kestra.plugin.git.Clone): Clones the project branch.
  4. run_sonar_scanner (io.kestra.plugin.scripts.shell.Commands via io.kestra.plugin.scripts.runner.docker.Docker): Executes sonarsource/sonar-scanner-cli to inspect code and upload metrics to your SonarQube server.
  5. fetch_quality_gate_status (io.kestra.plugin.scripts.python.Script): Fetches project status from SonarQube's /api/qualitygates/project_status REST endpoint.
  6. evaluate_quality_gate (io.kestra.plugin.core.flow.If): Evaluates whether any Quality Gate conditions failed.
  7. ai_code_quality_triage (io.kestra.plugin.ai.agent.AIAgent): Asks Google Gemini for actionable refactoring steps to fix failed conditions.
  8. post_github_quality_issue (io.kestra.plugin.github.issues.Create) & notify_slack_quality_failure (io.kestra.plugin.slack.notifications.SlackIncomingWebhook): File a GitHub issue with AI guidance and ping Slack.

What you get

  • Automated continuous code quality & security auditing.
  • Hermetic, containerized SonarScanner execution without local setup.
  • AI-assisted technical debt & security triage tailored to failed SonarQube conditions.
  • Multi-channel notification pipeline (GitHub Issues & Slack).

Who it's for

  • Engineering managers and tech leads enforcing code quality thresholds.
  • Developers wanting instant AI feedback on how to fix SonarQube failures.
  • DevOps engineers integrating SonarQube into automated CI/CD workflows.

Why orchestrate this with Kestra

SonarQube provides metrics, but does not provide end-to-end workflow orchestration, automated issue management, or AI-driven code refactoring. Kestra links SonarScanner container execution, REST API polling, conditional workflow branching (If), AI remediation (AIAgent), and developer notifications (GitHub/Slack) into a single reproducible YAML flow.

Prerequisites

  • A running SonarQube instance (Cloud or self-hosted).
  • A Docker-enabled Kestra worker node.
  • A GitHub Personal Access Token (GITHUB_TOKEN).
  • A Google Gemini API Key (GEMINI_API_KEY).
  • A Slack Incoming Webhook URL (SLACK_WEBHOOK_URL).

Secrets

  • SONAR_HOST_URL: Base URL of your SonarQube instance (e.g., https://sonarcloud.io or http://sonar.internal).
  • SONAR_TOKEN: Authentication token for SonarQube analysis.
  • GITHUB_TOKEN: GitHub personal access token.
  • GEMINI_API_KEY: API key for Google Gemini AI agent.
  • SLACK_WEBHOOK_URL: Slack channel incoming webhook.
  • SONARQUBE_WEBHOOK_KEY: Secret key guarding the flow webhook trigger.

Quick start

  1. Configure SONAR_HOST_URL and SONAR_TOKEN secrets in Kestra.
  2. Import this blueprint YAML.
  3. Run manually or link to your repository's webhook endpoint.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.