← Pipelines
Shared steps
Reusable step definitions managed in your org-pipelines config repo.
What shared steps are
A shared step is a reusable building block that any pipeline in the org can reference by name. Instead of duplicating the same Docker image, run command, and environment setup across every repo, define it once in the step registry.
Defining a step
Steps live in the org-pipelines repo under steps/.
# steps/trivy-scan.yaml
image: aquasec/trivy:0.62.1
run: trivy fs --exit-code 1 --severity HIGH,CRITICAL .
description: Scan for high and critical CVEs Using a step
Reference a shared step with use in your
pipeline config or policy:
# In a policy or .gittan.yaml
steps:
- name: security-scan
use: trivy-scan The step's image, run command, and defaults are resolved from the registry. You can override individual fields:
steps:
- name: security-scan
use: trivy-scan
env:
TRIVY_SEVERITY: CRITICAL Step fields
| Field | Description |
|---|---|
| image | Container image for this step. |
| run | Shell command to execute. |
| description | Human-readable purpose. |
| needs | Dependencies on other steps. |
| env | Default environment variables. |
Syncing
Steps are synced automatically when you push to the org-pipelines repo. The step registry updates within seconds — no manual deployment needed.