0
All projects

DevSecOps on AWS EKS

My build-scan-deploy pipeline and AWS setup for running a community three-tier app on EKS, with Terraform, Jenkins, SonarQube, Trivy, ECR and an ALB ingress.

Role
Solo. The app is upstream's, and the pipeline, AWS setup and deployment changes are mine.
When
Mar 2026
Status
Complete
Context
Built on a community reference app
Stack
  • AWS EKS
  • Terraform
  • Jenkins
  • SonarQube
  • Trivy
  • Docker
  • ECR

The problem

I wanted to stand up a real build, scan, push and deploy path to EKS in my own AWS account, end to end. Rather than write a toy app, I took a well-known community three-tier task app (React, Node and MongoDB) and built the pipeline and infrastructure around it.

To be clear about what's mine: the app, its manifests and the Jenkinsfile skeletons come from the upstream project. I retargeted the pipeline to my own ECR, credentials and Terraform backend, resized the infrastructure, reworked the ingress, and fixed the stages that broke.

How it works

  1. 1

    Infrastructure

    Terraform builds the VPC, security group, IAM role and the Jenkins host, with remote state in S3 and DynamoDB.

  2. 2

    CI

    Jenkins checks out the code, runs SonarQube and its quality gate, scans the filesystem with Trivy, builds the image, pushes it to ECR and scans the image.

  3. 3

    Manifest bump

    The pipeline writes the new image tag into the Kubernetes manifest and pushes it.

  4. 4

    Workloads

    Frontend, backend (two replicas with liveness, readiness and startup probes) and MongoDB on a persistent volume, with rolling updates.

  5. 5

    Ingress

    An internet-facing AWS Load Balancer Controller ingress routes traffic to the frontend and API.

Decisions and tradeoffs

  • A smaller Jenkins host. Upstream uses a t2.2xlarge. I moved to a t3.micro with my own state bucket, which was enough for a single-user pipeline and much cheaper.
  • A timeout on the SonarQube quality gate. The gate stage hung, so I wrapped it in a 5-minute timeout with error handling to keep the pipeline moving.

What broke

The quality-gate stage kept hanging, and it took five commits in one day to add and tune the timeout and its error handling. I also had to switch ECR credentials and fix the Jenkins package key URL, which had moved.

What I'd fix next

There's no benchmark here. It's a working pipeline, and the most useful output was seeing where it's weaker than it looks:

  • Trivy writes its findings to a file but never fails the build, and the image scan runs after the image is already in ECR. I'd scan before the push and fail on HIGH and CRITICAL findings.
  • The quality gate doesn't block either, because of the timeout and catch I added. It should block once the hang is fixed properly.
  • The EKS cluster itself isn't in Terraform, and deploys are a manifest bump instead of a GitOps controller. Argo CD would be the next step.

Next project

WuzzyFuzz

A fuzzy-logic language embedded in Scala 3, with fuzzy sets, logic gates, scoped variables, classes and partial evaluation.