My build-scan-deploy pipeline and AWS setup for running a community three-tier app on EKS, with Terraform, Jenkins, SonarQube, Trivy, ECR and an ALB ingress.
I wanted to stand up a real build, scan, push and deploy path to EKS in my own AWS account, end to end. Rather than write a toy app, I took a well-known community three-tier task app (React, Node and MongoDB) and built the pipeline and infrastructure around it.
To be clear about what's mine: the app, its manifests and the Jenkinsfile skeletons come from the upstream project. I retargeted the pipeline to my own ECR, credentials and Terraform backend, resized the infrastructure, reworked the ingress, and fixed the stages that broke.
Infrastructure
Terraform builds the VPC, security group, IAM role and the Jenkins host, with remote state in S3 and DynamoDB.
CI
Jenkins checks out the code, runs SonarQube and its quality gate, scans the filesystem with Trivy, builds the image, pushes it to ECR and scans the image.
Manifest bump
The pipeline writes the new image tag into the Kubernetes manifest and pushes it.
Workloads
Frontend, backend (two replicas with liveness, readiness and startup probes) and MongoDB on a persistent volume, with rolling updates.
Ingress
An internet-facing AWS Load Balancer Controller ingress routes traffic to the frontend and API.
The quality-gate stage kept hanging, and it took five commits in one day to add and tune the timeout and its error handling. I also had to switch ECR credentials and fix the Jenkins package key URL, which had moved.
There's no benchmark here. It's a working pipeline, and the most useful output was seeing where it's weaker than it looks:
Next project
WuzzyFuzzA fuzzy-logic language embedded in Scala 3, with fuzzy sets, logic gates, scoped variables, classes and partial evaluation.