End-to-End DevSecOps CI/CD Pipeline
03/2026Designed a secure, seven-stage delivery workflow using Jenkins, AWS, Docker, and automated security gates.
- Automated source checkout, build, analysis, image creation, security testing, and deployment through Jenkins.
- Integrated SonarQube SAST and quality gates before application deployment.
- Scanned container images with Trivy to identify vulnerabilities earlier in the delivery process.
- Performed DAST testing with OWASP ZAP against common web application risks.
- Deployed the containerized application to Linux on AWS EC2 with Nginx.
JenkinsSonarQubeTrivyAWS EC2LinuxDockerOWASP ZAPNginx