AWS / Delivery lab
DevSecOps demonstration

Source. Scan. Build. Deploy.

AWS CI/CD Demo

Built and deployed through an AWS DevSecOps pipeline, with security checks before release and public HTTPS verification after deployment.

Small application. Complete delivery path.

Static HTML, a lightweight nginx container, and an automated journey from Git commit to deployment.

Application release

Version 1.1

Container images use immutable full Git commit SHA tags.

Image built

2026-09-27 18:32:28 MDT

America/Denver · Recorded during the image build in CodeBuild.

Deployment environment

AWS · Ubuntu EC2

Docker deployment through AWS Systems Manager.

The delivery pipeline

Each stage advances only when the preceding stage succeeds.

  1. 01 / SOURCE

    Commit to GitHub

    A push to main starts AWS CodePipeline through AWS CodeConnections.

  2. 02 / BUILD & SECURE

    Check before release

    AWS CodeBuild runs Gitleaks and Semgrep, builds the Docker image, and runs Trivy before pushing to Amazon ECR.

  3. 03 / DEPLOY

    Deliver the exact image

    A dedicated build uses AWS Systems Manager to deploy the SHA-tagged image and verify the container locally.

  4. 04 / VERIFY

    Check public HTTPS

    A separate stage checks TLS, the HTTP response, and expected application content at the public endpoint.

  5. 05 / DAST

    Scan the deployed site

    OWASP ZAP Baseline crawls the public HTTPS application and passively checks responses without an active attack scan.

Tools & services in use

A focused toolchain for source control, delivery, security, and verification.

Passive DASTOWASP ZAP Baseline reports warnings; configured FAIL findings and scan errors block the pipeline.