Application release
Version 1.1
Container images use immutable full Git commit SHA tags.
Source. Scan. Build. Deploy.
Built and deployed through an AWS DevSecOps pipeline, with security checks before release and public HTTPS verification after deployment.
Static HTML, a lightweight nginx container, and an automated journey from Git commit to deployment.
Version 1.1
Container images use immutable full Git commit SHA tags.
America/Denver · Recorded during the image build in CodeBuild.
AWS · Ubuntu EC2
Docker deployment through AWS Systems Manager.
Each stage advances only when the preceding stage succeeds.
A push to main starts AWS CodePipeline through AWS CodeConnections.
AWS CodeBuild runs Gitleaks and Semgrep, builds the Docker image, and runs Trivy before pushing to Amazon ECR.
A dedicated build uses AWS Systems Manager to deploy the SHA-tagged image and verify the container locally.
A separate stage checks TLS, the HTTP response, and expected application content at the public endpoint.
OWASP ZAP Baseline crawls the public HTTPS application and passively checks responses without an active attack scan.
A focused toolchain for source control, delivery, security, and verification.