Overview

A complete, production-grade DevOps and SRE delivery pipeline designed to automate the full lifecycle of microservices: local container testing, continuous integration with security scanning, automated infrastructure provisioning on Amazon EKS, and cluster observability.


Architectural Highlights

  • Automated Multi-Stage CI Pipeline: Built with GitHub Actions to build container images, tag artifacts with unique Git commit SHAs, and execute automated vulnerability scanning via Trivy before pushing to registry.
  • Infrastructure as Code (IaC): Modular Terraform provisions the Amazon EKS cluster, dedicated VPC networking, and security groups with remote S3 backend state locking.
  • Kubernetes Deployments: Manages deployment manifests, database configurations, and AWS Application/Network LoadBalancers for external traffic routing.
  • Full-Stack Observability: Configured and deployed the kube-prometheus-stack (Prometheus, Grafana, Alertmanager) via Helm to monitor pod metrics, node resource saturation, and define alert routes.

Technical Pipeline

  Git Push (Master)
         │
  GitHub Actions CI
  ├── Docker Build (Flask + Postgres data loader)
  ├── Trivy Security Scanning (Gate check)
  └── Docker Hub Push (Tagged with Git SHA)
         │
  Terraform Infrastructure Provisioning
  ├── VPC & Subnets across AZs
  └── Amazon EKS Cluster & Node Groups
         │
  Kubernetes Deployment & Monitoring
  ├── kubectl Deployments & Services (AWS ELB)
  └── Helm kube-prometheus-stack (Grafana dashboards)