0% found this document useful (0 votes)
3 views22 pages

Amazon App Deployment-Pythonlife

Uploaded by

Akshay
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views22 pages

Amazon App Deployment-Pythonlife

Uploaded by

Akshay
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

AMAZON APP DEPLOYMENT: TERRAFORM AND JENKINS

CI/CD
Step1: create an IAM user (we need to generate access and
secret_key for programmatic access)

Step2: Aws Configure

aws configure

Provide your Aws Access key and Secret Access key

Step3: Install terraform

Step4: Terraform files and Provision Jenkins,sonar

Create [Link]

resource "aws_instance" "web" {

ami = "ami-0f5ee92e2d63afc18" #change ami id for


different region

instance_type = "[Link]"

key_name = "MUMBAI-TERRA"

vpc_security_group_ids = [aws_security_group.[Link]]

user_data = templatefile("./[Link]", {})


tags = {

Name = "Jenkins-sonarqube"

root_block_device {

volume_size = 30

resource "aws_security_group" "Jenkins-sg" {

name = "Jenkins-sg"

description = "Allow TLS inbound traffic"

ingress = [

for port in [22, 80, 443, 8080, 9000, 3000] : {

description = "inbound rules"

from_port = port

to_port = port

protocol = "tcp"

cidr_blocks = ["[Link]/0"]

ipv6_cidr_blocks = []

prefix_list_ids = []

security_groups = []

self = false

egress {

from_port = 0

to_port =0

protocol = "-1"
cidr_blocks = ["[Link]/0"]

tags = {

Name = "jenkins-sg"

Create user-data file like [Link]

#!/bin/bash

sudo apt update -y

wget -O - [Link] |
tee /etc/apt/keyrings/[Link]

echo "deb [signed-by=/etc/apt/keyrings/[Link]]


[Link] $(awk -F=
'/^VERSION_CODENAME/{print$2}' /etc/os-release) main" | tee
/etc/apt/[Link].d/[Link]

sudo apt update -y

sudo apt install temurin-17-jdk -y

/usr/bin/java --version

curl -fsSL [Link] | sudo


tee /usr/share/keyrings/[Link] > /dev/null

echo deb [signed-by=/usr/share/keyrings/[Link]]


[Link] binary/ | sudo tee
/etc/apt/[Link].d/[Link] > /dev/null

sudo apt-get update -y

sudo apt-get install jenkins -y

sudo systemctl start jenkins

sudo systemctl status jenkins

#install docker
sudo apt-get update

sudo apt-get install [Link] -y

sudo usermod -aG docker ubuntu

newgrp docker

sudo chmod 777 /var/run/[Link]

docker run -d --name sonar -p 9000:9000 sonarqube:lts-community

#install trivy

sudo apt-get install wget apt-transport-https gnupg lsb-release -y

wget -qO - [Link] | gpg --


dearmor | sudo tee /usr/share/keyrings/[Link] > /dev/null

echo "deb [signed-by=/usr/share/keyrings/[Link]]


[Link] $(lsb_release -sc) main" |
sudo tee -a /etc/apt/[Link].d/[Link]

sudo apt-get update

sudo apt-get install trivy -y

NOW EXECUTE THE TERRAFORM SCRIPT

terraform init

terraform validate

terraform plan

terraform apply
<instance-ip:8080> #jenkins

sudo cat /var/lib/jenkins/secrets/initialAdminPassword

Unlock Jenkins using an administrative password and install the suggested


plugins.
Create a user click on save and continue.

Jenkins Getting Started Screen.


Copy your Public key again and paste it into a new tab

<instance-public-ip:9000>

Now our sonarqube is up and running

Enter username and password, click on login and change password

username admin

password admin
Update New password, This is Sonar Dashboard.

Step 5 — Install Plugins like JDK, Sonarqube Scanner, NodeJs,


OWASP Dependency Check

5A — Install Plugin

Goto Manage Jenkins →Plugins → Available Plugins →


Install below plugins

1 → Eclipse Temurin Installer (Install without restart)

2 → SonarQube Scanner (Install without restart)

3 → NodeJs Plugin (Install Without restart)

5B — Configure Java and Nodejs in Global Tool Configuration

Goto Manage Jenkins → Tools → Install JDK(17) and NodeJs(16)→ Click on


Apply and Save
Step 6 — Configure Sonar Server in Manage Jenkins

Grab the Public IP Address of your EC2 Instance, Sonarqube works on Port
9000, so <Public IP>:9000. Goto your Sonarqube Server. Click on
Administration → Security → Users → Click on Tokens and Update Token
→ Give it a name → and click on Generate Token

copy Token

Goto Jenkins Dashboard → Manage Jenkins → Credentials → Add Secret


Text. It should look like this
You will this page once you click on create

Now, go to Dashboard → Manage Jenkins → System and Add like the


below image.

Click on Apply and Save

The Configure System option is used in Jenkins to configure different


server
Global Tool Configuration is used to configure different tools that we
install using Plugins

We will install a sonar scanner in the tools.

In the Sonarqube Dashboard add a quality gate also

Administration–> Configuration–>Webhooks

Click on Create
Add details

#in url section of quality gate

<[Link]

GOTO Jenkins dashboard create Jenkins pipeline job

pipeline{

agent any

tools{

jdk 'jdk17'

nodejs 'node16'

environment {

SCANNER_HOME=tool 'sonar-scanner'

stages {
stage('clean workspace'){

steps{

cleanWs()

stage('Checkout from Git'){

steps{

git branch: 'main', url: '[Link]


[Link]'

stage("Sonarqube Analysis "){

steps{

withSonarQubeEnv('sonar-server') {

sh ''' $SCANNER_HOME/bin/sonar-scanner -
[Link]=Amazon \

-[Link]=Amazon '''

stage("quality gate"){

steps {

script {

waitForQualityGate abortPipeline: false, credentialsId: 'Sonar-


token'

}
stage('Install Dependencies') {

steps {

sh "npm install"

Click on Build now, you will see the stage view like this

To see the report, you can go to Sonarqube Server and go to Projects.

You can see the report has been generated and the status shows as
passed. You can see that there are 1k lines it scanned. To see a detailed
report, you can go to issues.

Step 7 — Install OWASP Dependency Check Plugins

GotoDashboard → Manage Jenkins → Plugins → OWASP Dependency-


Check. Click on it and install it without restart.
First, we configured the Plugin and next, we had to configure the Tool

Goto Dashboard → Manage Jenkins → Tools →

Click on Apply and Save here.

Now go configure → Pipeline and add this stage to your pipeline and build.

stage('OWASP FS SCAN') {

steps {

dependencyCheck additionalArguments: '--scan ./ --


disableYarnAudit --disableNodeAudit', odcInstallation: 'DP-Check'
dependencyCheckPublisher pattern: '**/dependency-check-
[Link]'

stage('TRIVY FS SCAN') {

steps {

sh "trivy fs . > [Link]"

The stage view would look like this,

Step 8 — Docker Image Build and Push

We need to install the Docker tool in our system, Goto Dashboard →


Manage Plugins → Available plugins → Search for Docker and install these
plugins

Docker
Docker Commons

Docker Pipeline

Docker API

docker-build-step

and click on install without restart

Now, goto Dashboard → Manage Jenkins → Tools →

Add DockerHub Username and Password under Global Credentials

stage("Docker Build & Push"){


steps{

script{

withDockerRegistry(credentialsId: 'docker', toolName:


'docker'){

sh "docker build -t amazon ."

sh "docker tag amazon hanvitha/amazon:latest "

sh "docker push hanvitha/amazon:latest "

stage("TRIVY"){

steps{

sh "trivy image hanvitha/amazon:latest > [Link]"

You will see the output below, with a dependency trend.


When you log in to Dockerhub, you will see a new image is created

Now Run the container to see if the game coming up or not by


adding the below stage

stage('Deploy to container'){

steps{

sh 'docker run -d --name amazon -p 3000:3000


hanvitha/amazon:latest'

<Jenkins-public-ip:3000>
You will get this output

You might also like