AMAZON APP DEPLOYMENT: TERRAFORM AND JENKINS
CI/CD
Step1: create an IAM user (we need to generate access and
secret_key for programmatic access)
Step2: Aws Configure
aws configure
Provide your Aws Access key and Secret Access key
Step3: Install terraform
Step4: Terraform files and Provision Jenkins,sonar
Create [Link]
resource "aws_instance" "web" {
ami = "ami-0f5ee92e2d63afc18" #change ami id for
different region
instance_type = "[Link]"
key_name = "MUMBAI-TERRA"
vpc_security_group_ids = [aws_security_group.[Link]]
user_data = templatefile("./[Link]", {})
tags = {
Name = "Jenkins-sonarqube"
root_block_device {
volume_size = 30
resource "aws_security_group" "Jenkins-sg" {
name = "Jenkins-sg"
description = "Allow TLS inbound traffic"
ingress = [
for port in [22, 80, 443, 8080, 9000, 3000] : {
description = "inbound rules"
from_port = port
to_port = port
protocol = "tcp"
cidr_blocks = ["[Link]/0"]
ipv6_cidr_blocks = []
prefix_list_ids = []
security_groups = []
self = false
egress {
from_port = 0
to_port =0
protocol = "-1"
cidr_blocks = ["[Link]/0"]
tags = {
Name = "jenkins-sg"
Create user-data file like [Link]
#!/bin/bash
sudo apt update -y
wget -O - [Link] |
tee /etc/apt/keyrings/[Link]
echo "deb [signed-by=/etc/apt/keyrings/[Link]]
[Link] $(awk -F=
'/^VERSION_CODENAME/{print$2}' /etc/os-release) main" | tee
/etc/apt/[Link].d/[Link]
sudo apt update -y
sudo apt install temurin-17-jdk -y
/usr/bin/java --version
curl -fsSL [Link] | sudo
tee /usr/share/keyrings/[Link] > /dev/null
echo deb [signed-by=/usr/share/keyrings/[Link]]
[Link] binary/ | sudo tee
/etc/apt/[Link].d/[Link] > /dev/null
sudo apt-get update -y
sudo apt-get install jenkins -y
sudo systemctl start jenkins
sudo systemctl status jenkins
#install docker
sudo apt-get update
sudo apt-get install [Link] -y
sudo usermod -aG docker ubuntu
newgrp docker
sudo chmod 777 /var/run/[Link]
docker run -d --name sonar -p 9000:9000 sonarqube:lts-community
#install trivy
sudo apt-get install wget apt-transport-https gnupg lsb-release -y
wget -qO - [Link] | gpg --
dearmor | sudo tee /usr/share/keyrings/[Link] > /dev/null
echo "deb [signed-by=/usr/share/keyrings/[Link]]
[Link] $(lsb_release -sc) main" |
sudo tee -a /etc/apt/[Link].d/[Link]
sudo apt-get update
sudo apt-get install trivy -y
NOW EXECUTE THE TERRAFORM SCRIPT
terraform init
terraform validate
terraform plan
terraform apply
<instance-ip:8080> #jenkins
sudo cat /var/lib/jenkins/secrets/initialAdminPassword
Unlock Jenkins using an administrative password and install the suggested
plugins.
Create a user click on save and continue.
Jenkins Getting Started Screen.
Copy your Public key again and paste it into a new tab
<instance-public-ip:9000>
Now our sonarqube is up and running
Enter username and password, click on login and change password
username admin
password admin
Update New password, This is Sonar Dashboard.
Step 5 — Install Plugins like JDK, Sonarqube Scanner, NodeJs,
OWASP Dependency Check
5A — Install Plugin
Goto Manage Jenkins →Plugins → Available Plugins →
Install below plugins
1 → Eclipse Temurin Installer (Install without restart)
2 → SonarQube Scanner (Install without restart)
3 → NodeJs Plugin (Install Without restart)
5B — Configure Java and Nodejs in Global Tool Configuration
Goto Manage Jenkins → Tools → Install JDK(17) and NodeJs(16)→ Click on
Apply and Save
Step 6 — Configure Sonar Server in Manage Jenkins
Grab the Public IP Address of your EC2 Instance, Sonarqube works on Port
9000, so <Public IP>:9000. Goto your Sonarqube Server. Click on
Administration → Security → Users → Click on Tokens and Update Token
→ Give it a name → and click on Generate Token
copy Token
Goto Jenkins Dashboard → Manage Jenkins → Credentials → Add Secret
Text. It should look like this
You will this page once you click on create
Now, go to Dashboard → Manage Jenkins → System and Add like the
below image.
Click on Apply and Save
The Configure System option is used in Jenkins to configure different
server
Global Tool Configuration is used to configure different tools that we
install using Plugins
We will install a sonar scanner in the tools.
In the Sonarqube Dashboard add a quality gate also
Administration–> Configuration–>Webhooks
Click on Create
Add details
#in url section of quality gate
<[Link]
GOTO Jenkins dashboard create Jenkins pipeline job
pipeline{
agent any
tools{
jdk 'jdk17'
nodejs 'node16'
environment {
SCANNER_HOME=tool 'sonar-scanner'
stages {
stage('clean workspace'){
steps{
cleanWs()
stage('Checkout from Git'){
steps{
git branch: 'main', url: '[Link]
[Link]'
stage("Sonarqube Analysis "){
steps{
withSonarQubeEnv('sonar-server') {
sh ''' $SCANNER_HOME/bin/sonar-scanner -
[Link]=Amazon \
-[Link]=Amazon '''
stage("quality gate"){
steps {
script {
waitForQualityGate abortPipeline: false, credentialsId: 'Sonar-
token'
}
stage('Install Dependencies') {
steps {
sh "npm install"
Click on Build now, you will see the stage view like this
To see the report, you can go to Sonarqube Server and go to Projects.
You can see the report has been generated and the status shows as
passed. You can see that there are 1k lines it scanned. To see a detailed
report, you can go to issues.
Step 7 — Install OWASP Dependency Check Plugins
GotoDashboard → Manage Jenkins → Plugins → OWASP Dependency-
Check. Click on it and install it without restart.
First, we configured the Plugin and next, we had to configure the Tool
Goto Dashboard → Manage Jenkins → Tools →
Click on Apply and Save here.
Now go configure → Pipeline and add this stage to your pipeline and build.
stage('OWASP FS SCAN') {
steps {
dependencyCheck additionalArguments: '--scan ./ --
disableYarnAudit --disableNodeAudit', odcInstallation: 'DP-Check'
dependencyCheckPublisher pattern: '**/dependency-check-
[Link]'
stage('TRIVY FS SCAN') {
steps {
sh "trivy fs . > [Link]"
The stage view would look like this,
Step 8 — Docker Image Build and Push
We need to install the Docker tool in our system, Goto Dashboard →
Manage Plugins → Available plugins → Search for Docker and install these
plugins
Docker
Docker Commons
Docker Pipeline
Docker API
docker-build-step
and click on install without restart
Now, goto Dashboard → Manage Jenkins → Tools →
Add DockerHub Username and Password under Global Credentials
stage("Docker Build & Push"){
steps{
script{
withDockerRegistry(credentialsId: 'docker', toolName:
'docker'){
sh "docker build -t amazon ."
sh "docker tag amazon hanvitha/amazon:latest "
sh "docker push hanvitha/amazon:latest "
stage("TRIVY"){
steps{
sh "trivy image hanvitha/amazon:latest > [Link]"
You will see the output below, with a dependency trend.
When you log in to Dockerhub, you will see a new image is created
Now Run the container to see if the game coming up or not by
adding the below stage
stage('Deploy to container'){
steps{
sh 'docker run -d --name amazon -p 3000:3000
hanvitha/amazon:latest'
<Jenkins-public-ip:3000>
You will get this output