Author: Davido Assignment 7: Complete End-to-End DevOps Pipeline
A production-ready e-commerce platform with complete DevOps automation deployed on AWS. This project demonstrates comprehensive DevOps skills across infrastructure, CI/CD, security, monitoring, and automation.
- Primary Region: us-east-1 (production)
- DR Region: us-west-2 (standby with cross-region RDS replica)
- Compute: Amazon EKS (Kubernetes) with managed node groups
- Database: Amazon RDS PostgreSQL with read replica
- Caching: Amazon ElastiCache (Redis) for session management
- CDN: Amazon CloudFront with WAF integration
- Messaging: Amazon SQS/SNS for event-driven architecture
- Security: AWS WAF, Shield Standard, Secrets Manager, RBAC
- GitOps: ArgoCD for declarative Kubernetes deployments
| Service | Port | Description |
|---|---|---|
| user-service | 3001 | User registration, authentication, profiles |
| product-service | 3002 | Product catalog management |
| cart-service | 3003 | Shopping cart (Redis-backed) |
| payment-service | 3004 | Payment processing (SQS consumer) |
| order-service | 3005 | Order management (SQS/SNS publisher) |
assign7/
├── microservices/ # 5 Node.js microservices with Dockerfiles
├── terraform/ # Infrastructure as Code (AWS us-east-1)
│ └── dr/ # Disaster Recovery infrastructure (us-west-2)
├── kubernetes/ # K8s manifests (deployments, services, RBAC, HPA, network policies)
│ └── argocd/ # GitOps configuration (ArgoCD)
├── monitoring/ # Prometheus, Grafana, ELK, X-Ray configs
├── ansible/ # Configuration management playbooks
├── cicd/ # GitHub Actions CI/CD pipeline
├── scripts/ # Deploy, rollback, and load test scripts
└── docs/ # Architecture, API, runbooks, DR, cost analysis
- AWS CLI configured with appropriate permissions
- Terraform >= 1.5.0
- kubectl
- Docker
- Helm 3
- k6 (for load testing)
cd terraform
cp terraform.tfvars.example terraform.tfvars
# Edit terraform.tfvars with your values
terraform init
terraform plan
terraform applyaws eks update-kubeconfig --name davido-ecommerce-eks --region us-east-1kubectl apply -f kubernetes/namespaces.yaml
kubectl apply -f kubernetes/rbac.yaml
kubectl apply -f kubernetes/configmaps.yaml
kubectl apply -f kubernetes/secrets.yaml
kubectl apply -f kubernetes/deployments/
kubectl apply -f kubernetes/services/
kubectl apply -f kubernetes/ingress.yaml
kubectl apply -f kubernetes/hpa.yaml
kubectl apply -f kubernetes/network-policies.yaml
kubectl apply -f kubernetes/pdb.yaml# Prometheus + Grafana
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
helm install prometheus prometheus-community/kube-prometheus-stack \
-n monitoring -f monitoring/prometheus/values.yaml
# ELK Stack
helm repo add elastic https://helm.elastic.co
helm install elasticsearch elastic/elasticsearch -n logging -f monitoring/elk/values.yaml
helm install kibana elastic/kibana -n logging
helm install filebeat elastic/filebeat -n logging
# X-Ray
kubectl apply -f monitoring/xray-daemonset.yaml# Install ArgoCD
kubectl apply -f kubernetes/argocd/install.yaml
helm repo add argo https://argoproj.github.io/argo-helm
helm install argocd argo/argo-cd --namespace argocd \
--set server.service.type=LoadBalancer
# Deploy the GitOps application and project
kubectl apply -f kubernetes/argocd/project.yaml
kubectl apply -f kubernetes/argocd/application.yaml
# Get ArgoCD admin password
kubectl -n argocd get secret argocd-initial-admin-secret -o jsonpath="{.data.password}" | base64 -dcd terraform/dr
terraform init
terraform plan
terraform apply./scripts/load-test.sh http://<ALB_DNS_NAME>The GitHub Actions pipeline (.github/workflows/pipeline.yaml) automates:
- Build & Test - npm test for all services
- Container Build - Docker build + push to ECR
- Security Scan - Trivy vulnerability scanning
- Blue-Green Deploy - Rolling update to EKS
- Health Verification - Post-deploy health checks
- Auto-Rollback - Automatic rollback on failure
- Architecture Diagrams
- API Documentation
- Operations Runbooks
- Disaster Recovery
- Cost Analysis
- Load Testing Results
- AWS WAF with rate limiting, SQL injection, and common attack protection
- AWS Shield Standard for DDoS protection
- Secrets Manager for credential management
- Kubernetes RBAC with least-privilege service accounts
- VPC with private subnets, NAT gateway, and flow logs
- EKS secret encryption with KMS
- ECR image scanning on push
- Container security scanning with Trivy in CI/CD
- Kubernetes Network Policies for pod-to-pod traffic isolation
- Prometheus + Grafana: Metrics collection and visualization
- ELK Stack: Centralized logging (Elasticsearch, Kibana, Filebeat)
- AWS X-Ray: Distributed tracing
- CloudWatch: Custom dashboards and alarms
Davido - Complete End-to-End DevOps Pipeline