preprint وصول مفتوح

Implementing DevSecOps in CI/CD Pipelines for 3-Tier Web Applications: A Security-First Approach Using Jenkins, SonarQube, Trivy, and Kubernetes

  • Zenodo (CERN European Organization for Nuclear Research)
  • European Organization for Nuclear Research
Research footprint

At a glance

الاستشهادات
0
المراجع
0
Comments
0
Paper overview

Abstract

This paper presents the design and implementation of a comprehensive DevSecOps CI/CD pipeline for a 3-tier web application comprising a React.js frontend, Node.js backend API, and MySQL database. The pipeline is built using Jenkins as the automation engine and integrates multi-layer security tooling including GitLeaks for secret detection, SonarQube for Static Application Security Testing (SAST), and Trivy for filesystem and container image vulnerability scanning. A manual production approval gate ensures human oversight before deployment. The application is containerized using Docker and deployed to Amazon EKS (Elastic Kubernetes Service) on AWS in the ap-south-1 region using Kubernetes manifests for all three tiers. Slack notifications provide real-time pipeline visibility. The study demonstrates that integrating security at every stage of the CI/CD pipeline — the shift-left security model — significantly reduces the risk of credential leakage, dependency vulnerabilities, and container misconfigurations reaching production. The complete implementation is publicly available at https://github.com/jatin8318/DevSecOps-CI-CD-Pipeline-for-a-3-Tier-Web-Application

Record transparency

Publication details

DOI
10.5281/zenodo.20441671
OpenAlex
W7162763828
Document type
preprint
Language
EN
Source
Zenodo (CERN European Organization for Nuclear Research)
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.