CRMS DevSecOps Pipeline Design
19-gate security pipeline across 6 layers.
Designed for production deployment on AWS EKS.
Target implementation: after Week 16 DevOps foundation.
Gitleaks / TruffleHog — secret scanning. BLOCKS on any finding.
Hadolint — Dockerfile lint. BLOCKS on errors.
Checkov — IaC + K8s manifest scan. BLOCKS on HIGH/CRITICAL.
TerraSecure — ML-powered Terraform scan (custom tool). BLOCKS on HIGH risk.
Bandit — SAST for Python. BLOCKS on HIGH severity.
ESLint security plugin — SAST for TypeScript.
SonarQube — quality gate. BLOCKS if gate fails.
DEPENDENCY + SUPPLY CHAIN
Snyk — dependency CVE scan. BLOCKS on HIGH/CRITICAL.
Syft — SBOM generation in CycloneDX format. Stored as pipeline artifact.
Docker build
Trivy — image scan. BLOCKS on HIGH/CRITICAL CVEs.
Push to AWS ECR.
DEPLOYMENT + RUNTIME SECURITY
ArgoCD sync → EKS staging environment
OWASP ZAP — DAST against staging. BLOCKS on HIGH alerts.
OPA — admission control policy check. BLOCKS non-compliant workloads.
Prometheus smoke test — response time + error rate health check.
Manual approval gate (or auto-promote if all gates pass)
ArgoCD promote → EKS production
Slack/email deployment alert with security summary
Tool
Reason
TerraSecure
Own ML model — catches Terraform misconfigs others miss
Syft SBOM
Compliance requirement — proves full software supply chain visibility
OWASP ZAP
Only tool that tests the RUNNING application, not just code
OPA
Policy as code — security rules enforced at Kubernetes level
Gitleaks
Prevents secrets from ever entering git history
Push to GitHub
│
▼
┌─────────────────────────────────────────┐
│ PRE-FLIGHT GATES (4) │
│ Gate 1: TruffleHog - Secret Scan │
│ Gate 2: Hadolint - Dockerfile Lint │
│ Gate 3: Checkov - IaC Security │
│ Gate 4: TerraSecure - ML IaC Scan │
└─────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────┐
│ SAST GATES (3) │
│ Gate 5: Bandit - Python SAST │
│ Gate 6: ESLint Security - TS SAST │
│ Gate 7: SonarQube - Quality Gate │
└─────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────┐
│ SUPPLY CHAIN GATES (2) │
│ Gate 8: Snyk - Dependency CVE Scan │
│ Gate 9: Syft - SBOM Generation │
└─────────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────┐
│ RUNTIME GATES (3) │
│ Gate 10: OWASP ZAP - DAST Scan │
│ Gate 11: OPA - Policy Validation │
│ Gate 12: Vault - Secrets Check │
└─────────────────────────────────────────┘
│
▼
DEPLOY (ArgoCD → EKS)
Gate
Tool
What it catches
Blocks?
1
TruffleHog
AWS keys, tokens, passwords in code
Yes
2
Hadolint
Dockerfile bad practices, root user
Yes
3
Checkov
Terraform misconfigs, K8s security
Reports
4
TerraSecure
ML-detected IaC vulnerabilities
Reports
5
Bandit
SQL injection, weak crypto in Python
Yes (HIGH)
6
ESLint security
XSS, prototype pollution in TypeScript
Yes
7
SonarQube
Code quality, coverage, tech debt
Yes
8
Snyk
CVEs in Python + Node dependencies
Yes (HIGH)
9
Syft SBOM
Generates software bill of materials
No (report)
10
OWASP ZAP
XSS, SQLi, auth bypass at runtime
Reports
11
OPA
K8s policy violations
Yes
12
Vault
Hardcoded secrets detection
Yes
Real findings caught during development
Finding
Gate
Severity
Fix
CVE-2024-33663 python-jose
Trivy
CRITICAL
Upgraded to 3.4.0
Kafka missing liveness probe
OPA Gate 11
HIGH
Added health check
Public EKS endpoint
Checkov Gate 3
MEDIUM
Documented as dev
No NetworkPolicy
Checkov Gate 3
MEDIUM
Added networkpolicy.yaml
Containers running as root
Checkov Gate 3
HIGH
Added runAsUser: 10001
File
Gates
.github/workflows/ci.yml
pytest + ESLint + Trivy + Docker
.github/workflows/cd.yml
GHCR push on main merge
.github/workflows/devsecops-preflight.yml
Gates 1-4
.github/workflows/devsecops-sast.yml
Gates 5-7
.github/workflows/devsecops-supply-chain.yml
Gates 8-9
.github/workflows/devsecops-dast.yml
Gate 10
.github/workflows/devsecops-policy-vault.yml
Gates 11-12
"Every commit to CRMS runs through 12 automated security gates.
We catch secrets, Dockerfile issues, IaC misconfigs, Python and
TypeScript vulnerabilities, dependency CVEs, generate an SBOM,
run DAST against the live app, validate K8s policy compliance,
and check for hardcoded secrets - all before any code reaches
production. The pipeline caught a real CRITICAL JWT CVE and a
missing Kubernetes liveness probe during development."