This project demonstrates a DevSecOps infrastructure deployment pipeline using Terraform, AWS CodeBuild/CodePipeline, Semgrep (SAST), and OWASP ZAP (DAST).
The pipeline automatically provisions AWS infrastructure, deploys a web server, and performs security scans against the deployed application.
This project demonstrates modern Infrastructure as Code (IaC) and DevSecOps practices used in cloud engineering environments.
This repository contains Terraform configurations used to deploy AWS infrastructure and a CI/CD pipeline that performs security validation.
The pipeline performs the following actions:
- Install Terraform
- Run Semgrep static security scans
- Initialize Terraform
- Create AWS infrastructure
- Deploy an EC2 web server
- Wait for the application to respond
- Run OWASP ZAP dynamic security scanning
This demonstrates a full DevSecOps workflow integrating infrastructure automation with automated security validation.
Developer Push
│
▼
GitHub Repository
│
▼
AWS CodeBuild / CodePipeline
│
├── Pre-Build Stage
│ Install Terraform
│ Run Semgrep (SAST)
│
├── Build Stage
│ terraform init
│ terraform plan
│ terraform apply
│
├── Application Deployment
│ Launch EC2 Instance
│ Install Nginx
│ Configure security headers
│
└── Post-Build Security Testing
Wait for application
Run OWASP ZAP (DAST)
Terraform provisions the following AWS resources:
- VPC
- Public subnet
- Internet gateway
- Route table
- Security group
- EC2 instance
- Web server (Nginx)
The deployed EC2 instance runs Nginx configured with multiple security headers.
The deployed web server includes the following HTTP security headers:
- X-Frame-Options
- X-Content-Type-Options
- Content-Security-Policy
- Permissions-Policy
- X-XSS-Protection
- Referrer-Policy
These help mitigate common web vulnerabilities such as:
- clickjacking
- MIME sniffing
- cross-site scripting
- data leakage
terraform_example/
│
├── main.tf # Terraform infrastructure definition
├── buildspec.yml # CodeBuild pipeline configuration
├── Dockerfile # Container configuration
└── README.md
The Terraform configuration creates:
CIDR: 192.168.0.0/20
CIDR: 192.168.1.0/24
Availability Zone: us-east-2a
Allows:
HTTP (port 80)
from anywhere (0.0.0.0/0)
Instance type:
t2.micro
The instance installs and runs Nginx automatically using user_data.
The pipeline consists of three stages.
Installs Terraform and runs Semgrep security scans.
terraform -version
pip install semgrep
semgrep --config=p/ci --error
Semgrep performs static application security testing (SAST).
Terraform deploys infrastructure.
terraform init
terraform plan
terraform apply
The pipeline captures the deployed server's public IP:
terraform output -raw app_dns
The pipeline waits for the application to become available and then runs OWASP ZAP.
docker run zaproxy/zap-stable
OWASP ZAP performs dynamic application security testing (DAST).
- Terraform
- AWS
- AWS VPC
- AWS EC2
- AWS Security Groups
- AWS CodeBuild / CodePipeline
- Semgrep (SAST)
- OWASP ZAP (DAST)
- Nginx
To run this project locally you need:
- Terraform
- AWS CLI
- Docker
- Python
Configure AWS credentials:
aws configure
Verify authentication:
aws sts get-caller-identity
Clone the repository:
git clone https://github.com/Rtr665052/CodePipeline_Terraform.git
cd CodePipeline_Terraform
Initialize Terraform:
terraform init
Deploy infrastructure:
terraform apply
Once deployed, Terraform outputs the public IP of the application.
After deployment, open a browser and navigate to:
http://<EC2_PUBLIC_IP>
You should see the Nginx default page.
This project demonstrates several modern DevSecOps principles:
- Infrastructure as Code
- automated infrastructure deployment
- static security scanning
- dynamic security scanning
- secure web server configuration
- automated cloud provisioning
Possible improvements include:
- adding TLS with AWS ACM
- implementing private subnets
- using an Application Load Balancer
- adding Terraform remote state
- integrating additional security tools
- adding automated rollback pipelines
This project demonstrates skills in:
- Terraform infrastructure automation
- AWS cloud architecture
- CI/CD pipeline integration
- DevSecOps security scanning
- automated infrastructure deployment
Consider adding an open-source license such as:
MIT
Apache 2.0