Pipeline CI/CD DevSecOps sur KubernetesDevSecOps CI/CD pipeline on Kubernetes
Une chaîne Jenkins complète qui build, scanne, publie et déploie une application Java sur Kubernetes — avec la sécurité intégrée à chaque étape.A complete Jenkins chain that builds, scans, publishes and deploys a Java app to Kubernetes — with security built into every stage.
- Secrets (Gitleaks), SAST (SonarQube, Semgrep) et SCA (OWASP Dependency-Check) avant toute livraisonSecrets (Gitleaks), SAST (SonarQube, Semgrep) and SCA (OWASP Dependency-Check) before anything ships
- Artefacts versionnés dans JFrog Artifactory, images poussées sur Docker HubVersioned artifacts in JFrog Artifactory, images pushed to Docker Hub
- Déploiement Kubernetes orchestré par Ansible, vulnérabilités centralisées dans DefectDojoKubernetes deployment driven by Ansible, vulnerabilities centralised in DefectDojo
- Supervision du pipeline et du cluster avec Prometheus & GrafanaPipeline and cluster monitoring with Prometheus & Grafana
- checkoutsource
- buildbuild
- tomcatdeploy
- gitleakssecrets
- sonarqubesast
- semgrepsast
- dependency-checksca
- artifactoryartifact
- dockerimage
- k8s · ansibledeploy
- defectdojotriage