Stage 1: Code Commit (Git / GitHub). Push to a feature branch. The pipeline claims a short-lived federated identity, so there is no long-lived cloud key to leak in the first place. Evidence: All platforms.
Stage 2: Fetch Secrets (Vault (OIDC / JWT)). CI authenticates to Vault with a short-lived token instead of a stored credential, and receives only what that repository has been explicitly granted. Evidence: Terraform-managed.
Stage 3: Build & Test (Docker / Node). Multi-stage image build with unit and integration tests, and coverage reported back into the team channel. Evidence: Reusable workflows.
Stage 4: Security Scan (Semgrep · Trivy · Gitleaks). Static analysis, dependency CVEs and secret scanning, orchestrated concurrently by grc_watcher, a Go CLI I wrote for multi-repo sweeps. Evidence: grc_watcher (Go).
Stage 5: Push Registry (Private registry). Image tagged with the commit SHA and pushed to a private registry, encrypted at rest with a customer-managed key. Evidence: Managed as code.
Stage 6: Deploy (AWS CDK / Ansible). Infrastructure and application ship as code through the same reviewed path, with schema migrations handled by a dedicated step rather than by hand. Evidence: Infrastructure as code.
Stage 7: Observe (Prometheus · Loki · Grafana). Metrics and logs flow to the self-hosted stack, where the alert rules themselves are covered by unit tests. Evidence: promtool-tested rules.
Stage 8: Alert (Alertmanager / Slack). Rules evaluate outside the dashboard layer, and a dead-man’s-switch proves the alerting path itself is still alive. Evidence: Meta-monitoring.
Stage 9: Backup & DR (GPG · Object storage). Encrypted dumps with checksum manifests, plus restores replayed into throwaway containers to prove the backup actually comes back. Evidence: Restore verification.
02 / the run
One commit. Nine gates. Zero stored keys.
idle · scroll to deploy
Code Commit
Fetch Secrets
Build & Test
Security Scan
Push Registry
Deploy
Observe
Alert
Backup & DR
$ waiting for a commit…
Scroll to push it through the pipeline ↓
ci · run #0674
$
03 / the work
Pick a level.
7 platforms, 8 bonus tools, 4 tutorial labs.
Explored
1/19
←→ walkenter play platform bonus tool tutorial lab
World 0 · Tutorial 1/4
Java Task Manager
End-to-end CI/CD on VMs. Jenkins CI/CD with SonarQube, Trivy, Harbor, Ansible and Prometheus/Grafana.