Cloud & DevOps
Cloud-Native CI/CD Platform
GitOps pipeline with Kubernetes, Helm and progressive delivery
- Kubernetes
- Docker
- Helm
- Argo CD
- +2
Cloud & DevOps · Capstone
Code, dependencies and images scanned, with policy gates that block
Overview
Security checks placed where they are cheapest to act on. Every push is scanned for leaked secrets with Gitleaks and for risky code with Semgrep, dependencies and the built image are checked by Trivy, and Open Policy Agent rules decide whether a finding blocks the merge or is only reported. A deliberately vulnerable sample app shows each gate catching something real. It runs entirely on free GitHub Actions minutes.
What makes it stand up
Module breakdown
Gitleaks in pre-commit and in CI, with history scanning.
Semgrep rulesets tuned to cut false positives.
Trivy filesystem, image and SBOM generation.
OPA rules on severity, fix availability and exceptions.
SARIF uploads and a findings summary on each run.
After this, you will be able to
Technology stack
You receive
Keep looking
Cloud & DevOps
GitOps pipeline with Kubernetes, Helm and progressive delivery