Skip to content
EgyKode
08 · Continuous deliveryLab 46 / 59
Challengejenkins

Enterprise Multibranch CI/CD Pipeline with SonarQube & Trivy — Challenge

Make a commit build, get scanned for code and image vulnerabilities, and deploy itself — with gates that block.

Time
15 min
Level
Advanced
Objectives
4 objectives
Cost
Low cost

Where this fits in the platform

Before you start

CostLow cost

for the Jenkins instance itself; SonarQube wants ~2 GB of RAM, so a `t3.small` (~$15/month) is realistic. ECR storage for the images the pipeline pushes is inside the free tier at this scale.

How to clean up

The goal#

Build Enterprise Multibranch CI/CD Pipeline with SonarQube & Trivy yourself, starting from an empty directory, without following the guided steps.

Everything you need is in the criteria above. Work down them one at a time, and verify each before moving to the next.

Hands-on environment

Run it on your own machine

Run this lab on your own machine. One command starts the environment, with everything the lab needs already installed:

Everything up to and including the Trivy gate runs locally. The push and deploy stages need AWS.

You will need:

  • docker
git clone https://github.com/EgyKode/EgyKode-lab.git
cd EgyKode-lab
./egykode start cicd
./egykode shell

You need Docker and Git installed. Everything else runs inside the environment. The first start downloads it and takes a few minutes; later starts are seconds.

Not sure what you already have? Run: npm run doctor — it checks and changes nothing.

Run it on AWS

This lab builds real cloud infrastructure, so it needs your own AWS account. Follow the cost and cleanup notes above — the resources are yours, and so is the bill.

Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.

Rules#

  • Do not open the guided lab until you have genuinely tried.
  • When something fails, read the error before you search. The error message is the lesson.
  • Tear down anything billable as soon as you finish.

If you get stuck#

The guided lab is one click away at the bottom of this page. Using it is not failure — coming back and repeating the challenge afterwards is the point.

You are done when

0 of 4

The concept behind it

Stuck?Open the guided lab

Next up

Lab 46 of 59 on the project path

GitHub Actions: Build, Scan and Deploy to EKSThe same pipeline as the Jenkins lab, with no server to maintain and no stored AWS credentials.55 minIntermediateBillable — destroy resources when you finish