Enterprise Multibranch CI/CD Pipeline with SonarQube & Trivy — Challenge
Make a commit build, get scanned for code and image vulnerabilities, and deploy itself — with gates that block.
- Time
- 15 min
- Level
- Advanced
- Objectives
- 4 objectives
- Cost
- Low cost
Where this fits in the platform
Already built
This lab adds
- Gates that stop a vulnerable image before it is published
Before you start
Cost — Low cost
for the Jenkins instance itself; SonarQube wants ~2 GB of RAM, so a `t3.small` (~$15/month) is realistic. ECR storage for the images the pipeline pushes is inside the free tier at this scale.
The goal#
Build Enterprise Multibranch CI/CD Pipeline with SonarQube & Trivy yourself, starting from an empty directory, without following the guided steps.
Everything you need is in the criteria above. Work down them one at a time, and verify each before moving to the next.
Hands-on environment
Run it on your own machine
Run this lab on your own machine. One command starts the environment, with everything the lab needs already installed:
Everything up to and including the Trivy gate runs locally. The push and deploy stages need AWS.
You will need:
- docker
git clone https://github.com/EgyKode/EgyKode-lab.git
cd EgyKode-lab
./egykode start cicd
./egykode shellYou need Docker and Git installed. Everything else runs inside the environment. The first start downloads it and takes a few minutes; later starts are seconds.
Not sure what you already have? Run: npm run doctor — it checks and changes nothing.
Run it on AWS
This lab builds real cloud infrastructure, so it needs your own AWS account. Follow the cost and cleanup notes above — the resources are yours, and so is the bill.
Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.
Rules#
- Do not open the guided lab until you have genuinely tried.
- When something fails, read the error before you search. The error message is the lesson.
- Tear down anything billable as soon as you finish.
If you get stuck#
The guided lab is one click away at the bottom of this page. Using it is not failure — coming back and repeating the challenge afterwards is the point.
You are done when
0 of 4
The concept behind it
Next up
Lab 46 of 59 on the project path