Skip to content
EgyKode
08 · Continuous deliveryLab 45 / 59
Guided labjenkins

Jenkins Pipeline: Build, Scan and Push an Image

Take a commit to a scanned, tagged image in a registry, with a gate that blocks rather than reports.

Time
55 min
Level
Intermediate
Objectives
4 objectives
Cost
Free

Where this fits in the platform

Before you start

You will need

  • Docker
  • Jenkins with the Docker Pipeline plugin
  • A registry account

You do not need these already — the lab environment below provides them.

You will be able to

  • Build a container image from a pipeline without leaking credentials
  • Fail a build on a vulnerability rather than logging one
  • Tag images so a deployment can be traced to a commit

CostFree

— local Jenkins and a free registry account.

Nothing to pay in the browser. Open the terminal runs this against a simulated cloud — the same API calls and the same commands, with no account and no bill. The figure above applies only if you build it in your own.

How to clean up

The scenario#

The pipeline builds an image and pushes it as latest. Nobody can say which commit is in production, the scan runs after the push, and the registry password is an environment variable in the job configuration.

Hands-on environment

Run this lab in a real terminal, free and in your browser. The environment is temporary and yours alone — break it as much as you like.

Open the terminal

Opens in Killercoda, in a new tab — keep this page open for the steps.

Run it on your own machine

Run this lab on your own machine. One command starts the environment, with everything the lab needs already installed:

You will need:

  • docker
git clone https://github.com/EgyKode/EgyKode-lab.git
cd EgyKode-lab
./egykode start cicd
./egykode shell

You need Docker and Git installed. Everything else runs inside the environment. The first start downloads it and takes a few minutes; later starts are seconds.

Not sure what you already have? Run: npm run doctor — it checks and changes nothing.

Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.

The pipeline

Step 1 of 4

Clean up#

Run this even if you did not finish.

Terminal
docker image prune -af
docker logout docker.io

Cost of this lab: Free — local Jenkins and a free registry account.

Maintained by others, on Killercoda. Useful for extra repetition on one tool — it does not complete this lab or settle any criterion above.

Success criteria

0 of 4

The concept behind it

Ready to try it without help?Do the challenge

Next up

Lab 45 of 59 on the project path

Enterprise Multibranch CI/CD Pipeline with SonarQube & TrivyMake a commit build, get scanned for code and image vulnerabilities, and deploy itself — with gates that block.Why next: A commit that becomes a tagged image in the registry31 minAdvanced

Previous: Jenkins Fundamentals & Role-Based Access