You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Developer pushes code
β
βΌ
GitHub Actions CI pipeline:
1. Bandit SAST + Safety scan
2. Unit tests (pytest)
3. Docker build
4. Trivy container scan β CRITICAL/HIGH = pipeline fails
5. Push to ECR (main only)
6. Cosign image signing
7. Update image tag in k8s/base/*/deployment.yaml
8. Git push (triggers ArgoCD sync)
β
βΌ
ArgoCD detects git change
β
βΌ
ArgoCD syncs to EKS cluster
- Prune removed resources
- Self-heal drift
- Retry on failure (5x with backoff)
Cost Estimates (dev environment)
Resource
Approx Monthly Cost
EKS cluster
~$73
2Γ t3.medium nodes
~$60
RDS t3.medium (single-AZ)
~$60
NAT Gateways (3Γ)
~$100
ALB
~$20
CloudTrail + S3
~$5
GuardDuty
~$5
Total (dev)
~$323/month
π‘ Cost tip: Use 1 NAT gateway in dev (saves ~$67/month). Set nat_gateway_count = 1 in dev variables.
GitHub Secrets Required
Configure these in your GitHub repository settings:
AWS_ACCOUNT_ID β Your 12-digit AWS account ID
GITOPS_TOKEN β GitHub PAT with repo write access (for image tag updates)
SLACK_WEBHOOK_URL β Slack incoming webhook for deploy notifications
GitHub OIDC is used for AWS authentication β no static AWS keys needed.
Troubleshooting
# Check pod logs
kubectl logs -f deploy/auth-service -n payment-platform
# Check pod events
kubectl describe pod -l app=auth-service -n payment-platform
# Check IRSA is working (should show role ARN)
kubectl exec -it deploy/auth-service -n payment-platform -- \
aws sts get-caller-identity
# Test Secrets Manager access from pod
kubectl exec -it deploy/auth-service -n payment-platform -- \
aws secretsmanager get-secret-value --secret-id dev/payment-platform/db-auth
# ArgoCD sync status
argocd app list
argocd app sync auth-service
# Prometheus targets
kubectl port-forward svc/prometheus -n monitoring 9090:9090
# Visit: http://localhost:9090/targets
About
Secure cloud-native payment platform demonstrating real-world DevSecOps practices using AWS, Terraform, Kubernetes (EKS), GitHub Actions, ArgoCD, and observability tools with built-in security, scalability, and automation.