ECS Platform and DevSecOps Pipeline for an Event Streaming Service
Infrastructure, pipeline and security baseline for a new Kafka-based platform
Overview
An energy sector client was launching a new Kafka-based event streaming platform that would share data with downstream consumers. It needed a production-ready ECS environment and a deployment pipeline with security checks built in before launch. I provisioned the ECS cluster and services in Terraform, built the DevSecOps pipeline, and set up Security Hub and WAF as part of the launch baseline.
Problems
A new platform needed an ECS environment provisioned from scratch, with nothing existing to build on
There was no pipeline to build, test and deploy changes safely
Security findings were not aggregated anywhere for the platform's AWS environment
Public endpoints needed protection against common web attacks before launch
Goals
Provision the ECS cluster and task definitions as code
Deploy through an automated pipeline with security checks included
Give the team one place to review security findings
Protect public endpoints at launch
What Was Done
Delivered the ECS cluster and task definitions fully in Terraform
Built the DevSecOps pipeline used for ongoing deployments
Enabled Security Hub so findings were visible from launch
Put WAF in place so public endpoints were protected from launch
Results and Impact
Platform infrastructure fully defined as code, reproducible and version-controlled
Every deployment passes through an automated pipeline with security checks
Security findings reviewed in one place through Security Hub
Public endpoints protected by WAF as part of the baseline
Stack