This project is part of a DevOps technical assessment provided by Octa Byte AI Pvt Ltd. The goal is to demonstrate infrastructure provisioning using Terraform, CI/CD automation using GitHub Actions, containerization, deployment to AWS EC2, and pushing Docker images to GitHub Container Registry (GHCR).
- Cloud Provider: AWS (EC2, VPC, Subnets, IGW, Security Groups)
- CI/CD: GitHub Actions
- Infrastructure as Code: Terraform
- Containerization: Docker
- Image Registry: GitHub Container Registry (GHCR)
- App Type: Simple Flask Application
octabyte_project/
├── .github/workflows/docker-publish.yml # CI/CD GitHub Action Workflow
├── docker-app/ # Flask Application Source
│ ├── app.py
│ ├── requirements.txt
│ └── Dockerfile
├── main.tf # Terraform main configuration
├── variables.tf # Input variables
├── outputs.tf # Terraform outputs
├── terraform.tfvars # Variable values
├── terraform.tfstate # Terraform state file
├── README.md # Project documentation
Provision EC2 Instance and VPC
-
Initialize Terraform:
terraform init
-
Preview the plan:
terraform plan
-
Apply the infrastructure:
terraform apply
Output includes:
- EC2 Public IP
- VPC ID
- Subnet IDs
-
Navigate to
docker-app:cd docker-app -
Build Docker image locally:
docker build -t octabyte_project . -
Run container locally:
docker run -d -p 80:80 octabyte_project
This workflow:
- Triggers on every push to
main - Builds Docker image from
docker-app/ - Pushes image to GHCR with tag
:latest - Signs the image using
cosign
To force a rebuild:
echo "vX" > docker-app/version.txt
git add docker-app/version.txt
git commit -m "Trigger rebuild vX"
git push origin mainYou can pull the image using:
podman login ghcr.io -u <username> --password-stdin
podman pull ghcr.io/n8880/octabyte_project:latestReplace <username> with your GitHub username and use a Personal Access Token (PAT) as password.
SSH into EC2:
ssh -i ~/.ssh/<your-key>.pem ec2-user@<public-ip>Then pull and run container:
podman pull ghcr.io/n8880/octabyte_project:latest
podman run -d -p 80:80 ghcr.io/n8880/octabyte_project:latestAccess the Flask app via:
http://<EC2 Public IP>
- Terraform Provisioned Infra
- EC2 + VPC + Public Subnets
- Flask App in Docker
- CI/CD GitHub Action to GHCR
- Deployed image on EC2 using
podman - Updated
README.md
Niranjan U
GitHub: @N8880
This project is created for assessment purposes only.