← All demos
Aster Ridge Labs · 847219356041DT

Plumber

Point Plumber at a repo and it doesn't just deploy your app to AWS with fully working plumbing. It builds an entire CI/CD pipeline with mandatory security gates, so every change ships safely and your app stays continuously deployable.
CreatePipelines
GitHub
2App review
3Deployment
4CI/CD

aster-ridge/checkout-api

Node.js 20 · Express · listens on 8080 · no Dockerfile yet

Choose where and how you deploy

Website on a custom domainStatic or server-rendered site
Containers on ECSECS Fargate behind a load balancer
Serverless APILambda behind API Gateway
Infrastructure: AWS CloudFormation · region us-east-1 · deploys through TudovuDeployRole with GitHub OIDC

Generate the secure pipeline pull request

BackContinue
RepositoryLast runStack
customer-platformTudovu Secure Pipelinesuccess 1 hour agotudovu-customer-platform-app UPDATE_COMPLETE
checkout-apiTudovu Secure Pipelinesuccess just now · run #2211tudovu-checkout-api-app UPDATE_COMPLETE
orders-serviceTudovu Secure Pipelinepending runs after PR #42 mergesnot deployed yet
aster-ridge / checkout-apiPull requestsActionsSecurity

Add the Tudovu Secure Pipeline #57

⎇ Open tudovu wants to merge 1 commit into main from tudovu/plumber/secure-pipeline
ConversationCommits 1Checks 2Files changed 4
Files changed
+ Dockerfile multi-stage, non-root, HEALTHCHECK+ .dockerignore+ .github/workflows/tudovu-secure-pipeline.yml gates, then deploy with OIDC+ infra/checkout-api.yaml ECS Fargate service and load balancer
Opened on a branch; Tudovu never writes to your default branch. The workflow holds no AWS keys: deploys assume TudovuDeployRole through GitHub OIDC, pinned to this repository's main.
Merge pull request1 approval by priya-natarajan

Tudovu Secure Pipeline #2210

main · triggered by the merge of #57
build-test-securein progress
Build application imagerunning
Container smoke testqueued
Trivy dependency scan (blocking)queued
Semgrep policy scan (SAST)queued
CloudFormation template lintqueued
Deploy CloudFormation stackqueued
OWASP ZAP baseline (DAST)queued
Trivy dependency scan failed: 1 CRITICAL vulnerability with a fixed version available. The image never reached ECR and nothing was deployed.
priya-natarajan pushed 1 commit to main: Upgrade the vulnerable dependency to its fixed version
Tudovu

Plumber.

A CI/CD pipeline with the security gates already in it.

0:00 / 0:00