Push code β Auto-build β Auto-test β Auto-deploy β AI-powered monitoring
Zero manual steps. Zero cost. Production-grade DevOps.
CloudForge is a complete DevOps pipeline that demonstrates every major concept a DevOps engineer needs to know:
- β Containerization β Docker multi-stage builds
- β Infrastructure as Code β Terraform provisioning
- β Container Orchestration β Kubernetes on Minikube
- β CI/CD β GitHub Actions automated pipeline
- β Zero-downtime deploys β Kubernetes rolling updates
- β Monitoring Dashboard β Real-time build/deploy visibility
- β AI-powered log analysis β Gemini API integration
Everything runs on free tools β no cloud bills, no credit cards.
graph TB
DEV[π¨βπ» Developer] -->|git push| GH[GitHub Repository]
GH -->|trigger| CI[π GitHub Actions CI]
CI -->|lint + test| TEST[β
Jest Tests]
CI -->|build| DOCKER[π³ Docker Build]
DOCKER -->|push| GHCR[π¦ GitHub Container Registry]
GHCR -->|trigger| CD[π GitHub Actions CD]
CD -->|deploy| RENDER[π Render - Live URL]
CD -->|deploy| K8S[βΈοΈ Kubernetes - Minikube]
K8S -->|runs| POD1[Pod 1]
K8S -->|runs| POD2[Pod 2]
K8S -->|auto-scale| HPA[HPA 2-5 pods]
POD1 -->|serves| API[π Express API]
POD2 -->|serves| API
API -->|stores| DB[(PostgreSQL)]
API -->|serves| UI[π₯οΈ Dashboard UI]
API -->|logs| AI[π€ Gemini AI Summarizer]
TF[π Terraform] -->|provisions| LS[LocalStack - AWS Sim]
LS -->|creates| S3[S3 Bucket]
LS -->|creates| DDB[DynamoDB Table]
LS -->|creates| IAM[IAM Role]
style DEV fill:#F0FDFA,stroke:#14B8A6
style CI fill:#EFF6FF,stroke:#3B82F6
style CD fill:#ECFDF5,stroke:#10B981
style K8S fill:#EFF6FF,stroke:#326CE5
style RENDER fill:#ECFDF5,stroke:#10B981
style AI fill:#FFF7ED,stroke:#F59E0B
style TF fill:#F5F3FF,stroke:#7B42BC
| Tool | Version | Install |
|---|---|---|
| Node.js | β₯ 18 | nodejs.org |
| Docker Desktop | β₯ 20 | docker.com |
| Terraform | β₯ 1.0 | winget install Hashicorp.Terraform |
| Minikube | β₯ 1.30 | winget install Kubernetes.minikube |
| kubectl | β₯ 1.28 | Included with Docker Desktop |
| Git | β₯ 2.0 | git-scm.com |
cd app/backend
npm install
npm start
# Dashboard at http://localhost:3000# Build the image
docker build -t cloudforge:latest .
# Run the container
docker run -p 3000:3000 cloudforge:latest
# Dashboard at http://localhost:3000docker compose up
# App at http://localhost:3000
# LocalStack at http://localhost:4566# Start Minikube
minikube start --driver=docker
# Load image into Minikube
minikube image load cloudforge:latest
# Apply manifests
kubectl apply -f k8s/namespace.yaml
kubectl apply -f k8s/deployment.yaml
kubectl apply -f k8s/service.yaml
kubectl apply -f k8s/hpa.yaml
# Get URL
minikube service cloudforge -n cloudforge --url# Start LocalStack first
docker compose up localstack -d
# Initialize and apply Terraform
cd terraform
terraform init
terraform plan
terraform apply -auto-approve- Push this repo to GitHub
- Go to render.com β New β Blueprint
- Connect your GitHub repo
- Render auto-detects
render.yamland deploys - Your app is live at
https://cloudforge-xxxx.onrender.com
# Install Python dependencies
pip install requests python-dotenv
# Set your free Gemini API key
# Get one from https://aistudio.google.com
echo "GEMINI_API_KEY=your_key_here" >> .env
# Run the summarizer
python scripts/ai-summarizer.py
python scripts/ai-summarizer.py --type buildcloudforge/
βββ app/
β βββ backend/ # Node.js Express API
β β βββ src/
β β β βββ server.js # Entry point
β β β βββ routes/api.js # REST endpoints
β β β βββ middleware/ # Helmet, rate-limit, CORS
β β β βββ data/store.js # PostgreSQL database
β β βββ tests/ # Jest test suite
β βββ frontend/ # Static dashboard UI
β βββ index.html
β βββ css/styles.css
β βββ js/app.js
βββ terraform/ # Infrastructure as Code
β βββ provider.tf # LocalStack provider
β βββ main.tf # S3, DynamoDB, IAM
β βββ variables.tf
β βββ outputs.tf
βββ k8s/ # Kubernetes manifests
β βββ namespace.yaml
β βββ deployment.yaml # Rolling updates, health probes
β βββ service.yaml # NodePort service
β βββ hpa.yaml # Auto-scaling 2-5 pods
βββ .github/workflows/
β βββ ci.yaml # Build, test, push image
β βββ cd.yaml # Deploy on CI pass
βββ scripts/
β βββ ai-summarizer.py # Gemini-powered log analysis
β βββ deploy-local.ps1 # Minikube deploy helper
βββ Dockerfile # Multi-stage build
βββ docker-compose.yaml # App + LocalStack
βββ render.yaml # Render deploy config
βββ README.md # You are here
| Layer | Protection |
|---|---|
| HTTP Headers | Helmet.js β XSS, clickjacking, MIME sniffing |
| Rate Limiting | 100 req/15 min per IP |
| CORS | Whitelisted origins only |
| Docker | Non-root user, Alpine base, multi-stage |
| Input Validation | express-validator on all POST routes |
| SQL | Parameterized queries (no injection) |
| Secrets | .env file, never committed |
| Dependencies | npm audit in CI pipeline |
Q: Tell me about your project.
"I built CloudForge β a complete CI/CD pipeline that automates the entire software delivery process. When I push code to GitHub, it automatically runs linting and tests, builds a Docker image, pushes it to a registry, and deploys it with zero downtime using Kubernetes rolling updates.
The infrastructure is defined as code using Terraform, so I can spin up the entire environment with one command. I also built an AI-powered log analyzer that uses Google's Gemini API to read deployment logs and generate plain-English summaries β so anyone on the team can understand what happened without reading raw logs.
Everything runs on free tools β Docker, Minikube, LocalStack for AWS simulation, and GitHub Actions for CI/CD. The app is publicly deployed on Render's free tier."
Q: What was the hardest part?
"Getting zero-downtime deploys right. The key was configuring Kubernetes with
maxUnavailable: 0in the rolling update strategy, combined with proper liveness and readiness probes. The liveness probe checks/api/healthβ if it fails 3 times, Kubernetes restarts the container. The readiness probe controls when a pod receives traffic. This ensures users never see downtime during a deploy."
Q: How does the AI part work?
"The AI log summarizer reads raw deployment logs from the PostgreSQL database, formats them into a prompt, and sends them to Google's Gemini API. The API returns a structured summary β status, key events, duration, issues found, and recommendations. If the API key isn't configured, it falls back to a local pattern-matching analysis."
Licensed under the CloudForge Non-Commercial License. Commercial use requires written permission.