Skip to content

Repository files navigation

πŸš€ TaskManager β€” Production-Grade ASP.NET Core + Full DevOps Pipeline

CI/CD Pipeline Security Scan Coverage Docker License: MIT

A production-ready ASP.NET Core 8 REST API with MongoDB Atlas, demonstrating end-to-end DevOps practices β€” from code to cloud.


πŸ“ Architecture Overview

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                    GitHub (Source of Truth)                    β”‚
β”‚  main branch ──→ Production    develop branch ──→ Staging      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚ push / PR
                            β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚               GitHub Actions CI/CD Pipeline                    β”‚
β”‚  Quality β†’ Tests β†’ Security Scan β†’ Build β†’ Sign β†’ Deploy       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                            β”‚ Helm upgrade
                            β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ AWS EKS Cluster ────────────────────────────┐
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                     β”‚
β”‚  β”‚  Pod 1   β”‚  β”‚  Pod 2   β”‚  β”‚  Pod 3   β”‚  ← HPA (2-10)       β”‚
β”‚  β”‚ API:8080 β”‚  β”‚ API:8080 β”‚  β”‚ API:8080 β”‚                     β”‚
β”‚  β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜                     β”‚
β”‚       β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                            β”‚
β”‚                      β”‚                                          β”‚
β”‚              β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”                                β”‚
β”‚              β”‚  Nginx Ingress β”‚  ← TLS termination              β”‚
β”‚              β”‚  + Rate Limit  β”‚                                 β”‚
β”‚              β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜                                β”‚
β”‚                      β”‚ HTTPS                                    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
               β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
               β”‚  MongoDB Atlas     β”‚  ← Managed DB (M10+)
               β”‚  (Multi-Region)    β”‚
               β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Monitoring Stack (separate namespace):
  Prometheus β†’ Grafana β†’ Alertmanager β†’ Slack/PagerDuty
  OTel Collector β†’ Jaeger (traces)
  Seq (structured logs)

🧰 Technology Stack

Category Technology
Backend ASP.NET Core 8, C# 12
Database MongoDB Atlas (cloud-managed)
Auth JWT + Refresh Token rotation
Container Docker (multi-stage, Alpine)
Orchestration Kubernetes (EKS), Helm 3
IaC Terraform (AWS EKS, VPC, Secrets)
CI/CD GitHub Actions
Registry GitHub Container Registry (GHCR)
Monitoring Prometheus + Grafana + Alertmanager
Tracing OpenTelemetry + Jaeger
Logging Serilog + Seq
Security Trivy, CodeQL, Cosign (keyless)
Networking Nginx + cert-manager (Let's Encrypt)
Testing xUnit, Moq, FluentAssertions, Bogus

πŸ“ Repository Structure

taskmanager/
β”œβ”€β”€ .github/
β”‚   β”œβ”€β”€ workflows/
β”‚   β”‚   β”œβ”€β”€ ci-cd.yml              # Main pipeline (testβ†’buildβ†’deploy)
β”‚   β”‚   β”œβ”€β”€ pr-validation.yml      # PR checks (title, size, deps)
β”‚   β”‚   └── security-scan.yml      # Weekly CodeQL + Trivy scan
β”‚   └── dependabot.yml             # Automated dependency updates
β”‚
β”œβ”€β”€ src/TaskManagerApp/
β”‚   β”œβ”€β”€ Controllers/               # API endpoints
β”‚   β”œβ”€β”€ Services/                  # Business logic
β”‚   β”œβ”€β”€ Data/                      # MongoDB context + indexes
β”‚   β”œβ”€β”€ Models/                    # Domain entities
β”‚   β”œβ”€β”€ DTOs/                      # Request/response + validators
β”‚   β”œβ”€β”€ Middleware/                # Error handling, security headers
β”‚   β”œβ”€β”€ Configuration/             # Settings classes
β”‚   └── Program.cs                 # App bootstrap + DI
β”‚
β”œβ”€β”€ tests/TaskManagerApp.Tests/    # xUnit + Moq + FluentAssertions
β”‚
β”œβ”€β”€ infra/
β”‚   β”œβ”€β”€ terraform/                 # AWS EKS + VPC + Secrets Manager
β”‚   └── helm/taskmanager/          # Helm chart (deploy, HPA, PDB, etc.)
β”‚
β”œβ”€β”€ k8s/base/                      # Raw Kubernetes manifests
β”‚
β”œβ”€β”€ monitoring/
β”‚   β”œβ”€β”€ prometheus/                # Scrape config + alerting rules
β”‚   β”œβ”€β”€ grafana/                   # Dashboards + provisioning
β”‚   β”œβ”€β”€ alertmanager/              # Routing (Slack + PagerDuty)
β”‚   └── otel-collector.yml         # OTLP β†’ Jaeger + Prometheus
β”‚
β”œβ”€β”€ nginx/nginx.conf               # Reverse proxy + rate limiting
β”œβ”€β”€ scripts/                       # setup.sh, deploy.sh helpers
β”œβ”€β”€ Dockerfile                     # Multi-stage build
└── docker-compose.yml             # Full local dev stack

⚑ Quick Start (Local Dev)

Prerequisites

  • Docker Desktop / Docker Engine 24+
  • .NET 8 SDK
  • MongoDB Atlas account (free M0 cluster works)

1. Clone & Configure

git clone https://github.com/yourusername/taskmanager.git
cd taskmanager

# Copy env template
cp .env.example .env
# Edit .env and add your MongoDB Atlas URI + JWT secret
nano .env

2. One-command setup

chmod +x scripts/setup.sh
./scripts/setup.sh dev

This will:

  • Build the .NET application
  • Run all tests
  • Start the full Docker stack (API, Nginx, Prometheus, Grafana, Seq, Redis)
  • Seed demo data

3. Access the services

Service URL Credentials
API http://localhost:8080 β€”
Swagger UI http://localhost:8080/swagger β€”
Grafana http://localhost:3001 admin / admin
Prometheus http://localhost:9090 β€”
Alertmanager http://localhost:9093 β€”
Seq Logs http://localhost:5342 β€”

Demo credentials

Admin: admin@taskmanager.com  /  Admin@1234!
User:  demo@taskmanager.com   /  Demo@1234!

πŸ”Œ API Reference

Authentication

# Register
POST /api/auth/register
{
  "email": "you@example.com",
  "username": "yourname",
  "password": "Strong@Pass1",
  "firstName": "Your",
  "lastName": "Name"
}

# Login
POST /api/auth/login
{ "email": "you@example.com", "password": "Strong@Pass1" }
# β†’ { "accessToken": "...", "refreshToken": "...", "expiresAt": "..." }

Tasks (Bearer token required)

# Create task
POST /api/tasks
Authorization: Bearer <token>
{
  "title": "Set up monitoring",
  "priority": "High",
  "dueDate": "2025-12-31T00:00:00Z",
  "tags": ["devops", "monitoring"],
  "estimatedHours": 4
}

# List tasks (paginated + filtered)
GET /api/tasks?page=1&pageSize=20&status=InProgress&priority=High

# Dashboard stats
GET /api/tasks/dashboard

πŸ—οΈ CI/CD Pipeline

push to develop/main
        β”‚
        β”œβ”€β†’ Code Quality (format check, build, NuGet audit)
        β”‚
        β”œβ”€β†’ Tests (xUnit + MongoDB service container + coverage gate 80%)
        β”‚
        β”œβ”€β†’ Security Scan (Trivy CVE scan + Hadolint Dockerfile lint)
        β”‚
        β”œβ”€β†’ Build & Push (multi-arch linux/amd64+arm64, GHCR)
        β”‚         β”œβ”€β”€ Image signing (Cosign keyless OIDC)
        β”‚         └── SBOM generation (SPDX)
        β”‚
        β”œβ”€β†’ Deploy Staging (develop branch)
        β”‚         β”œβ”€β”€ Helm upgrade --atomic
        β”‚         β”œβ”€β”€ kubectl rollout status
        β”‚         └── Smoke tests
        β”‚
        └─→ Deploy Production (main branch, after staging)
                  β”œβ”€β”€ Helm upgrade --atomic (zero-downtime rolling)
                  β”œβ”€β”€ kubectl rollout status
                  β”œβ”€β”€ Production smoke tests (3x retry)
                  β”œβ”€β”€ GitHub Release created
                  └── Auto-rollback on failure

Required GitHub Secrets

# AWS
AWS_ROLE_ARN_STAGING     # OIDC role ARN for staging
AWS_ROLE_ARN_PROD        # OIDC role ARN for production
AWS_REGION               # e.g., us-east-1

# App secrets
MONGODB_URI_STAGING
MONGODB_URI_PROD
JWT_SECRET_STAGING
JWT_SECRET_PROD

# Notifications
SLACK_WEBHOOK_URL
PAGERDUTY_INTEGRATION_KEY  # (optional)

πŸ›οΈ Infrastructure (Terraform)

cd infra/terraform

# Initialize (S3 backend)
terraform init \
  -backend-config="bucket=your-terraform-state-bucket" \
  -backend-config="region=us-east-1"

# Plan
terraform plan \
  -var="environment=production" \
  -var="mongodb_uri=$MONGODB_URI" \
  -out=tfplan

# Apply
terraform apply tfplan

Provisions:

  • VPC with public/private subnets across 3 AZs + NAT Gateways
  • EKS Cluster (v1.31) with managed node groups (On-Demand + Spot)
  • IRSA (IAM Roles for Service Accounts) β€” Secrets Manager access
  • AWS Secrets Manager with KMS encryption for app secrets
  • VPC Flow Logs to S3 (90-day retention, compliance)

πŸ“Š Monitoring & Observability

The Three Pillars

Metrics (Prometheus + Grafana)

  • HTTP request rate, error rate, p50/p95/p99 latency
  • CPU/memory per pod, GC collections, thread pool
  • Custom SLO dashboards with error budget burn rate

Traces (OpenTelemetry β†’ Jaeger)

  • Distributed tracing across HTTP requests
  • Tail-based sampling: 100% errors, 10% success
  • MongoDB query traces

Logs (Serilog β†’ Seq)

  • Structured JSON logs with correlation IDs
  • Request/response logging (duration, status, user)
  • 90-day TTL on audit logs via MongoDB TTL index

Alerting

Alert Severity Channel
API Down Critical PagerDuty + Slack
Error rate > 5% Critical Slack #alerts-critical
p95 latency > 1s Warning Slack #alerts-warnings
Pod crash-looping Critical PagerDuty + Slack
CPU > 85% Warning Slack
SLO error budget burning Critical Slack #slo-alerts

πŸ”’ Security

  • JWT authentication with refresh token rotation (7-day TTL)
  • Account lockout after 5 failed login attempts (15min)
  • bcrypt password hashing (work factor 12)
  • Rate limiting β€” 100 req/min global, 10/15min for auth endpoints
  • Security headers β€” HSTS, CSP, X-Frame-Options, etc.
  • Container security β€” non-root user, read-only filesystem, no privilege escalation
  • Kubernetes β€” NetworkPolicy, Pod Security Standards (restricted), RBAC
  • Secrets β€” AWS Secrets Manager + KMS encryption (never in env files)
  • Supply chain β€” Cosign keyless image signing + SBOM generation
  • Dependencies β€” Dependabot weekly updates + Trivy/CodeQL scheduled scans

πŸ§ͺ Testing

# Run all tests
dotnet test tests/TaskManagerApp.Tests/

# With coverage report
dotnet test tests/TaskManagerApp.Tests/ \
  --collect:"XPlat Code Coverage" \
  --results-directory coverage

# Generate HTML report
reportgenerator \
  -reports:"coverage/**/coverage.cobertura.xml" \
  -targetdir:"coverage-report" \
  -reporttypes:Html

Coverage target: 80% (enforced in CI via gate)


πŸš€ Production Deployment

# Manual deploy (usually done by CI)
chmod +x scripts/deploy.sh
./scripts/deploy.sh 20241201-abc12345 production

Zero-downtime deploys

  • Rolling update strategy (maxSurge: 1, maxUnavailable: 0)
  • Pod Disruption Budget β€” minimum 1 pod always available
  • preStop hook β€” 5s drain before SIGTERM
  • gracefulTerminationPeriod β€” 30s for in-flight requests
  • HPA β€” scales 2-10 pods on CPU/memory

🧹 Maintenance

# View logs
docker-compose logs -f api

# Restart API only
docker-compose restart api

# Update and redeploy locally
docker-compose pull && docker-compose up -d

# Check Kubernetes pod status
kubectl get pods -n taskmanager
kubectl describe pod <pod-name> -n taskmanager
kubectl logs <pod-name> -n taskmanager --follow

# Helm rollback (emergency)
helm rollback taskmanager --namespace taskmanager

πŸ“„ License

MIT License β€” see LICENSE


Built as a DevOps showcase project demonstrating industry-standard practices. Covers: CI/CD, containerization, Kubernetes, IaC, monitoring, security, and testing.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages