Perancangan Dan Implementasi DAG Untuk Workflow Pipeline CI/CD DevSecOps Berbasis Jenkins

Setyawan, Delai Resgista (2026) Perancangan Dan Implementasi DAG Untuk Workflow Pipeline CI/CD DevSecOps Berbasis Jenkins. Other thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5025221221-Undergraduate_Thesis.pdf] Text
5025221221-Undergraduate_Thesis.pdf - Accepted Version
Restricted to Repository staff only

Download (5MB) | Request a copy

Abstract

Implementasi Continuous Integration dan Continuous Delivery/Deployment (CI/CD) diperlukan untuk meningkatkan konsistensi, kecepatan, dan keandalan proses pengembangan perangkat lunak. Pada lingkungan unit pengelola layanan teknologi informasi yang menjadi studi kasus, alur deployment telah berjalan hingga Kubernetes, tetapi belum terindikasi adanya pemindaian keamanan yang terintegrasi secara konsisten sebelum aplikasi diteruskan ke lingkungan production. Penelitian ini berfokus pada perancangan dan implementasi Directed Acyclic Graph (DAG) sebagai dasar penyusunan workflow pipeline CI/CD DevSecOps berbasis Jenkins. DAG digunakan untuk memodelkan ketergantungan antar-stage, kemudian topological sorting digunakan untuk mengidentifikasi kandidat stage yang dapat dijalankan secara paralel tanpa melanggar dependency. Praktik DevSecOps diterapkan melalui pemindaian keamanan menggunakan Semgrep, Snyk, Trivy, dan OWASP ZAP sebagai dasar security gate sebelum Deploy Prod, serta pengelolaan secret aplikasi menggunakan HashiCorp Vault melalui mekanisme runtime secret retrieval. Evaluasi dilakukan terhadap empat workflow, yaitu satu workflow serial dan tiga workflow paralel, berdasarkan timestamp pipeline, total waktu pipeline, durasi setiap stage, dan kompleksitas implementasi. Hasil pengujian menunjukkan bahwa seluruh workflow dapat berjalan secara end-to-end dan tetap memenuhi dependency antar-stage. Workflow paralel 3 agent menghasilkan rata-rata total waktu terendah sebesar 145,33 detik, dengan pengurangan waktu 10,49% hingga 13,17% dibandingkan workflow serial. Hasil ini menunjukkan bahwa penambahan agent dan titik paralelisasi tidak selalu menghasilkan waktu yang lebih rendah. Komparasi kualitatif-deskriptif dengan alur deployment existing menunjukkan perbedaan pada aspek kontrol keamanan sebelum deployment dan pengelolaan secret aplikasi.
======================================================================================================================================
The implementation of Continuous Integration and Continuous Delivery/Deployment (CI/CD) is required to improve consistency, speed, and reliability in software development processes. In the IT service management unit used as the case study, the deployment workflow already supports deployment to Kubernetes, but security scanning has not been indicated as a consistently integrated control before applications are promoted to the production environment. This study focuses on the design and implementation of a Directed Acyclic Graph (DAG) as the basis for constructing a Jenkins-based DevSecOps CI/CD pipeline workflow. The DAG is used to model inter-stage dependencies, while topological sorting is applied to identify candidate stages that can be executed in parallel without violating dependency constraints. DevSecOps practices are implemented through security scanning using Semgrep, Snyk, Trivy, and OWASP ZAP as inputs for a security gate before the Deploy Prod stage, as well as application secret management using HashiCorp Vault through a runtime secret retrieval mechanism. The evaluation compares four workflows, consisting of one serial workflow and three parallel workflows, based on pipeline timestamps, total pipeline time, per-stage duration, and implementation complexity. The results show that all workflows can run end-to-end while maintaining the designed inter-stage dependencies. The 3-agent parallel workflow achieves the lowest average total pipeline time of 145.33 seconds, with a time reduction ranging from 10.49% to 13.17% compared with the serial workflow. These results indicate that adding more agents and parallelization points does not always produce lower execution time. A qualitative-descriptive comparison with the existing deployment workflow shows differences in pre-deployment security controls and application secret management.

Item Type: Thesis (Other)
Uncontrolled Keywords: CI/CD, DAG, DevSecOps, Jenkins, Kubernetes, Secret Management, CI/CD, DAG, DevSecOps, Jenkins, Kubernetes, Secret Management.
Subjects: Q Science > QA Mathematics > QA76.758 Software engineering
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis
Depositing User: Delai Resgista Setyawan
Date Deposited: 24 Jul 2026 01:36
Last Modified: 24 Jul 2026 01:36
URI: http://repository.its.ac.id/id/eprint/136685

Actions (login required)

View Item View Item