Case Study ยท IoT ยท Docker ยท AWS ECR

IoT POC โ€” Docker / Kubernetes on EC2

Containerising an IoT telemetry stack with Docker Compose and AWS ECR, building a CI/CD pipeline that automatically rebuilds and redeploys on every push โ€” stepping stone toward AWS IoT Core and MSK.

RoleCloud & DevOps Architect
PlatformAWS EC2 ยท ECR ยท IAM
DomainIndustrial IoT
TypeContainerisation & CI/CD

An IoT stack that was impossible to deploy consistently

The IoT pipeline ran as bare processes on EC2 with manual start scripts. Every environment change meant SSH, stop, pull, restart โ€” with no consistency, rollback, or visibility into which version was running.

Goal: Containerise the entire stack, push to AWS ECR, and have GitHub Actions automatically build and redeploy on every merge to main โ€” with a clear path toward AWS IoT Core and MSK in Phase 2.

ECR-backed Docker Compose with GitHub Actions CI/CD

1
Dockerise each serviceIndividual Dockerfiles for MQTT broker, Kafka+Zookeeper, Python data consumer, Node.js simulator, React dashboard. Each image tagged with Git SHA for traceability.
2
AWS ECR private registryOne ECR repo per service. IAM role on EC2 with ECR permissions. GitHub Actions runner uses OIDC federation โ€” no long-lived AWS keys stored in secrets.
3
GitHub Actions CI/CD pipelineOn push to main: build images โ†’ push to ECR with :latest and :git-sha tags โ†’ SSH to EC2 โ†’ docker-compose pull โ†’ docker-compose up -d.
4
docker-compose migration to ECR referencesReplaced build: . directives with ECR image URIs. Added pre-pull step authenticating ECR before compose runs.
5
DynamoDB for device state persistenceTelemetry snapshots in DynamoDB. No persistent volume required โ€” state survives container restarts via DynamoDB reads on startup.

IAM, ECR auth, and container ordering

Deployments went from 20-minute manual ops to a git push

<5min
Full stack deploy time
Git SHA
Every image version traceable
0
Manual SSH deploys required
Phase 2
Ready for AWS IoT Core + MSK

Back to all projects