NUP recommended tools for infrastructure, containers, and deployment
Infrastructure tools enable teams to manage cloud resources, containerize applications, and automate deployments. This guide covers Infrastructure as Code (IaC), container orchestration, and environment management.
import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";
import * as awsx from "@pulumi/awsx";
// Create a VPC
const vpc = new awsx.ec2.Vpc("my-vpc", {
cidrBlock: "10.0.0.0/16",
numberOfAvailabilityZones: 3,
natGateways: {
strategy: "Single",
},
});
// Create an ECS cluster
const cluster = new aws.ecs.Cluster("my-cluster");
// Create a load-balanced Fargate service
const service = new awsx.ecs.FargateService("my-service", {
cluster: cluster.arn,
networkConfiguration: {
subnets: vpc.privateSubnetIds,
securityGroups: [],
},
desiredCount: 2,
taskDefinitionArgs: {
container: {
name: "app",
image: "nginx:latest",
cpu: 256,
memory: 512,
portMappings: [
{
containerPort: 80,
protocol: "tcp",
},
],
},
},
});
export const url = service.loadBalancer.loadBalancer.dnsName;
Container Tools
Container Runtimes
Tool
Type
Use Case
Docker
Runtime
Standard containerization
containerd
Runtime
Kubernetes default runtime
Podman
Runtime
Daemonless containers
CRI-O
Runtime
Kubernetes-native
Container Orchestration
Tool
Type
Best For
Kubernetes
Orchestration
Production workloads
Docker Compose
Orchestration
Local development
Docker Swarm
Orchestration
Simple clustering
AWS ECS
Managed
AWS-native containers
Azure Container Apps
Serverless
Serverless containers
Dockerfile Best Practices
# Use multi-stage builds
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
FROM node:20-alpine AS runner
WORKDIR /app
# Don't run as root
RUN addgroup --system --gid 1001 nodejs
RUN adduser --system --uid 1001 nextjs
# Copy only necessary files
COPY --from=builder /app/node_modules ./node_modules
COPY --chown=nextjs:nodejs . .
USER nextjs
EXPOSE 3000
ENV PORT 3000
CMD ["node", "server.js"]
This section fulfills ISO 13485 requirements for infrastructure management (6.3), production equipment (7.5.1), and validation (7.5.2), and ISO 27001 requirements for infrastructure security (A.8.20), cloud security (A.5.23), and configuration management (A.8.9).