Skip to content
Suiunbek Isaev
All case studies

Case study

Automated EMR Rehydration for Security Remediation

A Jenkins + Packer + Terraform Enterprise pipeline that rebuilds EMR clusters on compliant images, as self-service for multiple teams.

Result
Self-service rehydration used by multiple teams across AWS accounts
Role
Designed and built
Where
Capital One · 2025 – Present
Key stack
Jenkins · Packer · Amazon EMR · AMIs

Sanitized case study based on professional experience. Internal names, accounts, hostnames and configurations are intentionally omitted.

01Problem

Vulnerability findings on EMR clusters required remediation across multiple teams and AWS accounts. Patching long-lived clusters in place was slow, inconsistent and hard to verify.

02Context

Several teams run EMR in their own AWS accounts with different EMR versions and environments. Remediation needed to be repeatable, and teams needed to run it without platform-team hand-holding.

03Architecture

Sanitized conceptual architecture based on professional experience.

How it works

  • A vulnerability finding, or a routine refresh, starts the Jenkins pipeline. The user selects the EMR version, environment and other build variables.
  • Packer builds a custom AMI with all required packages and current patches.
  • Terraform Enterprise provisions a fresh EMR cluster from that AMI, replacing the old cluster instead of patching it in place.
  • The new cluster is validated and monitored before the old one is retired.

04Engineering approach

  1. Chose immutable rehydration over in-place patching: rebuild on a known-good image instead of mutating running clusters.
  2. Built Packer templates that bake all required packages into custom AMIs.
  3. Provisioned EMR through Terraform Enterprise, so cluster configuration is versioned and consistent.
  4. Integrated Jenkins, Packer and TFE into one parameterized pipeline that teams run themselves.

05Security

  • Remediation is built into the image, and every cluster launches from a patched baseline.
  • Consistent images across accounts reduce configuration drift.
  • Pipeline runs leave an auditable record of what was built and deployed.

06Automation

  • End-to-end pipeline from image build to cluster provisioning.
  • Parameterized for EMR version, environment and build variables.
  • Used by multiple teams across multiple AWS accounts.

07Results

  • Self-service EMR rehydration adopted by multiple teams across multiple AWS accounts.
  • Remediation became repeatable and standardized instead of manual and cluster-by-cluster.
  • Less manual work and less operational risk during remediation.

08Lessons learned

  • Immutable infrastructure turns remediation from an operation into a build.
  • Parameterize the pipeline for real variation (version, environment) and standardize everything else.

09Skills & technologies

Immutable infrastructureCI/CD pipeline designPackerTerraform EnterpriseVulnerability remediation
JenkinsPackerAmazon EMRAMIsTerraform EnterpriseAWS (multi-account)