- Promote the same immutable artifact through environments (development → QA → staging → production).
- Run environment‑specific validation (smoke tests, capacity/scalability tests, health checks).
- Update deployment manifests and GitOps configuration so clusters reconcile to the desired state.

- Minimize manual intervention (especially for Kubernetes operations).
- Bake safety and operational checks into the pipeline.
- Enable automated rollback and progressive rollout strategies when failures occur.

- Treat database migration scripts and versioned schemas as first-class artifacts.
- Use automated, versioned migrations that are coordinated with application deployments.
- Prefer backward-compatible migration patterns (expand → migrate → contract) and combine them with feature flags to avoid downtime.
Database migrations are high risk. Automate and version migrations alongside the application, and validate them with safety patterns (expand-then-migrate-then-contract, feature flags, ordered releases) to avoid outages.
- Declarative configuration — manifests in Git are the single source of truth.
- Automated reconciliation — cluster-side controllers continuously sync live state to the desired state in Git.
- Pull-based deployments — controllers pull and apply changes securely from Git into clusters.
- Complete audit trail — commits and pull requests provide traceability for every change.

- Store declarative manifests in Git.
- Run a GitOps controller (Argo CD, Flux, Rancher Fleet) inside each cluster.
- The controller pulls repositories and reconciles live cluster state to match Git.
- CI pipelines produce immutable artifacts and can update manifests in Git to reference those artifacts, which triggers reconciliation.
- Alan (infra engineer) needs to scale a database → he commits Terraform changes to Git.
- An automation tool or controller runs
terraform apply(via CI job, Atlantis, or a Terraform controller) so the change is applied reproducibly and auditable.

- CI-only heavy: CI server updates manifests and triggers deployments directly.
- GitOps-first: CI produces artifacts and updates Git; controllers pull from Git and reconcile.
- Hybrid: CI produces immutable artifacts and updates Git; controllers perform the actual cluster sync and policy enforcement.
- Developer pushes a feature branch.
- CI runs tests and builds an immutable artifact.
- CI merges into main and tags the artifact (immutable SHA).
- CI updates the deployment manifest in the GitOps repository to reference that artifact SHA.
- GitOps controller detects the manifest change and reconciles the cluster, optionally performing policy checks, health probes, and progressive promotions.

- Argo CD: strong UI, app-centric model, good for teams that want a user-friendly dashboard.
- Flux v2: Git-centric, Kubernetes-native design, integrated with Helm/Kustomize.
- Rancher Fleet: multi-cluster large-scale management.

- Build once, promote the exact same artifact across environments to minimize risk.

Plan percentages and timing against actual traffic volume and SLAs, and always combine rollouts with health checks and automated rollback triggers.

- PR validation: run pre-merge policy checks (OPA/Rego, Conftest) and static analysis on manifests.
- Admission control: enforce policies at apply/sync time with Gatekeeper or Kyverno.

- Deployment frequency — how often you deploy to production.
- Lead time for changes — time from commit to production (hour-level targets are common).
- Change failure rate / rollback rate — target high success rates (e.g., >95% without rollback).
- Time to restore — how quickly you remediate failed deployments.
- If all changes flow through Git and controllers reconcile state, drift should be rare. Teams can and do operate without manual server logins by using declarative tooling and APIs.
- Version environment manifests and use automated promotion to keep environments consistent, while preserving the ability to apply emergency fixes and environment-specific controls.

- Put platform configuration and manifests in Git; treat the platform like any customer workload.
- Automate platform deployment and testing so the platform is reproducible and versionable.

- Treat CD and GitOps as foundational: they transform manual, high-risk ops into low-risk automated workflows.
- Design pipelines with immutability, progressive delivery, policy gates, and observability built in.
- Track CD metrics and iterate on rollout strategies to match your organizational risk tolerance.
Key takeaways: automate repeatable deployments, use Git as the source of truth, promote immutable artifacts, enforce policy gates, and measure CD outcomes (deployment frequency, lead time, change failure rate).