- Balance speed with safety (deliver fast without breaking things).
- Build security in (shift-left and automated gates).
- Ensure observability and visibility (monitoring, logging, tracing).
- Provide consistency and repeatability (predictable, auditable deployments).
These are not separate concerns — reliability, speed, security, and observability must be integrated into every stage of the pipeline.
- Swati — platform/DevOps engineer building and operating the pipeline.
- Alan — infrastructure engineer using GitOps to manage infrastructure.
- Phong — application developer committing features and tests.

- Main (production-ready deployable branch; used to run integration pipelines).
- Feature (isolation for development work).
- Release (optionally used to prepare an official release containing many features).
- Hotfix (emergency fixes to production).

main while others use release branches or tags. Platform teams often prescribe conventions to ensure reproducibility and consistent pipelines.
CI/CD pipeline stages form a software delivery assembly line. Typical sequential stages (each acting as a quality gate):
- Build — compile or assemble code into an artifact.
- Test — unit, integration, UI, and end-to-end tests validate functionality.
- Scan — security scans (SAST, dependency checks, container scans, DAST).
- Package — produce versioned, immutable artifacts.
- Deploy — promote artifacts through environments (dev → QA → staging → production).
- Verify — automated or manual post-deployment validation.

- Small, frequent commits and merges into
main(small batches). - Automated builds and queued execution for concurrent merges.
- Run unit and integration tests as early as possible.
- Provide immediate, auditable feedback on failures.

- Unit tests — fast, isolated component tests (run earliest and most frequently).
- Integration tests — service-to-service or component integration validations.
- End-to-end tests — simulate a user’s journey through the system (heavier, run later).
- UI tests — browser-based tests (Selenium, Puppeteer) that are usually slower and run infrequently.

- SAST (static application security testing) — analyzes source code without execution.
- DAST (dynamic application security testing) — attacks a running application to identify runtime vulnerabilities.
- Dependency/third-party library scanning — checks for known vulnerable open-source packages.
- Artifact/container image scanning — inspects build outputs (containers, VM images).


- Versioning and immutable tags (semantic versioning or commit SHA tags).
- Security scanning on stored artifacts.
- Access control for different environments and service accounts.
- Retention policies and cleanup.


- Promote artifacts progressively through Dev, QA, Staging, and then Production.
- Use automated promotion gates and human approval gates when required (often for production).
- Support rollbacks or quick reversion capabilities to return to a known-good artifact.


- Continuous Delivery — code is always in a deployable state; a human approval step is often used to promote to production.
- Continuous Deployment — fully automates promotion to production with no human gate; requires mature automation, comprehensive testing, and robust monitoring/rollback automation.


- Fail fast — stop the pipeline as soon as a gate fails to reduce wasted work.
- Retry logic — transient failures should be retried intelligently.
- Rollback procedures — support quick reversion to a known-good artifact.
- Notifications — alert responsible teams promptly.
- Post-incident analysis — capture and learn from failures to improve the pipeline.


Continuous deployment can be powerful but increases risk if automation and test coverage are insufficient. Use it only when tests, monitoring, and rollback mechanisms are mature.
- CI/CD covers the path from source to production — it’s a foundational platform service.
- Pipeline-as-code, infrastructure-as-code, and version-controlled artifacts are essential.
- Environment promotion (dev → test → staging → production) should use immutable artifacts.
- Integrate security and observability across the pipeline (shift-left, pipelines, and runtime).
- Design pipelines to be reusable across teams — CI/CD as a service from the platform team.
- Use structured stages: integrate, build, test, scan, package, deploy, verify.
- Automate failure handling, retries, and rollback procedures.
- Practice continuous improvement — iterate on pipelines, tests, and platform capabilities.
