- Continuous delivery: every change is built and kept in a deployable state. Promotion to production is possible at any time but may require a human decision or business timing. Artifacts are promoted through environments (dev → QA → staging → pre-production) and typically stop before production.
- Continuous deployment: every change that passes automated gates is deployed all the way to production automatically. This requires strong automated tests, security checks, release automation, observability, and rollback processes.

Rollback capability is critical — it’s not enough to create artifacts or backups; you must regularly test restores and rollback procedures so they work when needed. A robust rollback system often indicates a solid deployment process.
- Retrieve the artifact from the artifact repository.
- Target the appropriate environment (dev, QA, staging, pre-prod).
- Apply environment-specific configuration (secrets, resource limits, feature flags).
- Deploy or update instances/services.
- Run verification (smoke tests, health checks, performance checks).
- Confirm deployment success or trigger rollback.

Each stage should have validation gates that grow stricter as you approach production.


- Start by routing a small percentage (e.g., 5–10%) of traffic to the new version.
- Monitor key metrics (error rates, latency, business KPIs).
- Gradually increase traffic if metrics remain healthy; abort and roll back on degradation.


- Allow shipping code that is disabled or hidden until toggled on.
- Enable targeted rollouts, A/B tests, and immediate disablement when issues occur.
- Combine feature flags with canary or traffic strategies for finely controlled rollouts.


- Automate configuration management, orchestration, and health monitoring to reduce human error and toil.
- Define explicit failure triggers in quality gates (smoke tests, performance tests, security checks, business validation) so rollbacks or pauses are automatic when thresholds are breached.
- Measure rollback cost in time, money, and resources to choose appropriate strategies.

- Typical gates: smoke tests, performance tests, security checks, and business validation.
- If a gate fails, either automatically rollback or pause promotion for manual review, depending on policy.

- Traffic redirection: route traffic back to the previous environment.
- Feature toggles: disable the new feature instantly.
- Version rollback: redeploy a known-good version.
- Partial rollback: scale down the fraction of systems or traffic receiving the change.

- Keep environment files, secrets, and resource limits appropriate and versioned for each environment.
- Feature flags, API keys, database endpoints, and capacity settings typically differ between environments and must be managed securely.
- Treat database migrations as first-class changes: coordinate, version, and test migrations to avoid release failures.


- Artifact deployment across environments is the heart of CD/CD processes.
- Continuous delivery keeps artifacts production-ready; continuous deployment pushes approved changes to production automatically.
- Common deployment approaches: rolling, blue-green, canary (traffic-based), feature flags, linear/in-place, and batch updates. Each balances cost, safety, and speed.
- Make validation and automated quality gates progressively stricter from dev → production.
- Prioritize rollback capability: deployability is valuable, but fast, tested recovery is essential.
- Track metrics and observability for every deployment; use them to trigger automated rollbacks where appropriate.
- Manage configuration and secrets per environment; treat migrations with the same discipline as code.
- CI/CD automation is core to internal developer platforms and platform engineering—enabling frequent, safe, low-effort releases.
