CI/CD Pipeline¶
Automate the path from code to production. Manual deployments are a risk, not a safety measure.
Pipeline Stages¶
A typical pipeline runs in order:
- Code quality checks — linting, formatting, static analysis
- Unit tests — fast, isolated
- Integration tests — component interactions
- Security scanning — dependency vulnerabilities, secrets detection
- Build and package
- Deploy — through the environments below
Every pull request runs stages 1–5. The same checks should run locally, through one shared task runner, so a green local run means a green pipeline.
Environments¶
How code reaches production depends on the Git Workflow.
Trunk-based:
| Environment | Trigger | Purpose |
|---|---|---|
| Preview | Pull request | Isolated build per branch, e.g. a prefixed schema |
| Production | Approved merge to main |
Live deployment |
GitFlow:
| Environment | Trigger | Purpose |
|---|---|---|
| Dev | Push to develop |
Continuous integration |
| UAT | Manual trigger | Validation and testing |
| Production | Approved merge to main |
Live deployment |
Deployment Standards¶
- Maintain rollback scripts for critical deployments
- Database migrations should be backward compatible where possible
- Production deployments should be auditable — who deployed what and when
Tooling¶
Common options (use what fits the organisation): - GitHub Actions - Azure DevOps - GitLab CI