6. CI/CD & Deployment

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-04-25 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

"If it hurts, do it more often."

What is CI/CD?

  • Continuous Integration โ€” Merge code frequently, validate automatically
  • Continuous Delivery โ€” Code is always deployable
  • Continuous Deployment โ€” Every change goes to production automatically

Deployment Strategies

Big Bang

  • All at once
  • Simple but risky
  • Use only for dev/test

Rolling Update

  • Gradual replacement of instances
  • Zero downtime
  • Mixed versions during rollout

Blue-Green

  • Two identical environments
  • Instant switchover
  • Easy rollback
  • 2x infrastructure cost

Canary

  • Small % of traffic to new version
  • Monitor for errors
  • Gradually increase if healthy
  • Best for catching real-world issues

Feature Flags

  • Deploy code without enabling feature
  • Enable for specific users/% of traffic
  • Decouple deployment from release

Key Concepts

Pipeline Stages

Commit โ†’ Build โ†’ Test โ†’ Security Scan โ†’ Deploy Dev โ†’ Deploy Staging โ†’ Deploy Prod

Artifact Management

  • Build once, deploy everywhere
  • Immutable artifacts (Docker images, binaries)
  • Versioned and tagged
  • Signed and verified

Environment Promotion

Dev โ†’ Staging โ†’ Production
     (same artifact)

Topics

  • โ˜ Pipeline design patterns
  • โ˜ Build optimization (caching, parallelization)
  • โ˜ Test strategies (unit, integration, e2e)
  • โ˜ Security scanning (SAST, DAST, SCA)
  • โ˜ Deployment automation
  • โ˜ Rollback strategies
  • โ˜ Feature flags implementation
  • โ˜ Database migrations
  • โ˜ Configuration management
  • โ˜ Secrets in pipelines

Progressive Delivery

Canary Analysis

Deploy canary (5% traffic)
  โ†’ Monitor metrics (errors, latency)
    โ†’ Compare to baseline
      โ†’ Pass: Increase traffic
      โ†’ Fail: Automatic rollback

Metrics to Watch During Rollout

  • Error rate (4xx, 5xx)
  • Latency (p50, p95, p99)
  • Resource usage
  • Business metrics (conversions, revenue)

Tools

ToolPurpose
GitHub ActionsCI/CD pipelines
GitLab CICI/CD pipelines
ArgoCDKubernetes GitOps
FluxKubernetes GitOps
SpinnakerAdvanced deployment strategies
FlaggerProgressive delivery for Kubernetes
LaunchDarklyFeature flags
Argo RolloutsCanary/Blue-green for Kubernetes

Pipeline Best Practices

Fast Feedback

  • Fail fast (run quick tests first)
  • Parallelize where possible
  • Cache dependencies
  • Target: < 10 minutes for CI

Secure Pipelines

  • No secrets in code
  • Use OIDC for cloud auth
  • Scan dependencies
  • Sign artifacts
  • Audit pipeline changes

Anti-Patterns

  • Long-running pipelines (> 30 min)
  • Manual approval gates everywhere
  • No rollback plan
  • Deploying on Fridays
  • Snowflake environments
  • Testing in production (without feature flags)

Reading

  • Accelerate (Forsgren, Humble, Kim)
  • Continuous Delivery (Humble, Farley)
  • Google SRE Book: Chapter 8 (Release Engineering)

Regulatory and control mappings

Atoms

Published expressions

  • CI/CD Pipelines, how do they work? โ€” Part 1: prod is burning -- why an unguarded pipeline lets prod burn.
  • CI/CD Pipelines, how do they work? โ€” Part 2: preventing prod fires -- the build/test/deploy gates that prevent prod fires.