"If it hurts, do it more often."
What is CI/CD?
- Continuous Integration โ Merge code frequently, validate automatically
- Continuous Delivery โ Code is always deployable
- Continuous Deployment โ Every change goes to production automatically
Deployment Strategies
Big Bang
- All at once
- Simple but risky
- Use only for dev/test
Rolling Update
- Gradual replacement of instances
- Zero downtime
- Mixed versions during rollout
Blue-Green
- Two identical environments
- Instant switchover
- Easy rollback
- 2x infrastructure cost
Canary
- Small % of traffic to new version
- Monitor for errors
- Gradually increase if healthy
- Best for catching real-world issues
Feature Flags
- Deploy code without enabling feature
- Enable for specific users/% of traffic
- Decouple deployment from release
Key Concepts
Pipeline Stages
Commit โ Build โ Test โ Security Scan โ Deploy Dev โ Deploy Staging โ Deploy Prod
Artifact Management
- Build once, deploy everywhere
- Immutable artifacts (Docker images, binaries)
- Versioned and tagged
- Signed and verified
Environment Promotion
Dev โ Staging โ Production
(same artifact)
Topics
- โ Pipeline design patterns
- โ Build optimization (caching, parallelization)
- โ Test strategies (unit, integration, e2e)
- โ Security scanning (SAST, DAST, SCA)
- โ Deployment automation
- โ Rollback strategies
- โ Feature flags implementation
- โ Database migrations
- โ Configuration management
- โ Secrets in pipelines
Progressive Delivery
Canary Analysis
Deploy canary (5% traffic)
โ Monitor metrics (errors, latency)
โ Compare to baseline
โ Pass: Increase traffic
โ Fail: Automatic rollback
Metrics to Watch During Rollout
- Error rate (4xx, 5xx)
- Latency (p50, p95, p99)
- Resource usage
- Business metrics (conversions, revenue)
Tools
| Tool | Purpose |
|---|---|
| GitHub Actions | CI/CD pipelines |
| GitLab CI | CI/CD pipelines |
| ArgoCD | Kubernetes GitOps |
| Flux | Kubernetes GitOps |
| Spinnaker | Advanced deployment strategies |
| Flagger | Progressive delivery for Kubernetes |
| LaunchDarkly | Feature flags |
| Argo Rollouts | Canary/Blue-green for Kubernetes |
Pipeline Best Practices
Fast Feedback
- Fail fast (run quick tests first)
- Parallelize where possible
- Cache dependencies
- Target: < 10 minutes for CI
Secure Pipelines
- No secrets in code
- Use OIDC for cloud auth
- Scan dependencies
- Sign artifacts
- Audit pipeline changes
Anti-Patterns
- Long-running pipelines (> 30 min)
- Manual approval gates everywhere
- No rollback plan
- Deploying on Fridays
- Snowflake environments
- Testing in production (without feature flags)
Reading
- Accelerate (Forsgren, Humble, Kim)
- Continuous Delivery (Humble, Farley)
- Google SRE Book: Chapter 8 (Release Engineering)
Regulatory and control mappings
- ISO 27001 Annex A.8 Technological Controls A.8.32 Change management. A.8.25-A.8.30 secure development lifecycle. A.8.31 Separation of dev/test/prod environments.
- NIS2 Security Measures Art 21(e) secure development + change management + vulnerability handling.
- DORA Resilience Testing Art 24-25 testing programme. TLPT for significant entities.
- ITIL 4 Practices Change Enablement + Release Management + Deployment Management.
- SLSA SBOM Cluster โ build provenance + SBOM at CI/CD gates.
- Cyber Resilience Act Cluster โ for software products: vulnerability handling + security updates.
Atoms
Published expressions
- CI/CD Pipelines, how do they work? โ Part 1: prod is burning -- why an unguarded pipeline lets prod burn.
- CI/CD Pipelines, how do they work? โ Part 2: preventing prod fires -- the build/test/deploy gates that prevent prod fires.