← Files Platform Engineering CopilotARCHIVED FILE
skills/platform-engineering/references/delivery_gitops_patterns.md
1.91 KB · Sep 30, 2026 · 23:18 UTC
# CI/CD and GitOps Patterns ## Delivery invariants Know: - source revision; - build; - artifact digest/version; - test evidence; - deployment environment; - config version; - approver/policy result; - rollout result. ## Build once, promote Prefer promoting the same tested immutable artifact between environments rather than rebuilding different artifacts per environment. ## Pipeline stages Typical shape: `commit → build → unit/static checks → package/sign → integration → deploy lower env → acceptance → approval/policy → production rollout → verification` Only include stages that serve a real risk/control. ## Credentials Prefer: - short-lived federation/workload identity; - environment-scoped permissions; - no long-lived cloud keys in repositories; - no production credential available to unrelated CI jobs. ## GitOps Desired state lives in Git. A reconciler: - compares desired vs actual; - applies changes; - reports sync/health. Define: - repo ownership; - application vs configuration separation; - environment promotion; - secret approach; - emergency change policy; - reconciliation after imperative fixes. ## Progressive delivery For high-risk changes consider: - canary; - blue/green; - percentage rollout; - feature flag; - region/tenant subset. Define: - success metric; - observation window; - automated/manual promotion; - rollback trigger. ## Rollback A rollback should be operationally possible, not just theoretically available. Check: - application backward compatibility; - schema changes; - config compatibility; - artifact availability; - data migrations; - traffic control. Sometimes forward-fix is safer than rollback; state the reason. ## Supply chain When relevant include: - dependency provenance; - artifact signing/verification; - image scanning; - SBOM; - protected branches; - review; - immutable tags/digests. Do not equate one scanner with complete supply-chain security.
SHA-256: 0057fea2cdd1b0cb58b82d8e05acbd3a933aa0318d0fe937eafd93e390d96f4d