Deployment Gates
Automated verification between stages, and the difference between a gate and a delay.
5 to work through
-
intermediate
A pipeline has accumulated a dozen approval gates and lead time has doubled. Which gates are worth keeping?
2 min answer -
intermediate
An enterprise's deployment gates have accumulated until releases take weeks. Which gates should remain automated, which manual, and which removed?
2 min answer -
intermediate
During an outage, an engineer wants to bypass the pipeline and patch production directly. It would save 25 minutes. What is your position?
2 min answer -
advanced
On 8 March 2023 a systemd security update was applied automatically across a large fraction of Datadog's virtual machines. The restart of systemd-networkd removed routes managed by the container network plugin and took roughly half the Kubernetes nodes offline across five regions. The deployment pipeline was not involved. What failed, and which design decision allowed it?
3 min answer -
advanced Multiple choice
Your edge platform propagates configuration changes to every location within seconds. Is that a strength or a risk?
2 min answer
4 terms in this topic
Automated Release Verification
A gate that compares the new version's live signals against the old one's and decides, on stated criteria, whether to continue or revert.
practiceDeployment Gate
A condition a change must satisfy before it advances, whether evaluated by a machine or signed by a person.
practiceSignificant-Minority Trigger
A stated rule defining which changes require human review, so the reservation of manual approval is a rule rather than a judgement made under time pr…
conceptUnmanaged Change Surface
Every mechanism that can alter production without passing through the deployment pipeline - so the organisation's rollout controls apply to a fractio…
Neighbouring topics
Delivery & Release Engineering
General material on getting a change from commit to production safely and often.
Pipeline Architecture
Stages, fan-out, caching, and the difference between a pipeline and a long script.
Build Reproducibility
Pinned inputs and hermetic builds, so one commit cannot produce two different artifacts.
Artifact Management
Immutable versioned outputs, promotion between repositories, and retention policy.
Environment Strategy
How many environments earn their cost, what each proves, and what none of them prove.
Branching Models
GitFlow, trunk and release branches as delivery constraints rather than Git preferences.
Continuous Integration Discipline
Integrating to the mainline daily, and the test speed and review culture that requires.
Deployment Strategies
Rolling, blue-green, canary and shadow, and the traffic and state each one assumes.
Progressive Delivery
Separating deploy from release, and exposing a change to users in controlled increments.
Rollback & Forward Fix
When reversing is genuinely possible, and designing so that it usually is.
Database Migration Under CD
Expand-contract, backwards-compatible schema change, and migrations that cannot roll back.
GitOps
Declared desired state in version control, with a reconciler closing the gap continuously.
IaC Modules & Drift
Reusable infrastructure modules, state ownership, and detecting what changed out of band.
Policy as Code
Encoding standards as automated admission and plan-time checks instead of review comments.
Pipeline Secrets
Short-lived credentials, workload identity, and why the CI system is a prime target.
Supply-Chain Provenance
SBOMs, signed artifacts, attestation, and knowing what actually went into a build.
Flow Metrics
Work in progress, flow time and flow efficiency — where a change waits rather than moves.
Change Management vs CD
Reconciling CAB-era controls with continuous delivery without pretending either away.
Multi-Region Rollout
Ordering regions, bake time, and stopping a bad change before it becomes global.