#CI/CD
Articles about CI/CD — exploring patterns, best practices, and real-world implementations in production systems.
16 posts tagged with ci/cd. ← All posts
A pipeline isn't a build-it-once artifact; it's a production system that needs operating. It degrades — tests get flaky, builds get slow, rollbacks get rusty — and if you can't measure your delivery, you can't improve it. This closing post is about keeping a pipeline healthy over time and using the DORA metrics to know whether your CI/CD is actually working.
A pipeline isn't a build-it-once artifact; it's a production system that needs operating. It degrades — tests get flaky, builds get slow, rollbacks get rusty — and if you can't measure your delivery, you can't improve it. This closing post covers keeping a pipeline healthy, fast recovery over rare failure, observability, and using the DORA metrics to know whether your CI/CD actually works.
The CI/CD pipeline is one of the most privileged systems in an engineering organization — it has access to source code, secrets, and the keys to production — which makes it a prime target. Worse, it can become the delivery mechanism for an attack: compromise the pipeline and you compromise everything it ships. This post is about securing the pipeline itself and building security into it, the heart of DevSecOps.
The CI/CD pipeline is one of the most privileged systems in an org — access to source, secrets, and the keys to production — which makes it a prime target and a potential delivery mechanism for an attack. This post secures the pipeline itself (least privilege, secrets, pinned deps) and builds security into it (SAST/SCA/DAST), plus supply-chain integrity: SBOM, signing, SLSA provenance.
A pipeline is only trustworthy if it's defined the same way your application is: as version-controlled code, reviewed and reproducible. "Pipeline as code" turns the path to production from clicked-together settings in a web UI into a file in your repository — and that shift, from configuration to code, brings the whole discipline of software engineering to bear on how you ship software.
A pipeline is only trustworthy if it's defined the same way your application is: as version-controlled code, reviewed and reproducible. Pipeline as code turns the path to production from clicked-together settings in a web UI into a file in your repository — bringing the whole discipline of software engineering to bear on how you ship software. The declarative model and principles for doing it well.
How you put new code into production is a design decision with real consequences for risk and downtime. Deploy it all at once and a bad release hits everyone; roll it out gradually and you can catch problems while they're small. Blue-green, canary, rolling, and feature flags are the core techniques — each trading complexity for safety in a different way. This post covers when and why to use each.
How you put new code into production is a design decision with real consequences for risk and downtime. Deploy it all at once and a bad release hits everyone; roll it out gradually and you catch problems while they're small. Blue-green, canary, rolling, and feature flags are the core techniques — each trading complexity for safety differently. When and why to use each.
The two D's in CD/CD get used interchangeably, but they name genuinely different practices with different risk profiles and different prerequisites. Getting the distinction right — and knowing which one your system is actually ready for — is the difference between a mature delivery pipeline and a dangerous one. This post draws the line clearly and covers what it takes to cross it.
The two D's in CD get used interchangeably, but they name genuinely different practices with different risk profiles and prerequisites. Continuous Delivery keeps a human approval before production; Continuous Deployment removes it. This post draws the line clearly, covers environment promotion, and helps you decide which your system is actually ready for.
The build and test stages are the engine of a pipeline — the part that decides, on every change, whether it's safe to proceed. Get them fast and trustworthy and the whole pipeline flows; get them slow or flaky and the pipeline becomes something developers route around. This post is about designing tests and builds that give a fast, reliable verdict.
The build and test stages are the engine of a pipeline — the part that decides, on every change, whether it's safe to proceed. Get them fast and trustworthy and the pipeline flows; get them slow or flaky and it becomes something developers route around. This post covers the test pyramid, deterministic tests, fail-fast staging, build-once-promote, caching, and parallelism.
Continuous Integration is the least glamorous and most important half of CI/CD. It's also the most misunderstood — teams install a build server, call it "CI," and miss the actual practice, which is a discipline about how often you merge, not which tool runs your tests. This post is about the real thing: integrating small, integrating often, and keeping the mainline always green.
Continuous Integration is the least glamorous and most important half of CI/CD, and the most misunderstood — teams install a build server, call it CI, and miss the actual practice, which is a discipline about how often you merge, not which tool runs your tests. This post is the real thing: integrate small, integrate often, keep the mainline always green.
CI/CD is one of those acronyms everyone uses and few can define precisely. Strip away the tooling and it's an answer to a simple, painful question: how do you take a change a developer just wrote and get it safely into users' hands, quickly and repeatedly, without fear? This opening post defines the terms from first principles and explains the problem they solve.
CI/CD is an answer to a simple, painful question: how do you take a change a developer just wrote and get it safely into users' hands, quickly and repeatedly, without fear? This opening post defines the terms from first principles — CI, Continuous Delivery vs Deployment, the pipeline — and explains the integration-hell and deployment-fear problems they were invented to kill.
CI/CD is the assembly line of modern software — the automated path from a developer's commit to running production code. It's the practice that turned releases from rare, terrifying events into routine, boring ones, and "boring releases" is one of the highest compliments in software. It's also the first capability any platform provides.
CI/CD is the assembly line of modern software — the automated path from a developer's commit to running production code. It turned releases from rare, terrifying events into routine, boring ones, and 'boring releases' is one of the highest compliments in software.
Beyond the interactive terminal, Claude Code can run headless in scripts and CI — which unlocks automation, and raises the stakes on permissions, review, and trust.
The capstone: running Claude Code headless in scripts and CI (PR review, batch ops, scheduled jobs) — and the guardrails it demands: least privilege, sandboxing, gating the produced artifact with human review, and the series' layered recap.
How the four families of automated security tests — static analysis, dynamic analysis, secret scanning, and instrumented runtime testing — fit together across a pipeline, and why tuning signal-to-noise matters more than adding scanners.
Automated security testing in the pipeline: SAST vs DAST vs IAST and their trade-offs, secret scanning (including git history), where each runs, and making findings actionable so false-positive fatigue doesn't get the scanner muted.
Governance is only as real as your ability to measure it. This is the MEASURE function of an AI risk program made concrete — a versioned eval set, the metric families that matter for an LLM system, and a CI gate that fails the build when quality regresses instead of just logging a warning.
Governance enforced through evaluation — the Measure function made real: build a versioned eval set, pick the metric families (quality, faithfulness, safety, bias, PII, cost/latency), and turn eval into a CI quality gate that fails the build on regression.
How to wire agent evaluations into continuous integration in Go — running a slow, model-calling eval harness under `go test`, setting per-metric thresholds that fail the build on a regression, and living honestly with the fact that these gates are softer than unit tests.
How to wire agent evaluations into continuous integration in Go — running a slow, model-calling eval harness under `go test`, setting per-metric thresholds that fail the build on a regression, and living...
The opening post of a DevSecOps series — how security stops being a gate at the end of delivery and becomes an automated, shared responsibility built into every stage of the pipeline.
The opener to a DevSecOps series: building security into the delivery lifecycle instead of bolting it on — shift-left (and shift-right), security as everyone's job, the CI/CD pipeline as the enforcement point, and the automated controls the series wires up.
The full pipeline should run in CI with zero API keys and zero network. A deterministic classifier is the test double that makes an agentic system testable.
Put the seam at the router: same interface, a deterministic classifier for tests. The whole orchestration, routing, gateway, human-in-the-loop, and checkpointing, runs in CI with zero API keys and zero network.
Treat agent output quality like a test. A baseline file plus a gate that fails the build on regression turns "the agents got worse" into a red X.
Agent systems rot because nobody catches quality regressions until users do. A committed baseline plus a gate that fails the build turns the agents got worse into a red X and a reviewable diff in the pull request.
All posts on this site are written by Pratik Dhanave, an Agentic AI Architect with 7+ years building production distributed systems, multi-agent AI platforms, and cloud-native infrastructure. About the author → Each article includes working code, architecture diagrams, and references to the specific frameworks and standards discussed. Browse all posts or explore related topics using the tag cloud above.