release-and-deployment
Ships changes safely and often — pipelines, deployment strategies, feature flags, rollback, and database changes. Use this to design a deployment pi…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Release and deployment
Release risk is dominated by batch size. Large infrequent releases are dangerous because many changes
land at once and nobody can tell which one broke it — so teams release less often, which makes each
release larger. The loop is the problem.
Separate deploy from release
Deploying code and exposing behavior to users are different acts, and coupling them forces every
deployment to be a business decision.
Decouple with flags: deploy continuously, expose deliberately. This makes rollback a configuration
change rather than a redeployment, which is the difference between seconds and minutes at the worst
possible time.
Flags are inventory and rot. Give each an owner and a removal date; a codebase full of stale flags
has combinatorial states nobody has tested.
The pipeline is the quality gate
Automate everything between commit and production, and let the pipeline reject. Manual steps get
skipped under pressure, which is exactly when they matter.
Order gates fast-to-slow so failure is cheap: lint and unit tests, then integration, then anything
requiring a deployed environment. A pipeline slow enough to be circumvented is worse than a fast one
with fewer checks, because it will be circumvented.
Build once and promote the same artifact through environments. Rebuilding per environment means the
thing you tested is not the thing you shipped.
Roll out gradually
Expose to a small population first and watch real signals before widening. Canary or percentage
rollout turns a total failure into a contained one.
Define the abort condition before starting, with a threshold and a named decision-maker. Under
pressure, and with the change fresh, the instinct is always to wait a little longer and see.
Database changes are the asymmetric risk
Code rolls back; data does not. Make schema changes backward-compatible and multi-step: add the new
structure, write to both, migrate, switch reads, then remove the old — with the application tolerant
of both shapes throughout.
Test the migration against production-scale data. A migration that is instant on a development
dataset can lock a large table for a length of time nobody modeled.
Sources
references/sources.md in this skill lists the outside authorities that settle the questions
here — what each one is authoritative for, and what you may do with it. Check them before
answering on anything they cover, and cite what you used. Most are free to read and not free
to reproduce; the use note on each is binding.
Tooling
Pipelines: GitHub Actions, GitLab CI, CircleCI, Buildkite, Jenkins, and similar.
Continuous delivery and progressive rollout: Argo CD, Flux, Spinnaker, and similar; feature flags
for decoupling deploy from release — LaunchDarkly, Unleash, Split, and similar.
Schema migrations: Flyway, Liquibase, Alembic, and similar. Whichever you use, the property that
matters is that migrations are versioned, ordered, and applied by the pipeline rather than by a
person with a database client.
Never
- Couple deploying code to exposing behavior.
- Promote a different artifact than the one that was tested.
- Begin a rollout without a defined abort condition.
- Ship a schema change that requires the application and database to deploy simultaneously.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/technology/skills/release-and-deployment/SKILL.md