跳到主要内容
知仓学习社ZHICANG

release-and-deployment

Ships changes safely and often — pipelines, deployment strategies, feature flags, rollback, and database changes. Use this to design a deployment pi…

不碰外部(只输出文字)无严重或高危命中cbrock84/headcount

它会碰到什么

扫了多少2 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Release and deployment

Release risk is dominated by batch size. Large infrequent releases are dangerous because many changes

land at once and nobody can tell which one broke it — so teams release less often, which makes each

release larger. The loop is the problem.

Separate deploy from release

Deploying code and exposing behavior to users are different acts, and coupling them forces every

deployment to be a business decision.

Decouple with flags: deploy continuously, expose deliberately. This makes rollback a configuration

change rather than a redeployment, which is the difference between seconds and minutes at the worst

possible time.

Flags are inventory and rot. Give each an owner and a removal date; a codebase full of stale flags

has combinatorial states nobody has tested.

The pipeline is the quality gate

Automate everything between commit and production, and let the pipeline reject. Manual steps get

skipped under pressure, which is exactly when they matter.

Order gates fast-to-slow so failure is cheap: lint and unit tests, then integration, then anything

requiring a deployed environment. A pipeline slow enough to be circumvented is worse than a fast one

with fewer checks, because it will be circumvented.

Build once and promote the same artifact through environments. Rebuilding per environment means the

thing you tested is not the thing you shipped.

Roll out gradually

Expose to a small population first and watch real signals before widening. Canary or percentage

rollout turns a total failure into a contained one.

Define the abort condition before starting, with a threshold and a named decision-maker. Under

pressure, and with the change fresh, the instinct is always to wait a little longer and see.

Database changes are the asymmetric risk

Code rolls back; data does not. Make schema changes backward-compatible and multi-step: add the new

structure, write to both, migrate, switch reads, then remove the old — with the application tolerant

of both shapes throughout.

Test the migration against production-scale data. A migration that is instant on a development

dataset can lock a large table for a length of time nobody modeled.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions

here — what each one is authoritative for, and what you may do with it. Check them before

answering on anything they cover, and cite what you used. Most are free to read and not free

to reproduce; the use note on each is binding.

Tooling

Pipelines: GitHub Actions, GitLab CI, CircleCI, Buildkite, Jenkins, and similar.

Continuous delivery and progressive rollout: Argo CD, Flux, Spinnaker, and similar; feature flags

for decoupling deploy from release — LaunchDarkly, Unleash, Split, and similar.

Schema migrations: Flyway, Liquibase, Alembic, and similar. Whichever you use, the property that

matters is that migrations are versioned, ordered, and applied by the pipeline rather than by a

person with a database client.

Never

  • Couple deploying code to exposing behavior.
  • Promote a different artifact than the one that was tested.
  • Begin a rollout without a defined abort condition.
  • Ship a schema change that requires the application and database to deploy simultaneously.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。