๐Ÿ” CI/CD & GitOps

Checklist

  • Git mastery: branching (trunk-based โญ), rebase vs merge, interactive rebase, bisect, conventional commits
  • GitHub Actions: workflows, jobs, matrices, caching (Maven/Gradle/Go), reusable workflows, OIDC to AWS (no static keys โญ)
  • Pipeline stages: lint โ†’ unit test โ†’ integration test (Testcontainers) โ†’ build โ†’ SAST/dependency scan โ†’ image build โ†’ sign โ†’ push โ†’ deploy
  • GitOps with ArgoCD (or Flux): app-of-apps, sync policies, drift detection
  • Progressive delivery: Argo Rollouts canary with metric analysis
  • Monorepo vs polyrepo; affected-only builds
  • Release management: semantic versioning, changelogs, release-please
  • Supply chain security: SBOM, cosign signing, SLSA levels, Dependabot/Renovate
  • DORA metrics: deploy frequency, lead time, change failure rate, time to restore

๐Ÿงช Labs (๐ŸŸข warm-up โ†’ ๐ŸŸก core โ†’ ๐Ÿ”ด hard โ†’ โšซ boss)

  • ๐ŸŸก A monorepo CI with path filters, Java + Go matrices, and caches (< 6 min)
  • ๐Ÿ”ด OIDC to AWS (no static keys); cosign signing; SBOMs
  • ๐Ÿ”ด ArgoCD app-of-apps; Argo Rollouts canary with Prometheus analysis
  • โšซ An eval gate: PRs touching prompts/models must pass orbit-evals

๐Ÿง  Cognitive tasks

  • Measure your own DORA metrics weekly

๐Ÿ›ฐ๏ธ Orbit integration

  • Every Orbit service ships through this pipeline

Go deeper

๐Ÿงฉ Distributed & Cloud Patterns (canary, feature flags)

Resources

  • GitHub Actions docs ยท argo-cd.readthedocs.io ยท Accelerate (Forsgren, Humble, Kim) โญ ยท Continuous Delivery (Humble & Farley)