🔄CI/CD Pipelines
Automate from commit to production. Master GitHub Actions, Docker builds, Helm deployments, ArgoCD GitOps, manual approvals, and safe rollback strategies.
Architecture & How It Works 07.1
Classic CI/CD: Source → Build → Test → Security Scan → Package → Deploy. GitOps adds the continuous reconciliation loop where Git is the single source of truth.
Core Components 07.2
| Platform | Definition File | Core Concepts |
|---|---|---|
| GitHub Actions | .github/workflows/ci.yml | jobs, steps, actions, secrets, matrix, OIDC |
| ArgoCD | Application + ApplicationSet CR | sync, self-heal, waves, generators |
| Jenkins | Jenkinsfile | declarative, stages, agent, when |
| Registry | ECR / GHCR policies | image scanning, lifecycle, signing |
WSL Hands-On Lab 07.3
GitHub Actions + Docker + Helm + ArgoCD on kind
name: Build and Deploy
on: [push]
jobs:
build:
runs-on: ubuntu-latest
permissions: { id-token: write, contents: read }
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- name: Build and push
uses: docker/build-push-action@v5
with:
push: true
tags: ghcr.io/${{ github.repository }}:${{ github.sha }}$ kind create cluster --name gitops $ kubectl create ns argocd $ kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml
- Create GitHub Actions workflow: lint → test → docker build → GHCR
- Add Helm upgrade step with image tag from commit SHA
- Run local Jenkins container and create pipeline job
- Install ArgoCD on kind and create first Application
- Practice Killercoda ArgoCD and GitHub Actions scenarios
Real-World Project 07.4
GitHub Actions free tier for Node app
CI only: lint, test, build, push.
Complete: Docker → ECR → EKS via Helm
OIDC auth, matrix strategy, Helm values per environment.
Multi-env ArgoCD + manual gates + Slack + automatic rollback on SLO breach
Troubleshooting 07.5
Check branch filter, repository secrets vs environment secrets, workflow permissions.
Inspect Application events tab, resource diffs, and sync options. Use server-side apply for CRDs.
Use OIDC with assume-role or aws-actions/configure-aws-credentials.
30-Day Roadmap 07.6
- Workflow syntax & triggers
- Secrets & variables
- Reusable workflows
- build-push-action
- Build cache
- Trivy scanning step
- Application CR
- Sync policies & waves
- ApplicationSets
- Manual approvals
- Rollback automation
- Notifications + SLO gates
Deep Dive: Enterprise Pipeline Patterns 07.7
Progressive Delivery
Use Argo Rollouts or Flagger for canary/blue-green. Gate promotions behind automated tests + manual approval. Integrate with PagerDuty or Slack for on-call sign-off.
Rollback Strategy
Always keep previous image tag in Git. Use ArgoCD automated rollback or Helm rollback. Trigger rollback automatically when SLO error budget burns too fast.