Intermediate
Quick reference for CI/CD pipelines — pipeline anatomy, stage and job syntax, triggers, caching, artifacts, environments, matrix builds, secrets, approval gates, and deployment strategies.
CICDPipelinesDeployment
Pipeline Anatomy
Stages and Jobs
stages:
- build
- test
- deploy
build:
stage: build
image: node:22-alpine
script:
- npm ci
- npm run build
Concepts
| Term | Meaning |
| Stage | Ordered phase; runs after previous succeeds |
| Job | Unit of work; jobs in a stage run in parallel |
| Runner | Agent that executes a job |
| Artifact | Build output passed downstream |
Triggers and Rules
Conditional Execution
rules:
- if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
- if: '$CI_COMMIT_BRANCH == "main"'
- if: '$CI_COMMIT_TAG'
- changes:
- src/**/* # only run when src changes
Common Triggers
| Trigger | Fires on |
| push | Commit to a branch |
| merge_request | MR/PR open or update |
| tag | Version tag pushed |
| schedule | Cron timer |
| manual / API | Human or webhook |
Cache and Artifacts
Cache Dependencies
cache:
key:
files: [package-lock.json]
paths:
- .npm/
script:
- npm ci --cache .npm --prefer-offline
Pass Artifacts
artifacts:
paths:
- dist/
- coverage/
expire_in: 1 week
reports:
junit: report.xml
Matrix and Parallel
test:
parallel:
matrix:
- VERSION: ["20", "22", "24"]
OS: ["linux", "macos"]
script: npm test
Secrets and Environments
Environment Deploy
deploy:
environment:
name: production
url: https://example.com
script: ./deploy.sh prod
OIDC (no static keys)
id_tokens:
AWS_ID_TOKEN:
aud: https://sts.amazonaws.com
# then assume-role-with-web-identity
Secret Rules
| Do | Don't |
| Masked + protected vars | Commit keys to repo |
| Short-lived OIDC tokens | Long-lived static creds |
| Fetch from Vault at runtime | echo secrets to logs |
Gates and Approvals
deploy-prod:
when: manual # human approval
allow_failure: false
rules:
- if: '$CI_COMMIT_TAG'
Deployment Strategies
| Strategy | Downtime | Rollback |
| Recreate | Yes | Slow |
| Rolling | No | Medium |
| Blue-Green | No | Instant (flip) |
| Canary | No | Fast (small blast) |
Canary Steps
deploy --strategy canary --weight 10
check-slo --error-rate-max 1% --window 5m
deploy --strategy canary --weight 50
deploy --strategy canary --weight 100