contentintech
Intermediate

CI/CD Pipelines Cheatsheet

Quick reference for CI/CD pipelines — pipeline anatomy, stage and job syntax, triggers, caching, artifacts, environments, matrix builds, secrets, approval gates, and deployment strategies.

CICDPipelinesDeployment
NotesCheatsheet

Pipeline Anatomy

Stages and Jobs

stages:
  - build
  - test
  - deploy

build:
  stage: build
  image: node:22-alpine
  script:
    - npm ci
    - npm run build

Concepts

TermMeaning
StageOrdered phase; runs after previous succeeds
JobUnit of work; jobs in a stage run in parallel
RunnerAgent that executes a job
ArtifactBuild output passed downstream

Triggers and Rules

Conditional Execution

rules:
  - if: '$CI_PIPELINE_SOURCE == "merge_request_event"'
  - if: '$CI_COMMIT_BRANCH == "main"'
  - if: '$CI_COMMIT_TAG'
  - changes:
      - src/**/*        # only run when src changes

Common Triggers

TriggerFires on
pushCommit to a branch
merge_requestMR/PR open or update
tagVersion tag pushed
scheduleCron timer
manual / APIHuman or webhook

Cache and Artifacts

Cache Dependencies

cache:
  key:
    files: [package-lock.json]
  paths:
    - .npm/
script:
  - npm ci --cache .npm --prefer-offline

Pass Artifacts

artifacts:
  paths:
    - dist/
    - coverage/
  expire_in: 1 week
  reports:
    junit: report.xml

Matrix and Parallel

test:
  parallel:
    matrix:
      - VERSION: ["20", "22", "24"]
        OS: ["linux", "macos"]
  script: npm test

Secrets and Environments

Environment Deploy

deploy:
  environment:
    name: production
    url: https://example.com
  script: ./deploy.sh prod

OIDC (no static keys)

id_tokens:
  AWS_ID_TOKEN:
    aud: https://sts.amazonaws.com
# then assume-role-with-web-identity

Secret Rules

DoDon't
Masked + protected varsCommit keys to repo
Short-lived OIDC tokensLong-lived static creds
Fetch from Vault at runtimeecho secrets to logs

Gates and Approvals

deploy-prod:
  when: manual          # human approval
  allow_failure: false
  rules:
    - if: '$CI_COMMIT_TAG'

Deployment Strategies

StrategyDowntimeRollback
RecreateYesSlow
RollingNoMedium
Blue-GreenNoInstant (flip)
CanaryNoFast (small blast)

Canary Steps

deploy --strategy canary --weight 10
check-slo --error-rate-max 1% --window 5m
deploy --strategy canary --weight 50
deploy --strategy canary --weight 100

Section navigation