Learning · CI/CD

Artifacts and versioning

Build once, promote the same bits — immutable artifacts, digests, and traceability from commit to runtime.

Delivery trust starts with knowing exactly what runs. Rebuild-per-environment is how “works in staging” lies to you.

Build once

Produce a versioned artifact in CI (container image, package, binary). Promote that artifact through test → staging → production. Config differs by environment; the artifact does not.

Identity that survives debate

Prefer immutable references: git SHA, image digest, or both. Mutable tags like latest or floating v1 are operational landmines. Tags are for humans; digests are for production.

Traceability

Every deploy should answer: which commit, which pipeline run, which artifact id? Store that in release metadata, Kubernetes annotations, or your CD system — not only in Slack.

Registries and retention

Push to a controlled registry. Set retention so you can roll back to recent digests without keeping infinite garbage. Signing and vulnerability scanning belong here, not as an afterthought wiki page.

Anti-patterns

  • “We’ll rebuild the same commit on the prod runners” with different base images
  • Hand-edited images in the cluster
  • Version numbers that do not map to a commit

If you cannot point from a running pod to a commit, your CD audit trail is broken.

← CI/CD