Artifacts and versioning
Build once, promote the same bits — immutable artifacts, digests, and traceability from commit to runtime.
Delivery trust starts with knowing exactly what runs. Rebuild-per-environment is how “works in staging” lies to you.
Build once
Produce a versioned artifact in CI (container image, package, binary). Promote that artifact through test → staging → production. Config differs by environment; the artifact does not.
Identity that survives debate
Prefer immutable references: git SHA, image digest, or both. Mutable tags like latest or floating v1 are operational landmines. Tags are for humans; digests are for production.
Traceability
Every deploy should answer: which commit, which pipeline run, which artifact id? Store that in release metadata, Kubernetes annotations, or your CD system — not only in Slack.
Registries and retention
Push to a controlled registry. Set retention so you can roll back to recent digests without keeping infinite garbage. Signing and vulnerability scanning belong here, not as an afterthought wiki page.
Anti-patterns
- “We’ll rebuild the same commit on the prod runners” with different base images
- Hand-edited images in the cluster
- Version numbers that do not map to a commit
If you cannot point from a running pod to a commit, your CD audit trail is broken.