Phase 7 · Platform DeliveryModule 47~58 min read

CI/CD & Team Workflow

Create a reproducible delivery pipeline with reviews, analysis, tests, builds, protected secrets, artifacts, promotion, and rollback drills.

What you'll learn

Create a reproducible delivery pipeline with reviews, analysis, tests, builds, protected secrets, artifacts, promotion, and rollback drills. The lesson turns the APIs into a repeatable engineering workflow instead of a collection of isolated snippets.

By the end of this lesson, you'll be able to:

  • Apply Git and review in a production-shaped Flutter feature
  • Apply Pinned toolchains in a production-shaped Flutter feature
  • Apply CI quality gates in a production-shaped Flutter feature
  • Apply Signing secrets in a production-shaped Flutter feature

Core mental model

Connect each API to the decision it supports. Flutter code stays maintainable when state, ownership, lifecycle, and platform boundaries are explicit.

ConceptWhat it meansDecision rule
Quality gateAn automated check required before change promotionRun formatting, analysis, tests, and representative builds on every review
Artifact promotionThe same verified binary moves through release environmentsAvoid rebuilding source differently after approval
Least privilegeAutomation receives only the access required for one taskScope signing and store credentials and rotate them deliberately

Professional workflow

Work in small vertical slices and keep behavior observable from the first iteration.

  1. Define the reproducible delivery pipeline boundary: user goal, inputs, visible states, ownership, and expected failures.
  2. Build the smallest working vertical slice with typed data and explicit dependencies.
  3. Represent loading, empty, success, and failure behavior where the feature can encounter them.
  4. Verify logic away from the UI, then exercise the rendered behavior at its public boundary.
  5. Inspect lifecycle, accessibility, performance, security, and platform behavior before widening the feature.
  6. Refactor only after behavior is protected by repeatable evidence.

Protect the frame

Keep build methods predictable, move side effects to explicit owners, and measure before introducing caches, isolates, or architectural layers.

Guided Flutter lab

Build a focused reproducible delivery pipeline slice

This compact example keeps the important ownership and data-flow decisions visible so the behavior is easy to extend and test.

.github/workflows/quality.yml
name: Flutter quality
on: [pull_request]

jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: subosito/flutter-action@v2
        with:
          flutter-version: 3.x # Pin the exact supported release in the real project.
          channel: stable
          cache: true
      - run: flutter pub get
      - run: dart format --output=none --set-exit-if-changed .
      - run: flutter analyze --fatal-infos
      - run: flutter test --coverage
      - run: flutter build web --release

Production practice

Contract

Define the reproducible delivery pipeline inputs, outputs, owner, lifecycle, visible states, and platform assumptions before selecting APIs or packages.

Verification

Protect pure rules with unit tests and the rendered public contract with widget or integration evidence; include one unavailable or failure case.

Operations

Keep dependencies replaceable, log actionable context without user secrets, and measure user-visible behavior before optimizing.

Common failure mode

Allowing floating SDK versions in delivery means an unchanged commit can produce different analysis, tests, generated files, or binaries over time.

Independent workshop

Extend the guided lab into a review-ready reproducible delivery pipeline feature that fits the running course portfolio app.

Your finished workshop must include:

  • Git and review
  • Pinned toolchains
  • CI quality gates
  • Signing secrets
  • Artifact promotion
  • Automated verification and a short design note

Definition of done

Demonstrate the happy path, an empty or unavailable state, and at least one failure path. Add an automated check and a short note explaining one design decision.

Recap & quick check

Key takeaways

  • Quality gate: Run formatting, analysis, tests, and representative builds on every review
  • Artifact promotion: Avoid rebuilding source differently after approval
  • Least privilege: Scope signing and store credentials and rotate them deliberately

Quick check

1. Which rule best applies to Quality gate?

2. Which rule best applies to Artifact promotion?

3. Which rule best applies to Least privilege?

Next: Production Capstone Projects