What you'll learn
A delivery pipeline turns one reviewed commit into a verified immutable artifact, then promotes that artifact through environments with least privilege, controlled migrations, health checks, and rollback or roll-forward procedures.
By the end of this lesson, you'll be able to:
- Build deterministic CI gates
- Minimize workflow permissions
- Promote immutable artifacts
- Design safe deployment and migration order
Core mental model
Node.js becomes easier when you separate the JavaScript language from the runtime and the operating-system capabilities it exposes. Use this table as a decision guide.
| Concept | What it means | Decision rule |
|---|---|---|
| Quality gate | A required automated check | Keep lint, typecheck, tests, build, and security evidence explicit |
| Artifact promotion | Moving one built artifact between environments | Never rebuild different bytes for production |
| Deployment strategy | How old and new versions overlap | Select rolling, blue-green, or canary from risk and capacity |
Professional workflow
Build and verify Node.js programs from the terminal in small, observable steps.
- Define the delivery pipeline boundary: inputs, outputs, invariants, ownership, and expected failures.
- Design the data or message contract before choosing implementation details.
- Implement the smallest correct path with dependencies passed explicitly.
- Add validation, failure translation, cleanup, and concurrency behavior.
- Verify the boundary with realistic data and at least one adversarial case.
- Measure or observe the behavior before optimizing or extracting abstractions.
Keep the feedback loop short
Guided code lab
Create a least-privilege Node gate
Clean locked installs and explicit permissions make the workflow reproducible and constrain token authority.
name: ci
on: [push, pull_request]
permissions:
contents: read
jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 24
cache: npm
- run: npm ci
- run: npm run lint
- run: npm run typecheck
- run: npm test
- run: npm run buildProduction practice
Contract
A release links commit, checks, dependency graph, artifact digest, migration version, approvals, deployment evidence, and recovery action.
Verification
Test clean runners, failed gates, fork permissions, artifact checksums, migration failure, health-check failure, rollback, and concurrent deploy prevention.
Operations
Use short-lived federated credentials, protected environments, pinned actions, signed provenance, deploy locks, and release audit trails.
Common failure mode
Independent workshop
Create a complete CI/CD design for the containerized API.
Your finished workshop must include:
- PR quality gates
- Dependency/security scan
- Immutable image artifact
- Protected deployment job
- Migration sequence
- Rollback drill
Definition of done
Recap & quick check
Key takeaways
- CI starts clean
- Permissions stay minimal
- Artifacts are immutable
- Migrations span versions
- Recovery is designed before release
Quick check
1. What should production promote?
2. Why declare workflow permissions?
3. What must migrations tolerate?
Next: Observability: Logs, Metrics & Traces