Phase 6 · Testing, Delivery & ProductionModule 45~66 min read

CI/CD & Release Automation

Build a secure pipeline for clean installs, checks, tests, artifacts, migrations, staged deployments, and rollback-aware releases.

What you'll learn

A delivery pipeline turns one reviewed commit into a verified immutable artifact, then promotes that artifact through environments with least privilege, controlled migrations, health checks, and rollback or roll-forward procedures.

By the end of this lesson, you'll be able to:

  • Build deterministic CI gates
  • Minimize workflow permissions
  • Promote immutable artifacts
  • Design safe deployment and migration order

Core mental model

Node.js becomes easier when you separate the JavaScript language from the runtime and the operating-system capabilities it exposes. Use this table as a decision guide.

ConceptWhat it meansDecision rule
Quality gateA required automated checkKeep lint, typecheck, tests, build, and security evidence explicit
Artifact promotionMoving one built artifact between environmentsNever rebuild different bytes for production
Deployment strategyHow old and new versions overlapSelect rolling, blue-green, or canary from risk and capacity

Professional workflow

Build and verify Node.js programs from the terminal in small, observable steps.

  1. Define the delivery pipeline boundary: inputs, outputs, invariants, ownership, and expected failures.
  2. Design the data or message contract before choosing implementation details.
  3. Implement the smallest correct path with dependencies passed explicitly.
  4. Add validation, failure translation, cleanup, and concurrency behavior.
  5. Verify the boundary with realistic data and at least one adversarial case.
  6. Measure or observe the behavior before optimizing or extracting abstractions.

Keep the feedback loop short

Run the smallest useful command after every meaningful change. Read the complete error message before editing again, and keep inputs and outputs visible while you learn.

Guided code lab

Create a least-privilege Node gate

Clean locked installs and explicit permissions make the workflow reproducible and constrain token authority.

.github/workflows/ci.yml
name: ci
on: [push, pull_request]
permissions:
  contents: read
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: 24
          cache: npm
      - run: npm ci
      - run: npm run lint
      - run: npm run typecheck
      - run: npm test
      - run: npm run build

Production practice

Contract

A release links commit, checks, dependency graph, artifact digest, migration version, approvals, deployment evidence, and recovery action.

Verification

Test clean runners, failed gates, fork permissions, artifact checksums, migration failure, health-check failure, rollback, and concurrent deploy prevention.

Operations

Use short-lived federated credentials, protected environments, pinned actions, signed provenance, deploy locks, and release audit trails.

Common failure mode

Building again during production deployment can ship bytes different from the artifact that passed tests.

Independent workshop

Create a complete CI/CD design for the containerized API.

Your finished workshop must include:

  • PR quality gates
  • Dependency/security scan
  • Immutable image artifact
  • Protected deployment job
  • Migration sequence
  • Rollback drill

Definition of done

Run the happy path and at least two edge cases, keep responsibilities separated, and add a short README explaining how to run the program.

Recap & quick check

Key takeaways

  • CI starts clean
  • Permissions stay minimal
  • Artifacts are immutable
  • Migrations span versions
  • Recovery is designed before release

Quick check

1. What should production promote?

2. Why declare workflow permissions?

3. What must migrations tolerate?

Next: Observability: Logs, Metrics & Traces