Phase 6 · Testing, Delivery & ProductionModule 48~120 min read

Phase Project: Production Delivery

Convert the secure API into a typed, containerized, observable service with CI/CD, production configuration, deployment, and operational documentation.

What you'll learn

Turn the secure API into a strict TypeScript service delivered as an immutable container through CI/CD, with complete telemetry, safe deployment, reliability targets, and operator-facing recovery documentation.

By the end of this lesson, you'll be able to:

  • Integrate typing and runtime validation
  • Deliver a verified container
  • Automate secure promotion
  • Operate with telemetry, SLOs, and runbooks

Core mental model

Node.js becomes easier when you separate the JavaScript language from the runtime and the operating-system capabilities it exposes. Use this table as a decision guide.

ConceptWhat it meansDecision rule
Release candidateOne immutable artifact eligible for promotionIdentify it by digest and commit
Operational readinessEvidence the service can be supportedRequire dashboards, alerts, runbooks, rollback, and ownership
Recovery objectiveAcceptable time and data loss after failureAlign backups and procedures to RTO/RPO

Professional workflow

Build and verify Node.js programs from the terminal in small, observable steps.

  1. Define the production delivery boundary: inputs, outputs, invariants, ownership, and expected failures.
  2. Design the data or message contract before choosing implementation details.
  3. Implement the smallest correct path with dependencies passed explicitly.
  4. Add validation, failure translation, cleanup, and concurrency behavior.
  5. Verify the boundary with realistic data and at least one adversarial case.
  6. Measure or observe the behavior before optimizing or extracting abstractions.

Keep the feedback loop short

Run the smallest useful command after every meaningful change. Read the complete error message before editing again, and keep inputs and outputs visible while you learn.

Guided code lab

Describe the release evidence

A machine-readable manifest ties source, artifact, schema, checks, and runbook into one handoff.

release-manifest.json
{
  `commit`: `abc123`,
  `image`: `registry.example/task-api@sha256:...`,
  `schemaVersion`: `014`,
  `checks`: [`lint`, `typecheck`, `test`, `scan`],
  `slo`: `99.9% successful requests over 30 days`,
  `runbook`: `docs/runbooks/task-api.md`
}

Production practice

Contract

Production handoff includes immutable artifact identity, configuration schema, migration state, deployment plan, telemetry, SLO, ownership, and recovery evidence.

Verification

Rebuild cleanly, deploy to a production-like environment, run contracts and smoke load, inject a dependency failure, rollback, and restore data.

Operations

Schedule dependency/base rebuilds, backup drills, alert reviews, capacity reviews, access audits, and post-release observation.

Common failure mode

A green CI build is only build readiness. Production readiness includes deployment, observability, recovery, and accountable ownership.

Independent workshop

Ship and present the Phase 6 production delivery portfolio artifact.

Your finished workshop must include:

  • Strict typed service
  • Scanned image
  • CI/CD pipeline
  • Production-like deployment
  • Telemetry/SLO
  • Runbooks and recovery drill

Definition of done

Run the happy path and at least two edge cases, keep responsibilities separated, and add a short README explaining how to run the program.

Recap & quick check

Key takeaways

  • One artifact moves forward
  • Runtime data stays validated
  • Deployment is tested behavior
  • Telemetry supports decisions
  • Recovery evidence earns readiness

Quick check

1. What identifies an immutable release?

2. What does RPO describe?

3. What completes production readiness?

Next: Portfolio Project: Publish a Node.js CLI Package