# Deployment Pipeline Design > Diseña pipelines CI/CD multi-etapa con gates de aprobación, verificaciones de seguridad y orquestación de despliegues, incluyendo canary, rollback y depuración de gates fallidos. Fuente: https://skillsagentes.com/skills/wshobson/agents/deployment-pipeline-design Markdown: https://skillsagentes.com/skills/wshobson/agents/deployment-pipeline-design.md Repositorio: https://github.com/wshobson/agents Autor: wshobson Licencia: MIT Actualizado: hace 4 meses Coste de contexto: 76 tok instalada, 1.4k tok al activarse, 8.4k tok con todos los archivos del bundle Bundle: 3 archivos, 33 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add wshobson/agents --skill deployment-pipeline-design --agent claude-code # Cursor npx -y skills add wshobson/agents --skill deployment-pipeline-design --agent cursor # Codex npx -y skills add wshobson/agents --skill deployment-pipeline-design --agent codex # Gemini CLI npx -y skills add wshobson/agents --skill deployment-pipeline-design --agent gemini # Windsurf npx -y skills add wshobson/agents --skill deployment-pipeline-design --agent windsurf # Cline npx -y skills add wshobson/agents --skill deployment-pipeline-design --agent cline ``` ## Qué hace - Diseña la arquitectura de pipelines CI/CD multi-etapa con gates de aprobación y verificaciones de seguridad - Define estrategias de despliegue como canary o blue-green con configuración anotada - Configura health checks (superficiales vs profundos) y scripts de smoke test post-despliegue - Establece definiciones de gates automáticos por métricas y flujos de aprobación manual - Produce planes de rollback con triggers automáticos y pasos de runbook manual ## Cuándo usarla - Diseñar la arquitectura CI/CD para un nuevo servicio o migración de plataforma - Implementar gates de despliegue entre entornos - Configurar pipelines multi-entorno con escaneo de seguridad obligatorio - Depurar pipelines donde las etapas pasan pero el comportamiento en producción es incorrecto ## Qué la activa - "Diseña un pipeline CI/CD con despliegue canary usando Argo Rollouts" - "¿Por qué mi canary nunca promociona al 100%?" - "Ayúdame a configurar gates de aprobación entre staging y producción" - "El health check pasa en el pipeline pero el servicio está caído en producción" ## Archivos - SKILL.md — 5 KB - references/advanced-strategies.md — 16 KB - references/details.md — 12 KB ## SKILL.md Reproducido tal cual desde wshobson/agents bajo MIT. Esta sección es el documento original y está en inglés. # Deployment Pipeline Design Architecture patterns for multi-stage CI/CD pipelines with approval gates, deployment strategies, and environment promotion workflows. ## Purpose Design robust, secure deployment pipelines that balance speed with safety through proper stage organization, automated quality gates, and progressive delivery strategies. This skill covers both the structural design of pipeline architecture and the operational patterns for reliable production deployments. ## Input / Output ### What You Provide - **Application type**: Language/runtime, containerized or bare-metal, monolith or microservices - **Deployment target**: Kubernetes, ECS, VMs, serverless, or platform-as-a-service - **Environment topology**: Number of environments (dev/staging/prod), region layout, air-gap requirements - **Rollout requirements**: Acceptable downtime, rollback SLA, traffic splitting needs, canary vs blue-green preference - **Gate constraints**: Approval teams, required test coverage thresholds, compliance scans (SAST, DAST, SCA) - **Monitoring stack**: Prometheus, Datadog, CloudWatch, or other metrics sources used for automated promotion decisions ### What This Skill Produces - **Pipeline configuration**: Stage definitions, job dependencies, parallelism, and caching strategy - **Deployment strategy**: Chosen rollout pattern with annotated configuration (canary weights, blue-green switchover, rolling parameters) - **Health check setup**: Shallow vs deep readiness probes, post-deployment smoke test scripts - **Gate definitions**: Automated metric thresholds and manual approval workflows - **Rollback plan**: Automated rollback triggers and manual runbook steps ## When to Use - Design CI/CD architecture for a new service or platform migration - Implement deployment gates between environments - Configure multi-environment pipelines with mandatory security scanning - Establish progressive delivery with canary or blue-green strategies - Debug pipelines where stages succeed but production behavior is wrong - Reduce mean time to recovery by automating rollback on metric degradation ## Detailed patterns and worked examples Detailed pattern documentation lives in `references/details.md`. Read that file when the navigation tier above is insufficient. ## Troubleshooting ### Health check passes in pipeline but service is unhealthy in production The pipeline health check is hitting a shallow `/ping` endpoint that returns 200 even when the database is unreachable. Use a deep readiness check that verifies actual dependencies (see Health Checks section above). ### Canary deployment never promotes to 100% Argo Rollouts requires a valid `AnalysisTemplate` to auto-promote. If the Prometheus query returns no data (e.g., metric name changed), the analysis stays inconclusive and promotion stalls. Add `inconclusiveLimit` so the rollout fails fast rather than hanging: ```yaml spec: metrics: - name: error-rate failureCondition: "result[0] > 0.05" inconclusiveLimit: 2 # fail after 2 inconclusive results, not hang indefinitely provider: prometheus: query: | sum(rate(http_requests_total{status=~"5.."}[2m])) / sum(rate(http_requests_total[2m])) ``` ### Staging deploy succeeds but production job never starts Check that production environment protection rules are configured — a missing reviewer assignment means the approval gate waits indefinitely with no notification. In GitHub Actions, ensure `Required reviewers` is set to an existing user or team in **Settings → Environments → production**. ### Docker layer cache busted on every run causing slow builds If `COPY . .` appears before dependency installation, any source file change invalidates the dependency layer. Reorder to copy dependency manifests first: ```dockerfile # Good: dependencies cached separately from source code COPY package*.json ./ RUN npm ci COPY . . RUN npm run build ``` ### Rollback leaves database migrations applied to old code A service rollback without a migration rollback causes schema/code mismatch errors. Always make migrations backward-compatible (additive only) for at least one release cycle, and keep undo scripts versioned alongside the migration: ```bash # migrations/V20240315__add_nullable_column.sql (forward) # migrations/V20240315__add_nullable_column.undo.sql (backward) ``` Never run destructive migrations (DROP COLUMN, ALTER NOT NULL) until the old code version is fully retired from all environments. ## Advanced Topics For platform-specific pipeline configurations, multi-region promotion workflows, and advanced Argo Rollouts patterns, see: - [`references/advanced-strategies.md`](references/advanced-strategies.md) — Extended YAML examples, platform-specific configs (GitHub Actions, GitLab CI, Azure Pipelines), multi-region canary patterns, and database migration rollback strategies ## Related Skills - `github-actions-templates` - For GitHub Actions implementation patterns and reusable workflows - `gitlab-ci-patterns` - For GitLab CI/CD pipeline implementation - `secrets-management` - For secrets handling in CI/CD pipelines ## Dónde encaja - Categoría: [DevOps e infraestructura](https://skillsagentes.com/categorias/devops-infraestructura.md) — Despliegues, contenedores, IaC y flujos de gestión de incidentes. - Creador: [wshobson](https://skillsagentes.com/creators/wshobson.md) — 183 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Hermes Tweet](https://skillsagentes.com/skills/wshobson/agents/hermes-tweet.md): Instala y opera Hermes Tweet, un plugin de Hermes Agent para investigar X/Twitter, leer timelines, analizar tweets y ejecutar operaciones privadas o de cambio de estado con aprobación previa. - [Superself](https://skillsagentes.com/skills/wshobson/agents/superself.md): Úsalo cuando un proyecto guarda su estado en Superself: lee `self context` al iniciar sesión, vincula el trabajo a una work unit, reporta con evidencia y registra decisiones confirmadas. - [Grounded Vault](https://skillsagentes.com/skills/wshobson/agents/grounded-vault.md): Úsalo para mantener un almacén Markdown de conocimiento donde cada afirmación compilada se rastrea hasta una fuente inmutable y el drift se detecta con git diff sin gastar tokens. - [Postgresql Table Design](https://skillsagentes.com/skills/wshobson/agents/postgresql-table-design.md): Úsalo al diseñar o revisar un esquema específico de PostgreSQL: buenas prácticas, tipos de datos, indexación, restricciones, patrones de rendimiento y funciones avanzadas. - [Prompt Engineering Patterns](https://skillsagentes.com/skills/wshobson/agents/prompt-engineering-patterns.md): Úsalo cuando pidan optimizar un prompt, mejorar su rendimiento, diseñar una plantilla, aplicar chain-of-thought, few-shot prompting o técnicas avanzadas de prompt engineering para producción. ## Skills relacionadas - [Bazel Build Optimization](https://skillsagentes.com/skills/wshobson/agents/bazel-build-optimization.md): Optimiza builds de Bazel en monorepos a gran escala. Úsalo al configurar Bazel, implementar ejecución remota u optimizar el rendimiento de builds en codebases empresariales. - [Workflow Orchestration Patterns](https://skillsagentes.com/skills/wshobson/agents/workflow-orchestration-patterns.md): Diseña workflows duraderos con Temporal para sistemas distribuidos: separación workflow/activity, patrones saga, gestión de estado y restricciones de determinismo. - [Terraform Module Library](https://skillsagentes.com/skills/wshobson/agents/terraform-module-library.md): Construye módulos Terraform reutilizables para infraestructura AWS, Azure, GCP y OCI siguiendo buenas prácticas de infraestructura como código. - [Spark Training Gotchas](https://skillsagentes.com/skills/wshobson/agents/spark-training-gotchas.md): Preflight y diagnóstico de los diez fallos conocidos de entrenamiento ML en NVIDIA DGX Spark; úsala ante fallos de arranque, OOM bajo el límite de 128GB, caídas de throughput o antes de runs largos en GB10. - [Spark Environment Setup](https://skillsagentes.com/skills/wshobson/agents/spark-environment-setup.md): Configura un entorno de entrenamiento/inferencia de ML en NVIDIA DGX Spark (GB10, aarch64, CUDA 13): instalación de PyTorch/Unsloth/TRL/vLLM, errores ABI de libcudart y NGC vs pip. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)