Guides
How to structure deployment jobs
Deploys are slow, risky and hard to audit.
5 min read
Deploys are slow, risky and hard to audit.
Why it happens
Build, test and deploy are entangled in one job with production credentials in scope.
How to fix it
- Separate deploy into its own job with a deployment environment
- Require reviewers on the production environment
- Use OIDC so no long-lived cloud credential exists
- Promote artefacts rather than rebuilding
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.
Related
How to scale self-hosted runnersSelf-hosted runners either queue at peak or sit idle and expensive.How to use runner groupsAny repository can schedule jobs on any runner.How to design a runner label strategyLabels grew organically and nobody knows which to use.Hosted or BYOC: how to chooseYou are unsure whether to use hosted runners or deploy into your own cloud.