Release — Professional¶
SLSA defines provenance levels; Sigstore uses transparency logs and keyless signing; Argo Rollouts and Flagger automate progressive delivery; The Update Framework protects update metadata. At fleet scale, control-plane failure, credential compromise, registry availability, and incompatible automation become systemic risks.
Design and operations checklist¶
- Make artifacts immutable and provenance verifiable.
- Separate build, deployment, and exposure.
- Test mixed versions, migrations, and rollback.
- Bound rollout and automate stop conditions.
- Protect signing and deployment authority.
- Audit release outcomes and stale flags.
Test yourself¶
- Design release recovery after registry compromise.
- How can automated canaries approve a broken release?
- Which provenance evidence supports incident response?
- How do you avoid one global release-control bottleneck?
Further reading¶
- SLSA specification.
- Sigstore and The Update Framework documentation.
- Humble and Farley, Continuous Delivery.