Let CI end at a signed, immutable artifact
A CI run should produce one thing: a container image or package identified by an immutable digest, accompanied by a provenance attestation and a software bill of materials. Tag by digest, never by a mutable label like latest. Everything downstream then refers to something that cannot silently change.
Use reusable workflows and composite actions so build logic lives in one repository rather than being copy-pasted into forty. Pin third-party actions to a commit SHA; a floating tag is a supply-chain hole.
Make delivery a reconciliation loop
ArgoCD watches a configuration repository and continuously reconciles cluster state toward it. Deployment becomes a commit that changes an image digest, which means every environment change is reviewable, revertible, and attributable without anyone holding cluster credentials.
Model environments with ApplicationSets rather than duplicated manifests. A generator over a list of clusters and overlays gives you consistent structure and one place to change a policy for every environment at once.
Control promotion and drift explicitly
Promotion from staging to production should be a pull request against the production overlay, opened automatically once staging health checks pass. Enable automated self-heal so manual cluster edits are reverted, and enable pruning so deleted manifests actually remove resources instead of leaving orphans behind.
Sync waves and health checks matter for anything with ordering constraints — databases and migrations before the workloads that depend on them.
Keep runtimes fast and observable
Cache dependency directories aggressively, shard test suites across matrix jobs, and run heavy integration suites on merge rather than on every push. Track pipeline duration and failure rate as first-class metrics; a slow pipeline is a reliability problem because it delays the fix as much as the feature.
Emit deployment events into the same observability stack as runtime metrics. Correlating a latency change with the deploy that caused it should take seconds.
Key takeaways
- CI produces immutable, signed artifacts addressed by digest — nothing more.
- ArgoCD reconciles declarative state so deploys are commits, not credentials.
- Use ApplicationSets and overlays instead of duplicated environment manifests.
- Enable self-heal and pruning to eliminate manual cluster drift.
- Treat pipeline duration and failure rate as reliability metrics.
Need a pod that already works this way?
DevGrid Staffing assembles managed DevOps, platform, and SRE pods with the compliance and delivery practices described here built in from week one.
