You cannot ship confidently without understanding what your pipeline is actually doing. Every commit triggers a chain of automated decisions — build, test, scan, deploy — and the teams at Razorpay, PhonePe, and Swiggy who ship dozens of times per day have mastered how each of those stages is designed, secured, and measured. A slow or insecure pipeline is not a tooling problem; it is a business risk that shows up as delayed features, leaked credentials, and incidents that take too long to recover from.
What This Pillar Covers
- Understanding pipeline anatomy — triggers, stages, jobs, artifacts, and environments
- Designing multi-stage pipelines with parallel job execution and proper artifact promotion
- Securing pipelines with OIDC token exchange, eliminating long-lived cloud credentials
- Managing secrets safely with GitHub Secrets, HashiCorp Vault, and AWS Secrets Manager
- Applying least-privilege access so each pipeline job has only the permissions it needs
- Measuring and improving delivery performance with the four DORA metrics
Who This Is For
DevOps engineers and backend developers building their first production pipelines or inheriting pipelines that are slow, flaky, or insecure — and who want the foundational model before diving into specific tools.
Why This Matters in Production
At Razorpay, a static AWS key accidentally committed in a GitHub Actions workflow was discovered by a secret-scanning bot within minutes — but only because someone had set one up. Without OIDC and proper secret management, long-lived credentials accumulate silently and become the most common vector for supply chain attacks. Teams that measure DORA metrics consistently reduce their lead time by 60% or more within six months simply by making the bottlenecks visible.
Prerequisites
- Familiarity with Git — commits, branches, pull requests
- Basic Docker knowledge — building and tagging images
- Understanding of Linux command line and shell scripting basics