A deployment pipeline is a chain of evidence. Each stage should increase confidence in one specific artifact, identified by an immutable digest, and the release should deploy that same artifact. Continuous Delivery's rule is "only build your binaries once". Rebuilding for production means production runs something your tests never saw.
Where pipelines lie:
- Advisory tests.
continue-on-erroror an ignored exit code turns the test stage into decoration. Failing tests must stop the deploy. The test report should still upload, so use analways()-style step for the report, not for the gate. - Stale caches and mutable tags. Deploying
:latest, or a cache keyed on something other than the commit, can ship an older build under a green checkmark. Deploy by digest and record the source commit and digest together. - Moving tags. A published release tag is a promise. If it names the wrong commit, create a corrective release rather than silently moving it.
- No rollback target. Retain the previous known-good digest and test the rollback command, or the rollback path is untested code run during an incident.
Accelerate's four delivery measures (lead time, deployment frequency, change failure rate, and time to restore) reward exactly this discipline. Small, traceable, reversible changes make failures cheaper and recovery faster.