The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Practitioner · Module 6: Safe delivery and release engineering

Promote the Artifact, Not a Rebuild

Test one thing, ship the same thing. Promotion moves the identical artifact through stages by digest; rebuilding per environment certifies one binary and ships another.

10 min reading

Objectives

  • Explain why the tested artifact must be the deployed artifact
  • Trace an artifact from build through promotion stages by digest
  • Reject rebuild-per-environment pipelines and name their failure mode
  • Verify artifact identity at deploy time with digest comparison

Why this matters

Staging passes every check, production breaks on launch. The pipeline rebuilt the image for production with a newer base layer and a dependency resolved minutes later, and the difference hid inside two tags with the same name. The tests certified artifact A; the users received artifact B. Rebuild-per-environment makes every green suite a statement about something nobody ships. The M06 rule returns at larger scale: one version, one artifact, promoted unchanged or the tests prove nothing.

Concepts

Promotion is movement without mutation. The build stage produces an immutable artifact with a digest; test stages run against that digest; deploy stages pull that digest. Environment differences travel as config (M11 values, M13 variables), never as rebuilt code. The release record names the digest at every stage, and the L40 lab verifies equality between tested and deployed as a first-class check.

Rebuilds sneak in through plausible doors: Dockerfiles that install latest at build time, lock files ignored in one stage, base images that float between build and deploy. Each produces artifacts with the same tag and different bytes. Pin everything (bases by digest, dependencies by lock file, toolchain by version) so a rebuild would produce identical bytes; then stop rebuilding anyway, because the proof of identity is the digest comparison, not the hope of determinism.

Tag discipline supports promotion. Mutable tags (staging, latest) point at whatever arrived last and cannot answer what is deployed. Immutable release identifiers (git SHA plus build number, never reused) name one artifact forever. Promotion updates the pointer per environment; the artifact underneath never changes.

Worked example

A demo pipeline builds once, records the digest, runs checks against it, then deploys the same digest to two staged environments. The learner compares digests across stages and finds them equal. Then a rebuild step is added deliberately: same tag, different digest, checks green against a binary nobody deploys. The comparison exposes the gap the suite could not see.

Common wrong move

Tagging per environment with separate builds (api-staging, api-prod as different images). The names suggest a pipeline; the bytes are unrelated artifacts with unrelated test evidence. One build, promoted pointers, digest proof.

Quick check

An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.

Lesson feedback

No published feedback yet.

Log in and complete the lesson to leave feedback.

Exercise

Build a demo artifact once, record its digest, deploy the same digest to two staged targets, and quote the digest comparison proving identity.

Pass criteria

The record shows one build, the digest at every stage, and the quoted equality check between tested and deployed.

Sources

Log in to track progressFree account: stores only your lesson progress and quiz results.