The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Professional · Module 1: Platform design and tenancy

Self-Service with Checkpoints

Self-service removes the ticket queue without removing the guardrails. Automated checkpoints verify tests, policy and budgets at deploy time; humans handle only the exceptions, and the audit trail writes itself.

10 min reading

Objectives

  • Explain what self-service promises: teams move without waiting, inside guardrails
  • Design checkpoints that verify without human queues: tests, policy, budgets
  • Keep the audit trail automatic: who shipped what, when, under which policy
  • Intervene by exception: humans review violations and appeals, not every deploy

Why this matters

Every deploy waits two days for a platform ticket: approve the namespace, approve the quota, approve the pipeline. The queue was the guardrail, and removing it feels like removing safety. So teams keep the queue, and velocity dies by a thousand approvals. Checkpoints replace the queue with verification: the same rules enforced in seconds by machinery, with humans reviewing only what the machinery flags. Same safety, none of the waiting, and the audit trail is better because machines record everything.

Concepts

Checkpoints stack at deploy time. Tests on the promoted artifact (M14's rule). Policy admission (M17's non-negotiables). Budget and quota checks (error budget healthy, quota headroom sufficient). Each checkpoint names its evidence and its failure path: blocked with the reason quoted, or flagged for human review with the context attached. A deploy that passes all checkpoints ships without a human in the path; that is the promise, and breaking it for comfort destroys trust in the whole system.

Humans review exceptions: policy violations with appeal context, budget overrides with incident references, wilderness requests with ownership plans. Exception review is fast because it is rare and context-rich; it stays rare because the checkpoints handle the routine. Review latency is a platform metric: exceptions answered in hours, not sprints.

The audit trail is a byproduct, not a chore. Every checkpoint decision logs who, what, which policy version, which evidence. Post-incident and post-audit questions answer from the log instead of from memory. The L51 delivery template wires these checkpoints in from day one, so the first service a team ships already carries the whole verification stack.

Worked example

A fictional team ships through the demo path: tests green on the digest, policy admits the manifests, quota covers the reservation, budget healthy. The deploy proceeds with zero tickets and a full log. Then a policy violation stages an exception: blocked with the quoted rule, the appeal reviewed with context, the decision recorded either way.

Common wrong move

Keeping a human approval in the standard path just in case. The approver clicks through within a week, the checkpoint that mattered rots from disuse, and the team kept the queue while believing it modernized. Automate the routine; reserve humans for genuine judgment.

Quick check

An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.

Lesson feedback

No published feedback yet.

Log in and complete the lesson to leave feedback.

Exercise

Ship a fictional service through a checkpointed path (tests, policy, quota, budget) with zero tickets, then stage one violation and record the exception review.

Pass criteria

The record shows the passed checkpoints with evidence, the zero-ticket ship, and the violation with its quoted rule and recorded decision.

Sources

Log in to track progressFree account: stores only your lesson progress and quiz results.