Modern Delivery Pipeline
CI/CD, review, runner, and deploy workflows for teams shipping apps and websites safely.
7 chapters · about 190 min end to end
- The Modern Delivery Pipeline: From Commit to Production with Agents in the LoopThe map for the whole series: what a modern software delivery pipeline actually looks like in 2026, from a keystroke on a laptop to a release in production — and where AI agents now sit inside it without ever being allowed to merge or ship on their own. The canonical commit-to-production flow, the agent-proposes/human-disposes rule, the non-negotiable best practices (trunk-based development, branch protection, one check script, build-once-deploy-many, progressive delivery, observability + rollback), the one common shape shared by five very different targets (Cloudflare web, iOS, Android, Mac, Windows), and a reference architecture for a real indie fleet — one always-on Mac mini plus several developer MacBook Pros — with the diagrams to see it all at once.Intermediate · 29 min
- The Agent-Assisted Pull Request: Review, Edit, and Merge Without Lowering the BarCh 1 said agents propose and humans dispose; this chapter makes it concrete at the busiest box on the board — the pull request. Two agents with two jobs (author and reviewer) and why they must be separate contexts, the four-layer review funnel that catches a different class of problem at each stage (ci:local, CI checks, reviewer agent, human), the review→edit→pass loop that converges a diff before a human ever looks, the exact guardrails that keep an agent from merging or touching production (least privilege, no secrets, no force-push to main, no auto-submit), branch protection and CODEOWNERS as the mechanical enforcement, the security section nobody writes (prompt injection through PR content, untrusted contributions, secrets in logs), and how to keep the quality bar going up while the speed does too — grounded in how this very repo is developed with Claude Code, npm run check, and /code-review.Intermediate · 27 min
- One Pipeline, Five Targets: Cross-Platform CI That Stays Fast and CheapCh 2 built the review funnel; this chapter builds the checks that feed it — for five platforms at once. How a single CI pipeline satisfies Cloudflare web, iOS, Android, Mac, and Windows without turning into five copy-pasted YAML files: the fail-fast DAG that runs the cheap shared checks first and only fans out to expensive platform builds if they pass, runner routing by label (free Linux in the cloud, the Mac mini for anything Apple, a Windows runner for Windows), the matrix strategy for testing across OS and versions, what's genuinely shared versus platform-specific, dependency and build caching that turns ten-minute jobs into ninety-second ones, build-once-deploy-many with artifacts passed between jobs, and how to keep the whole thing near $0 by putting each job on the cheapest machine that can run it — grounded in this repo's real npm run check and self-hosted macOS job.Intermediate · 26 min
- Your Own Build Cluster: Architecting a Mac mini + MacBook Pro FleetThe chapter the rest of the series kept assuming. How to turn one always-on Mac mini and a few developer MacBook Pros into a real, secure CI build cluster: registering self-hosted runners and labels, why the runner polls outbound so the mini needs no open ports, the hardening that makes one trusted machine safe to hold your signing identity (a dedicated runner user, an isolated signing keychain, private-repo-only, owner-gated workflows), Tailscale networking so you and your agents reach the mini without exposing it to the internet, running the mini's services (like a SwiftUI preview renderer) on the tailnet only, what to do when the single mini becomes the bottleneck (ephemeral MacBook runners, bursting to cloud), and the maintenance that keeps it healthy — pinned Xcode, disk hygiene, runner updates. The fleet from Ch 1, built for real.Intermediate · 27 min
- Shipping the Web Half: Cloudflare Preview Deploys, Promotion, and Instant RollbackThe fleet is built; now we ship from it. The web half of the pipeline, all the way to production on Cloudflare Workers: a real preview URL for every pull request so reviewers click instead of imagine, the build-once-deploy-many promotion that uploads one immutable Worker version and carries it forward, gradual deployments that send 10% of traffic to the new version before 100%, the one-command instant rollback that makes a bad deploy a thirty-second non-event, per-environment secrets and vars, and the observability (wrangler tail, analytics) that tells you a release is bad before your users do — grounded in this project's real OpenNext-on-Workers deploy (npm run check → cf:build → cf:deploy) and the upgrade path to versioned, gradual, instantly-reversible releases.Intermediate · 26 min
- Shipping the App Half: iOS, Android, Mac, and Windows Release PipelinesThe web half reverts in seconds; the app half doesn't, and that one difference reshapes everything. The four native release pipelines side by side — iOS to TestFlight and the App Store, Android through Play Console tracks, a notarized Mac app distributed directly, and a code-signed Windows app — all the same build/sign/package/distribute/update spine with four very different, store-shaped endings. Where the signing identity from Ch 4 finally gets used in anger, why each platform's 'gradual rollout' (phased release, staged rollout %) is the stores' answer to Cloudflare's traffic split, and the hard truth that there's no one-command rollback for a shipped app — so your real safety nets are halting the rollout, expediting a fix-forward, and server-side kill switches. Grounded in this project's real notarize-and-distribute Mac pipeline.Intermediate · 28 min
- After Deploy: Environments, Secrets, Observability, and the Rollback Safety NetThe series finale — the fifth act, Operate, that turns shipping from scary into calm. What happens after the deploy button: environments and promotion done right across all five targets, where every secret lives and how to scope it to least privilege (Cloudflare secrets, GitHub environments, the Mac mini keychain, store and signing certs, and OIDC short-lived tokens instead of long-lived ones), the observability that tells you a release is bad before your users do (logs, error rate, latency, crash-free rate), and the universal recovery playbook — web rollback, app rollout-halt, and the server-side feature flag that is the one kill switch that works on every platform. Where agents help triage but humans still own the recovery decision, why mean-time-to-recovery beats mean-time-between-failures, and a synthesis of the whole reference architecture from a keystroke to five production targets.Intermediate · 27 min