Deploying means putting a new version of your app somewhere people can use it. CI has checked the code; now CD helps you release it carefully.

Do not start by automatically deploying every project to production. A safe first step is deploying to a staging environment after code reaches main.

Why environments exist

Different deployment targets need different controls.

Examples:

Environments let you apply rules to each target.

Environment secrets

Environment secrets are only available to jobs that deploy to that environment.

This prevents a staging job from accidentally using production credentials.

Example:

Approval gates

Production deployments often require manual approval.

Approval gates reduce risk by making a human confirm:

Deployment job example

jobs:
  deploy-production:
    runs-on: ubuntu-latest
    environment: production
    steps:
      - uses: actions/checkout@v4
      - run: ./deploy.sh

If the production environment requires reviewers, this job waits before running.

Rollback thinking

A deployment workflow should not only push new code. It should also support recovery.

Plan for:

Quick revision