Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Design multi-stage CI/CD pipelines with approval gates, security checks, and deployment orchestration. Use when architecting deployment workflows, setting up continuous delivery, or implementing GitOps practices.
.claude/skills/asymmetric-al-deployment-pipeline-design/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 73% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 172% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 67% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 420% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 84% | 0% |
Architecture patterns for multi-stage CI/CD pipelines with approval gates and deployment strategies.
Design robust, secure deployment pipelines that balance speed with safety through proper stage organization and approval workflows.
┌─────────┐ ┌──────┐ ┌─────────┐ ┌────────┐ ┌──────────┐
│ Build │ → │ Test │ → │ Staging │ → │ Approve│ → │Production│
└─────────┘ └──────┘ └─────────┘ └────────┘ └──────────┘yaml# GitHub Actions production-deploy: needs: staging-deploy environment: name: production url: https://app.example.com runs-on: ubuntu-latest steps: - name: Deploy to production run: | # Deployment commands
yaml# GitLab CI deploy:production: stage: deploy script: - deploy.sh production environment: name: production when: delayed start_in: 30 minutes only: - main
yaml# Azure Pipelines stages: - stage: Production dependsOn: Staging jobs: - deployment: Deploy environment: name: production resourceType: Kubernetes strategy: runOnce: preDeploy: steps: - task: ManualValidation@0 inputs: notifyUsers: "team-leads@example.com" instructions: "Review staging metrics before approving"
Reference: See assets/approval-gate-template.yml
yamlapiVersion: apps/v1 kind: Deployment metadata: name: my-app spec: replicas: 10 strategy: type: RollingUpdate rollingUpdate: maxSurge: 2 maxUnavailable: 1
Characteristics:
yaml# Blue (current) kubectl apply -f blue-deployment.yaml kubectl label service my-app version=blue # Green (new) kubectl apply -f green-deployment.yaml # Test green environment kubectl label service my-app version=green # Rollback if needed kubectl label service my-app version=blue
Characteristics:
yamlapiVersion: argoproj.io/v1alpha1 kind: Rollout metadata: name: my-app spec: replicas: 10 strategy: canary: steps: - setWeight: 10 - pause: { duration: 5m } - setWeight: 25 - pause: { duration: 5m } - setWeight: 50 - pause: { duration: 5m } - setWeight: 100
Characteristics:
pythonfrom flagsmith import Flagsmith flagsmith = Flagsmith(environment_key="API_KEY") if flagsmith.has_feature("new_checkout_flow"): # New code path process_checkout_v2() else: # Existing code path process_checkout_v1()
Characteristics:
yamlname: Production Pipeline on: push: branches: [main] jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Build application run: make build - name: Build Docker image run: docker build -t myapp:${{ github.sha }} . - name: Push to registry run: docker push myapp:${{ github.sha }} test: needs: build runs-on: ubuntu-latest steps: - name: Unit tests run: make test - name: Security scan run: trivy image myapp:${{ github.sha }} deploy-staging: needs: test runs-on: ubuntu-latest environment: name: staging steps: - name: Deploy to staging run: kubectl apply -f k8s/staging/ integration-test: needs: deploy-staging runs-on: ubuntu-latest steps: - name: Run E2E tests run: npm run test:e2e deploy-production: needs: integration-test runs-on: ubuntu-latest environment: name: production steps: - name: Canary deployment run: | kubectl apply -f k8s/production/ kubectl argo rollouts promote my-app verify: needs: deploy-production runs-on: ubuntu-latest steps: - name: Health check run: curl -f https://app.example.com/health - name: Notify team run: | curl -X POST ${{ secrets.SLACK_WEBHOOK }} \ -d '{"text":"Production deployment successful!"}'
yamldeploy-and-verify: steps: - name: Deploy new version run: kubectl apply -f k8s/ - name: Wait for rollout run: kubectl rollout status deployment/my-app - name: Health check id: health run: | for i in {1..10}; do if curl -sf https://app.example.com/health; then exit 0 fi sleep 10 done exit 1 - name: Rollback on failure if: failure() run: kubectl rollout undo deployment/my-app
bash# List revision history kubectl rollout history deployment/my-app # Rollback to previous version kubectl rollout undo deployment/my-app # Rollback to specific revision kubectl rollout undo deployment/my-app --to-revision=3
yaml- name: Post-deployment verification run: | # Wait for metrics stabilization sleep 60 # Check error rate ERROR_RATE=$(curl -s "$PROMETHEUS_URL/api/v1/query?query=rate(http_errors_total[5m])" | jq '.data.result[0].value[1]') if (( $(echo "$ERROR_RATE > 0.01" | bc -l) )); then echo "Error rate too high: $ERROR_RATE" exit 1 fi
references/pipeline-orchestration.md - Complex pipeline patternsassets/approval-gate-template.yml - Approval workflow templatesgithub-actions-templates - For GitHub Actions implementationgitlab-ci-patterns - For GitLab CI implementationsecrets-management - For secrets handling| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 16,371 | 13,169 | -20% | 1 | 1 | 0% | 2,457 | 4,245 | +73% | 0 | 0 | — |
case-02 | pass→pass | 8,627 | 5,386 | -38% | 1 | 1 | 0% | 1,412 | 3,015 | +114% | 0 | 0 | — |
case-03 | pass→pass | 4,910 | 6,311 | +29% | 1 | 1 | 0% | 883 | 3,259 | +269% | 0 | 0 | — |
case-04 | fail→pass | 6,503 | 6,252 | -4% | 1 | 1 | 0% | 1,225 | 3,337 | +172% | 0 | 0 | — |
case-14 | pass→pass | 15,977 | 13,754 | -14% | 1 | 1 | 0% | 2,344 | 4,237 | +81% | 0 | 0 | — |
case-05 | fail→fail | 7,008 | 8,333 | +19% | 1 | 1 | 0% | 1,160 | 3,583 | +209% | 0 | 0 | — |
case-06 | fail→fail | 8,348 | 7,045 | -16% | 1 | 1 | 0% | 1,551 | 3,346 | +116% | 0 | 0 | — |
case-07 | fail→pass | 11,096 | 5,540 | -50% | 1 | 1 | 0% | 1,825 | 3,039 | +67% | 0 | 0 | — |
case-08 | pass→pass | 7,116 | 7,507 | +5% | 1 | 1 | 0% | 1,124 | 3,376 | +200% | 0 | 0 | — |
case-09 | pass→pass | 10,379 | 10,951 | +6% | 1 | 1 | 0% | 2,168 | 4,454 | +105% | 0 | 0 | — |
case-10 | fail→fail | 11,674 | 8,472 | -27% | 1 | 1 | 0% | 2,297 | 3,614 | +57% | 0 | 0 | — |
case-11 | fail→pass | 3,792 | 3,725 | -2% | 1 | 1 | 0% | 534 | 2,778 | +420% | 0 | 0 | — |
case-12 | fail→fail | 8,135 | 8,882 | +9% | 1 | 1 | 0% | 1,523 | 3,749 | +146% | 0 | 0 | — |
case-13 | fail→pass | 11,595 | 8,974 | -23% | 1 | 1 | 0% | 1,953 | 3,599 | +84% | 0 | 0 | — |
case-15 | pass→pass | 11,611 | 7,249 | -38% | 1 | 1 | 0% | 1,808 | 3,424 | +89% | 0 | 0 | — |
case-16 | pass→pass | 11,963 | 9,790 | -18% | 1 | 1 | 0% | 2,565 | 4,176 | +63% | 0 | 0 | — |
case-17 | fail→pass | 8,403 | 1,570 | -81% | 1 | 1 | 0% | 1,541 | 2,404 | +56% | 0 | 0 | — |
case-18 | fail→pass | 10,056 | 1,150 | -89% | 1 | 1 | 0% | 1,853 | 2,310 | +25% | 0 | 0 | — |
case-19 | pass→pass | 13,795 | 9,460 | -31% | 1 | 1 | 0% | 2,608 | 3,864 | +48% | 0 | 0 | — |
case-20 | pass→pass | 7,704 | 7,785 | +1% | 1 | 1 | 0% | 1,511 | 3,719 | +146% | 0 | 0 | — |
case-21 | pass→pass | 8,025 | 8,892 | +11% | 1 | 1 | 0% | 1,577 | 4,006 | +154% | 0 | 0 | — |
case-22 | pass→pass | 3,620 | 4,716 | +30% | 1 | 1 | 0% | 700 | 3,028 | +333% | 0 | 0 | — |
case-23 | pass→pass | 13,815 | 12,081 | -13% | 1 | 1 | 0% | 2,969 | 4,874 | +64% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +30 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.