Skip to content
Back to skills

Deploy

ASecurity

Ship applications reliably with CI/CD, rollback strategies, and zero-downtime deployment patterns.

  • 17 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 6, 2026
devopsgogitdatabaseci/cdsecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill deploy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Deploy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Deploy
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-deploy/badge)](https://www.skillsdirectory.com/skills/clawic-deploy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Deploy
slug: deploy
version: 1.0.0
description: Ship applications reliably with CI/CD, rollback strategies, and zero-downtime deployment patterns.
homepage: https://clawic.com/skills/deploy
metadata:
  clawdbot:
    emoji: πŸš€
    os:
    - linux
    - darwin
    - win32
    displayName: Deploy
---

# Deployment Rules

## Pre-Deploy Checklist
- Tests passing in CI β€” never deploy with failing tests
- Environment variables set in target β€” missing secrets cause silent failures
- Database migrations run before code deploy β€” new code expecting new schema fails
- Rollback plan ready β€” know exactly how to revert before you need to

## Deployment Strategies
- **Rolling**: update instances one by one β€” safe, slower, no extra resources
- **Blue-green**: full parallel environment, instant switch β€” fast rollback, 2x resources
- **Canary**: route percentage to new version β€” catch issues early, complex routing
- Choose based on risk tolerance and resources β€” no universal best

## Zero-Downtime Deploys
- Health checks must pass before traffic routes β€” unhealthy instances stay out
- Graceful shutdown: finish in-flight requests before terminating
- Database changes must be backwards compatible β€” old code still running during deploy
- Session handling: sticky sessions or external session store β€” don't lose user state

## CI/CD Pipeline
- Build once, deploy everywhere β€” same artifact to staging and prod
- Cache dependencies between builds β€” save minutes per deploy
- Parallel steps where possible β€” tests, linting, security scans
- Fail fast: quick checks first β€” don't wait for slow tests to catch typos
- Pin action versions with SHA β€” tags can change unexpectedly

## Environment Management
- Staging mirrors prod β€” different configs cause "works in staging" bugs
- Secrets in secret manager, not environment files β€” rotation without redeploy
- Feature flags decouple deploy from release β€” ship dark, enable later
- Config as code in version control β€” except secrets

## Database Migrations
- Migrations must be backwards compatible during deploy window
- Add columns nullable first, then backfill, then add constraint
- Never rename columns in one step β€” add new, migrate data, remove old
- Test migrations on prod-size data β€” 10 rows is fast, 10 million isn't
- Rollback script for every migration

## Rollback
- Automated rollback on health check failure
- Keep previous version artifacts available β€” can't rollback what you deleted
- Database rollbacks are hard β€” design migrations to not need them
- Feature flags for instant rollback of functionality without deploy
- Document rollback procedure β€” panic time is not learning time

## Monitoring Post-Deploy
- Watch error rates for 15 minutes after deploy β€” most issues surface quickly
- Compare key metrics to pre-deploy baseline
- Alerting on anomalies: latency spike, error rate increase
- Log correlation: trace requests through systems
- User-facing smoke tests after deploy

## Platform-Specific

### Containers
- Image tagged with git SHA β€” know exactly what's running
- Health check endpoint that verifies dependencies
- Resource limits set β€” prevent runaway containers

### Serverless
- Cold start optimization β€” keep bundles small
- Provisioned concurrency for latency-sensitive paths
- Timeout set appropriately β€” default is often too short

### Static Sites
- CDN cache invalidation after deploy
- Immutable assets with content hashes β€” cache forever
- Preview deploys for PRs

## Common Mistakes
- Deploying Friday afternoon β€” issues surface when nobody's watching
- No rollback plan β€” hoping nothing goes wrong isn't a strategy
- Mixing code and migration deploys β€” one thing at a time
- Manual deploy steps β€” if it's not automated, it's wrong sometimes
- Deploying without monitoring β€” you won't know it's broken until users complain

Files in this skill

  • SKILL.md3.8 KB
  • _meta.json164 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…