Concept and mechanism
A pipeline should answer three questions: what was built, what was tested, and what will run. The commit hash identifies code but not every build input. Variable dependencies, tools, and configuration can produce a different binary on rebuild. Promote identified, tested artifacts while separating environment configuration and secrets. Keep reports linked to the actual version. A test command masking failure with a successful exit status breaks the gate even when its report documents errors. Report collection should preserve the failure determining whether promotion can continue.
Guided application
In CodeBuild, retrieving a secret through an appropriate integration avoids placing it in visible configuration, but does not make every log safe. A transformed value may escape exact-value masking. Do not print secrets or variants. Across accounts, distinguish role assumption from artifact access: the source needs sts:AssumeRole authorization and the destination needs suitable trust; S3, KMS, and other boundaries still apply. A pipeline in account A does not simply support passing an artifact produced in B to C when both actions are outside A. Confirm the supported flow before increasing permissions. Finally, an expired manual approval is failure, not implicit acceptance. The current API allows timeout configuration; record the effective value.
The checksum changed after QA. The change owner needs evidence about the new binary or promotion of the already validated artifact.
Common pitfalls
Commit as binary; encoded secret as safe; notification as approval; excessive permissions to bypass a service limitation.
Related topics: Progressive delivery and rollback · IaC, drift, and reconciliation
Connect identity, evidence, and authorization to the object actually promoted.
Reference: DOP-C02 domain 1 · DOP-C02