← Release Management: prepare, deploy, and recover
02 / 6 · 40 MIN

Artifacts and traceability

Ensure the approved package matches what will be deployed and recovered.

Concept and mechanism

A release package needs a verifiable identity. Connect code revision, build, artifact, configuration, migrations, and test results. A name such as latest may change between approval and deployment; retain a stable content reference and check what was actually promoted. Reproducible builds depend on controlled tools and dependencies rather than merely the same code revision. The aim is to understand how the artifact was produced and avoid accidental environment differences. Approval of one package does not automatically transfer to another rebuilt or modified package. Maintain notes explaining changes, limitations, and links to relevant evidence with audience-appropriate access.

Guided application

In a fictional exercise, QA approves artifact A, but the production job resolves a label to B. Halt promotion and determine which package matches the evidence. Do not rename B to make it appear to be A. For database changes, EF Core documentation recommends executing the reviewed script rather than regenerating it during deployment. Keeping a rollback script also does not guarantee reconstruction of deleted data. Record configuration and migration versions alongside the binary and confirm compatibility between them. If two pipelines change the same environment, traceability should include actual order, previous state, and outcome. A completed job log demonstrates job execution rather than functional release acceptance.

IN PRACTICE

Approval of A with deployment of B leaves the release without the expected evidence.

Common pitfalls

Mutable label as identity; rebuild as identical package; script generated after review.

Related topics: Scope and coordination · Readiness and authorization · Exposure and observation

Take this idea with you

Promote reviewed content and retain the chain between change, test, and execution.

Create account

Reference: Reproducible builds versioned artifacts and release traceability · Release management practices 2026-09; scoped GitLab GitHub CodeDeploy and EF Core documentation