CI/CD quality gates
Principles
- Fast feedback on every PR; expensive jobs scheduled or nightly
- Fail closed on security and contract breaks
- Same commands locally and in CI
Tiered gates
| Tier | When | Examples |
|---|---|---|
| PR required | Every push | Lint, unit tests, typecheck |
| PR optional | Large repos | Integration, e2e subset |
| Main/nightly | Post-merge | Full e2e, perf budget, dependency audit |
Gate design
- Lint/format — consistent style, catch syntax issues
- Unit tests — required; flaky tests fixed or quarantined
- Build — artifact or package builds for deployable repos
- Security — secret scan, dependency audit (fail on critical)
- Contract — OpenAPI/schema diff when APIs change
Merge policy
- Required checks green before merge
- No force-push to protected default branch without policy
- Document bypass process for emergencies
Anti-patterns
- 30+ minute PR feedback loops
- Different test command in CI vs README
- Ignored flaky tests accumulating
Related
verify-before-done, gstack/ship, test-failure-triage, api-security-testing