1---2name: ci-cd-pipeline-review3description: Use when performing ci cd pipeline review — reviews CI/CD pipeline configuration for reliability, speed, security, and best practices. Covers build optimization, test strategy, deployment patterns, secret management, artifact handling, and pipeline-as-code quality to improve developer experience and release confidence.4---56# CI/CD Pipeline Review78## Phase 1: Pipeline Architecture Assessment91. Map the full pipeline flow10 - [ ] Trigger mechanisms (push, PR, schedule, manual)11 - [ ] Build stages and their sequence12 - [ ] Test stages (unit, integration, e2e, performance)13 - [ ] Security scanning stages14 - [ ] Artifact creation and storage15 - [ ] Deployment stages (staging, canary, production)16 - [ ] Post-deployment validation172. Document pipeline dependencies and bottlenecks183. Measure total pipeline duration (P50, P95)1920### Pipeline Stage Timing2122| Stage | Duration (P50) | Duration (P95) | Failure Rate | Parallelizable |23|-------|---------------|----------------|-------------|---------------|24| Checkout/Setup | | | % | N/A |25| Build | | | % | [ ] |26| Unit Tests | | | % | [ ] |27| Integration Tests | | | % | [ ] |28| Security Scan | | | % | [ ] |29| Artifact Build | | | % | [ ] |30| Deploy Staging | | | % | [ ] |31| E2E Tests | | | % | [ ] |32| Deploy Prod | | | % | [ ] |33| **Total** | | | | |3435## Phase 2: Build Optimization361. Review build performance37 - [ ] Dependency caching configured and effective38 - [ ] Build cache (Docker layer cache, incremental builds)39 - [ ] Parallel execution where possible40 - [ ] Minimal base images for containers41 - [ ] Build matrix efficient (not redundant)42 - [ ] Runner/agent sizing appropriate432. Identify slow build steps and optimization opportunities4445## Phase 3: Test Strategy Review461. Evaluate test coverage and quality47 - [ ] Unit tests: coverage %, execution time48 - [ ] Integration tests: scope, reliability (flaky test rate)49 - [ ] E2E tests: critical path coverage, stability50 - [ ] Test parallelization and splitting51 - [ ] Test data management strategy52 - [ ] Flaky test handling (quarantine, retry, fix)532. Assess test feedback loop speed5455### Test Pyramid Assessment5657| Level | Count | Duration | Coverage | Flaky Rate | Quality |58|-------|-------|----------|----------|-----------|---------|59| Unit | | s | % | % | Good/Fair/Poor |60| Integration | | s | | % | |61| E2E | | s | critical paths | % | |62| Performance | | s | | % | |6364## Phase 4: Security & Compliance651. Review pipeline security66 - [ ] Secrets management (no hardcoded secrets, vault integration)67 - [ ] SAST (static analysis) scanning68 - [ ] SCA (dependency vulnerability) scanning69 - [ ] Container image scanning70 - [ ] DAST (dynamic) scanning for web apps71 - [ ] License compliance checking72 - [ ] SBOM generation73 - [ ] Pipeline permissions (least privilege)74 - [ ] Signed commits and artifacts752. Review approval gates and compliance controls7677## Phase 5: Deployment Strategy Review781. Assess deployment practices79 - [ ] Blue-green or canary deployment support80 - [ ] Automated rollback capability81 - [ ] Database migration handling82 - [ ] Feature flag integration83 - [ ] Deployment notification (Slack, email)84 - [ ] Post-deployment smoke tests85 - [ ] Environment promotion flow (dev → staging → prod)86 - [ ] Drift detection between environments872. Review deployment frequency and success rate8889## Phase 6: Pipeline-as-Code Quality901. Review pipeline configuration quality91 - [ ] DRY (reusable workflows, templates, shared libraries)92 - [ ] Version controlled pipeline definitions93 - [ ] Environment-specific configuration separation94 - [ ] Clear naming and documentation95 - [ ] Error handling and failure notifications96 - [ ] Pipeline self-testing (validate on PR)9798### Review Summary99100| Area | Score (1-5) | Key Finding | Recommendation | Priority |101|------|-----------|-------------|----------------|----------|102| Build Speed | | | | |103| Test Quality | | | | |104| Security | | | | |105| Deployment | | | | |106| Maintainability | | | | |107108## Counter-Rationalizations109110| Shortcut | Counter | Why |111|----------|---------|-----|112| "We can skip some steps for this case" | Adapt the workflow steps, don't skip them | Skipped steps are where incidents and oversights originate |113| "The user seems to already know what to do" | Complete all workflow phases with the user | The workflow catches blind spots that experience alone misses |114| "This is a minor case, full process is overkill" | Scale the process down, don't turn it off | Minor cases become major when unstructured; the process scales, not disappears |115| "I'll fill in the details later" | Complete each section before moving on | Deferred details are forgotten; real-time capture is more accurate |116| "The template output isn't necessary" | Always produce the structured output format | Structured output enables comparison, audit trails, and handoff to other teams |117118## Output Format119- **Pipeline Architecture Diagram**: Visual flow of all stages120- **Performance Report**: Stage timing and bottleneck analysis121- **Security Findings**: Vulnerabilities in pipeline configuration122- **Optimization Recommendations**: Prioritized improvements123- **Best Practices Checklist**: Compliance with CI/CD best practices124125## Action Items126- [ ] Map and document current pipeline architecture127- [ ] Measure stage timing and identify bottlenecks128- [ ] Implement build caching and parallelization129- [ ] Address security gaps in pipeline configuration130- [ ] Reduce flaky test rate to < 1%131- [ ] Implement automated rollback capability132- [ ] Document pipeline configuration and runbooks