A fast pipeline is useful only when it produces a release the team can trust and recover from. Security controls and deployment reliability belong in the same design.
Keep build and deployment boundaries clear
Build a release artifact once and promote that artifact through the environments that matter. Rebuilding separately for production makes it harder to establish what was tested.
Keep configuration separate from the artifact and make environment-specific differences explicit and reviewable.
Reduce the credential footprint
Give workflows the permissions required for the job. Treat untrusted pull-request code carefully, especially around workflows with secrets or write access.
Review third-party actions as dependencies. Pinning actions to full commit SHAs gives the workflow a fixed reference, while updates still require review and maintenance.
Plan for failed releases
Deployment checks need to measure service behavior, not just whether a process started. Decide which signals stop a rollout and who owns the decision.
Test the recovery path before an incident. Database and data changes can constrain rollback, so include those dependencies in the release plan rather than assuming the previous image is always enough.