Module 10 · CI/CD and Containers
"Final project: Tallybook's delivery review"
Plan your final project, a review of how Tallybook builds, secures and releases software, with DORA measures, fixed Dockerfile and workflow, scanning and canary policies, and the next improvements.
About 20 minutes
The problem
Three months after switching to the new pipeline, Tallybook's CTO wants a review for the board: was it worth it, what's still risky, and what comes next? Your final project is that review, built from the files and data in this course, with fixed versions of the Dockerfile and workflow attached.
The concept
The parts of the review
| Part | Built in |
|---|---|
| DORA measures, before and after | lesson 1 |
| The image: size, build time, Dockerfile fixes | lessons 2 and 3 |
| Vulnerabilities and the scanning policy | lesson 4 |
| The workflow: problems found and the fixed version | lessons 5 and 6 |
| Pipeline speed and caching | lesson 7 |
| Canary performance and policy | lesson 8 |
| Recovery | lesson 9 |
Show the trade-offs
The board will ask whether faster releases mean more risk. The data answers it; make sure your review shows it plainly.
Example
The headline table for the board:
import pandas as pd
deploys = pd.read_csv("https://academy.cloudtechanalytics.com/datasets/cicd/deployments.csv",
parse_dates=["first_commit_at", "deployed_at"])
deploys["lead_time_hours"] = (deploys["deployed_at"] - deploys["first_commit_at"]).dt.total_seconds() / 3600
headline = deploys.groupby("pipeline").agg(
deploys_per_week=("deploy_id", lambda s: round(len(s) / 13, 1)),
median_lead_time_hours=("lead_time_hours", lambda s: round(s.median(), 1)),
change_failure_rate_pct=("caused_incident", lambda s: round(s.mean() * 100, 1)),
median_minutes_to_restore=("minutes_to_restore", "median"),
).T[["old", "new"]]
headlinepipeline old new
deploys_per_week 3.1 20.4
median_lead_time_hours 159.1 16.4
change_failure_rate_pct 20.0 0.8
median_minutes_to_restore 205.0 21.5Walkthrough
- Complete the review with every part in the table above.
- Attach your fixed Dockerfile and workflow, with your checkers' output showing they pass.
- List the three biggest remaining risks, with evidence.
- Open the project brief on the course page and plan the write-up.
Practice
Practice
Under the new pipeline, how many deployments per week did Tallybook make? One decimal place.
Task
10 minWrite the executive summary for the board (100 to 200 words): the DORA results with numbers, what was fixed (Dockerfile, secrets, workflow), what's still risky, and the next three improvements.
Your work is checked for
- At least three numbers
- Names DORA measures (frequency, lead time, failure, restore)
- Mentions the secret in the image or workflow problems
- Remaining risks
- Next improvements
- Between 100 and 200 words
Check your understanding
Answer every question to check.