100% Free Forever
AI-Powered Learning
Industry Expert Content
Certificates & Badges
Learn At Your Own Pace
YAML

Deploying Containers from CI/CD

Learn the common patterns pipelines use to deploy containerized applications, from direct kubectl updates to GitOps-driven reconciliation.

Containers in CI/CDIntermediate10 min readJul 8, 2026
Analogies

Deploying Containers from CI/CD

Once a container image is built, scanned, and pushed to a registry, the pipeline's final job is to get that image running in a target environment — a Kubernetes cluster, a serverless container platform like AWS Fargate or Cloud Run, or a simpler VM-based Docker host. How this happens varies enormously across organizations, ranging from a pipeline directly issuing imperative commands against an API, to a fully declarative GitOps model where the pipeline's only job is to update a manifest and a separate controller handles the actual rollout. Understanding these patterns, and their tradeoffs around auditability, blast radius, and rollback speed, is central to designing dependable container deployments.

🏏

Cricket analogy: Like the final step after a player is selected and cleared — actually getting him onto the field, whether a captain personally inserts him (imperative) or team management updates the official team sheet for match officials to process (GitOps-style), with different implications for accountability and how fast a mistake reverses.

Push-Based Deployment

In a push-based model, the CI pipeline itself has credentials to the target environment and directly issues the update — running kubectl set image, calling a cloud provider's deploy API, or executing a Helm upgrade. This is simple to set up and gives immediate feedback within the pipeline about whether the deployment succeeded. The tradeoff is that the pipeline now holds powerful, often broad, credentials to production infrastructure, and any pipeline misconfiguration, malicious code injection, or compromised CI runner has a direct path to modifying production. Push-based deployment also means the actual state of the cluster can drift from what's declared in git if anyone runs manual kubectl commands outside the pipeline.

🏏

Cricket analogy: Like giving the assistant coach the master key to change the batting order directly on the official scoresheet mid-match — fast and instant, but if that key is misused or someone else scribbles changes on the scoresheet later, the official record no longer matches what's happening on the field.

GitOps: Pull-Based Deployment

In the GitOps model, the CI pipeline's only responsibility after pushing an image is to update a manifest in a separate 'deploy' git repository (or a designated path in the same repo) to reference the new image tag, then open or auto-merge a commit. A cluster-resident controller — Argo CD or Flux are the dominant tools — continuously watches that repository and reconciles the live cluster state to match it, pulling the change rather than the pipeline pushing it. This inverts the trust model: the CI pipeline never holds cluster credentials at all, only git write access, while the in-cluster controller holds the deployment credentials and is the only thing that can modify the cluster. This significantly shrinks the blast radius of a compromised CI pipeline and gives a full audit trail of every deployment as git commits.

🏏

Cricket analogy: Like a captain only submitting the team sheet to the match referee's office (git write access) rather than substituting players himself, while match officials (controller) actually enforce the lineup on the pitch, so a rogue captain can only alter paperwork, never play directly, and every change is logged.

yaml
# .github/workflows/deploy.yml — GitOps-style: pipeline only updates the manifest
name: promote-to-staging
on:
  workflow_run:
    workflows: ["docker-build"]
    types: [completed]
jobs:
  update-manifest:
    if: ${{ github.event.workflow_run.conclusion == 'success' }}
    runs-on: ubuntu-latest
    steps:
      - name: Checkout deploy repo
        uses: actions/checkout@v4
        with:
          repository: acme/k8s-manifests
          token: ${{ secrets.DEPLOY_REPO_TOKEN }}

      - name: Update image tag with yq
        run: |
          yq -i '.spec.template.spec.containers[0].image = "ghcr.io/acme/api:${{ github.sha }}"' \
            environments/staging/deployment.yaml

      - name: Commit and push
        run: |
          git config user.name "ci-bot"
          git config user.email "[email protected]"
          git commit -am "deploy: api image ${{ github.sha }} to staging"
          git push
      # Argo CD, watching this repo, detects the commit and syncs the cluster.

GitOps flips the deployment analogy from a delivery truck driving into your warehouse (push) to a warehouse worker continuously checking a shared order sheet and restocking shelves to match it (pull). The worker inside never needs to trust or admit anyone from outside.

A subtle failure mode in push-based deployments is 'kubectl apply drift' — if the pipeline applies a partial manifest or a manual hotfix is applied directly to the cluster, the git-declared state and the live state silently diverge, and the next pipeline run may unexpectedly revert an emergency fix nobody remembered was manual.

Deployment Verification and Health Gates

Regardless of push or pull model, a responsible deployment pipeline does not consider the job done the moment a new image reference is applied — it must verify the new version is actually healthy before declaring success. This typically means polling readiness/liveness probes, checking that the expected number of replicas reached Ready state within a timeout, and optionally running smoke tests against the newly deployed endpoint. Pipelines that skip this step can report a false 'deployment successful' status while pods are actually crash-looping in production.

🏏

Cricket analogy: Like not declaring a returning injured bowler match-fit the moment he steps onto the field — the physio must watch him bowl a full spell at pace within a set window and run him through drills before certifying him, otherwise a team risks fielding someone who breaks down mid-over.

  • Push-based deployment has the CI pipeline directly apply changes using credentials to the target environment.
  • GitOps (pull-based) has the pipeline only update a manifest; an in-cluster controller reconciles the live state to match it.
  • GitOps shrinks the CI pipeline's blast radius since it never holds direct cluster credentials.
  • Manual out-of-band changes cause drift between declared and live state in push-based setups.
  • Deployment pipelines should verify rollout health (readiness, replica counts, smoke tests) before declaring success.
  • Argo CD and Flux are the dominant GitOps controllers used to reconcile Kubernetes clusters against git.

Practice what you learned

Was this page helpful?

Topics covered

#YAML#CICDToolsPipelinesStudyNotes#DevOps#DeployingContainersFromCICD#Deploying#Containers#Push#Based#Docker#StudyNotes#SkillVeris

Frequently Asked Questions

21 categories · pick one to explore

Where can I get free study notes for programming and tech subjects?
SkillVeris offers completely free study notes covering programming and tech subjects, with no signup fees or paywalls. The notes are structured by course and topic, written for quick understanding, and enriched with the Learn Through Hobbies analogy method, so you can revise concepts through cricket, music, gaming, cooking and more.
Are SkillVeris study notes good for exam revision?
Yes, the study notes are designed for efficient revision: each topic answers its heading immediately, keeps explanations concise, and links to related glossary terms and cheat sheets. Students preparing for university exams or certification tests use them as quick revision notes because they distil concepts without the padding of full textbooks.
What subjects do the free study notes cover?
The study notes span the platform's main domains, including AI and machine learning, Python and programming, web development, DevOps, cloud, security and databases. Coverage mirrors the 37 live courses, so notes exist for the topics you are actually studying, and new note sets are added as courses launch.
How are SkillVeris study notes different from regular textbooks?
The notes are answer-first, concise and free, whereas textbooks are long and often expensive. Each section explains one concept directly, then reinforces it through selectable hobby analogies like cricket or cooking. Notes also cross-link to the glossary, blog and cheat sheets, letting you jump to related material instantly instead of flipping pages.
Can I use the developer study material without creating an account?
The study notes are free to access, and SkillVeris does not charge anything for its developer study material at any point. Browsing notes is straightforward from the Study Notes section, and if you want progress tracking, certificates and AI Mentor conversations tied to your learning, a free account unlocks those extras.
Do the study notes explain concepts with analogies?
Yes, this is a signature SkillVeris feature. Study notes use the Learn Through Hobbies method, explaining technical concepts through analogies from twelve domains including cricket, music, gaming, photography, travel, movies, fitness, chess, cooking, finance, business and sports. You can switch the analogy domain instantly to whichever hobby makes the concept click.
Are the revision notes suitable for last-minute exam preparation?
Yes, revision notes on SkillVeris work well for last-minute preparation because every section states the answer in its first sentences, so skimming is genuinely effective. Pair them with the relevant cheat sheet for formulas and syntax, and use the glossary for any unfamiliar term you meet while cramming.
Is there free study material for AI and machine learning?
Yes, SkillVeris provides free study notes across its AI and ML catalogue, covering Python for AI, deep learning frameworks like PyTorch and TensorFlow, Hugging Face Transformers, Large Language Models, RAG, AI agents and MLOps. All of it is free, making it a strong resource for Indian students and global learners alike.
Can beginners understand the study notes, or are they for experts?
Beginners can absolutely use them. The notes are written in plain language, define terms as they appear, and lean on hobby analogies to make abstract ideas concrete. Difficulty scales with the underlying course level, so beginner-course notes stay gentle while advanced-course notes go deeper, and the glossary supports you throughout.
How do study notes connect with SkillVeris courses?
Study notes are organised by course and topic, so they map directly to the structured courses and their 24–40-lesson curriculum. Many learners study a lesson first, then use the matching notes for revision before module assessments and the final exam, where 80 percent is required to pass and earn the certificate.
Are there study notes for Python specifically?
Yes, Python is well covered through notes tied to the Python-focused courses, including Python for AI and ML. Topics span fundamentals through applied machine learning usage. You can reinforce the notes with Python practice in Code Lab, which runs code in your browser with no installation required.
Do the study notes include code examples?
Yes, study notes include code examples wherever a concept is best shown in code, alongside explanations, key points and analogies. Reading a snippet in the notes and then reproducing it yourself in Code Lab is an effective loop, since Code Lab lets you run code in the browser across six languages.
How often is new study material added to SkillVeris?
Study material grows alongside the course catalogue. Whenever new courses join the platform's 37 live courses, matching study notes, glossary entries and cheat sheets are added so the resources stay in sync. Existing notes are also refined over time, so it is worth revisiting topics you studied earlier.
Can I use SkillVeris notes to prepare for technical interviews?
Yes, the notes make excellent interview revision because they compress each concept into direct, answer-first explanations, which mirrors how you should answer interview questions. Combine them with the SkillVeris interview questions feature, which includes readiness scoring, to test whether your revision has actually made you interview-ready.
Are the study notes mobile-friendly for studying on the go?
Yes, the study notes are built to load fast and read comfortably on mobile devices, so you can revise during a commute or between classes. Sections are short and answer-first, which suits small screens, and analogy switching works on mobile too, letting you study anywhere without carrying books.
What is the difference between study notes and cheat sheets?
Study notes explain concepts in depth with context, examples and analogies, making them ideal for learning and revision. Cheat sheets are compact quick-reference summaries of syntax, commands and key facts, ideal once you already understand a topic. Most learners study the notes first, then keep the cheat sheet handy while coding.
Do study notes help if I am stuck on a course lesson?
Yes, reading the matching study notes often clarifies a lesson because the same concept is explained from a different angle, frequently with a different analogy. If you are still stuck, ask the AI Mentor, which answers 24/7 at Quick, Detailed or Deep-dive depth until the idea genuinely makes sense.
Is there free study material for DevOps and cloud topics?
Yes, SkillVeris carries free study notes for DevOps and cloud topics as part of its coverage across 37 live courses. The material suits learners following the DevOps Engineer or Cloud Engineer paths, and it links to related glossary terms and cheat sheets so you can revise the whole toolchain in one place.
Can school or college students in India use these notes for projects?
Yes, students across India and worldwide use SkillVeris notes for coursework, projects and exam preparation, and everything is free, which matters for student budgets. The notes explain concepts clearly enough to cite in project reports, and Code Lab lets you prototype the project code directly in your browser.
How should I combine study notes with other SkillVeris resources?
A proven loop: learn from a course lesson, revise with the matching study notes, look up unfamiliar terms in the glossary, keep the cheat sheet open while practising in Code Lab, and quiz yourself with interview questions. The AI Mentor fills any remaining gaps 24/7, at whatever depth you need.

What Learners Say

Real journeys from the SkillVeris community — swipe for more.

SkillVeris taught me Python through Cricket. Now I’m building real projects and feeling confident!
Arjun S. · B.Tech Student
The best platform for hobby-based learning. Concepts finally stick.
Priya R. · Data Analyst
I went from zero coding to a portfolio of projects — all by learning through my love for gaming. Landed my first internship!
Kabir M. · CS Undergraduate
Trending Topics50 popular tags — tap to explore
Trending CoursesAll 37 free courses — tap to browse