
Ci/Cd Pipeline Builder
Design production-grade CI/CD pipelines with caching, parallelism, and security scanning
What You Can Do
You can generate complete, production-ready CI/CD pipeline configurations that automatically optimize build times through intelligent caching and parallel job execution, integrate security scanning (SAST, dependency checks, supply-chain validation), and implement multi-environment deployment strategies with rollback mechanisms. The skill analyzes your tech stack and team constraints to design pipelines that reduce build times while maintaining security and reliability standards.
Features
supports GitHub Actions, GitLab CI, and CircleCI with platform-specific syntax and best practices
automatically configures dependency, build artifact, and Docker layer caching to reduce pipeline runtime
optimizes build matrices, test suites, and deployment stages to run concurrently where safe
embeds SAST, dependency scanning, container image analysis, and supply-chain validation into pipeline stages
designs dev→staging→production workflows with environment-specific configurations and approval gates
implements automated or manual rollback strategies with health checks and previous version verification
identifies bottlenecks and recommends caching, parallelization, and resource allocation improvements
creates runbooks for pipeline maintenance, troubleshooting, and team onboarding
Example Output
Example 1: GitHub Actions Node.js Pipeline
name: Build & Deploy
on: [push, pull_request]
jobs:
build:
runs-on: ubuntu-latest
strategy:
matrix:
node-version: [18.x, 20.x]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}
cache: 'npm'
- run: npm ci && npm run build
- uses: snyk/actions/node@master
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
deploy:
needs: build
runs-on: ubuntu-latest
if: github.ref == 'refs/heads/main'
steps:
- uses: actions/checkout@v4
- run: |
./scripts/deploy.sh staging
./scripts/health-check.sh staging || ./scripts/rollback.sh
Example 2: GitLab CI Python + Docker
stages:
- build
- test
- scan
- deploy
build:
stage: build
image: python:3.11
cache:
paths:
- .venv/
script:
- python -m venv .venv && source .venv/bin/activate
- pip install -r requirements.txt
- python -m PyInstaller app.py
dependency-check:
stage: scan
script:
- pip install safety bandit
- safety check --json
- bandit -r . -f json
deploy:prod:
stage: deploy
when: manual
script:
- ./deploy.sh production
- ./verify-deployment.sh || ./rollback.sh
What's Included
- SKILL.md instruction file: complete CI/CD pipeline design framework with platform-specific guidance
- Pipeline templates: starter configurations for GitHub Actions, GitLab CI, and CircleCI (Node.js, Python, Go, Docker)
- Security scanning checklist: SAST tools, dependency scanning, container scanning, and secret detection checklist
- Optimization worksheet: caching strategy planner, parallelization matrix, and resource allocation calculator
- Rollback strategy guide: patterns for automatic and manual rollbacks with health checks and verification steps
- Multi-environment deployment framework: approval gates, configuration management, and environment parity checklist
Who It's For
- DevOps Engineers — design and optimize CI/CD infrastructure for multiple teams and projects
- Software Engineering Managers — establish standardized pipeline patterns and deployment governance
- Platform Engineers — build self-service CI/CD platforms and shared pipeline templates
- Backend/Full-stack Developers — implement efficient pipelines for microservices and multi-tier applications
- Security/Compliance Architects — integrate security scanning, compliance checks, and audit logging into deployment automation
Best For
- Setting up CI/CD pipelines from scratch with security and performance best practices
- Optimizing slow pipelines by analyzing bottlenecks and implementing caching + parallelization
- Migrating pipelines between platforms (Jenkins → GitHub Actions, Travis → GitLab CI)
- Implementing multi-environment deployments with approval gates and rollback strategies
- Integrating security scanning (SAST, dependency checks, container scanning) into existing pipelines
- Documenting pipeline architecture and creating team runbooks for self-service deployments







