Project challenges / verified progress
Engineering project paths

The engineering notebook

Beacon: ship it without fear

You can design and implement a zero-cloud-cost delivery path for Beacon: CI checks, supply-chain gates, digest promotion, Argo CD GitOps on kind, Kustomize overlays, progressive delivery, rollback runbooks and meaningful releases.

Your learning trail

0 / 9 complete

Verified project-agent submissions only. Reading or clicking cannot unlock progress.

System design

What you are building

Course 6 replaces hand-applied delivery with a verified path from GitHub events to immutable artifacts, GitOps reconciliation and release operations on a local kind cluster.

BEACON / THE PATH TO PRODUCTIONA commitone change, one authorTHE PIPELINE YOU OWNCIvet, race tests, buildGatesSBOM, scan, sign, attestConfig repothe digest, written downCanarya few users firstWHAT CLOSES THE LOOPArgo CDpulls, never pushed toRollbackmeasured in minutesanalysis rejects a bad canary without waking anyoneBUILD ONCE, PROMOTE A DIGEST, LET THE CLUSTER PULL

Stages

9 stages, in order

Expand any stage to read what it teaches. A stage opens for work once the stage before it passes a verified submission.

Phase 1Stages 1–20 of 2 stages verified

Trust the path

Separate integration, delivery and deployment, then make checks enforceable.

  • Trust the path first70 minutes (locked)

    What is a delivery pipeline actually for?

    You will be able to define CI, continuous delivery and continuous deployment in docs/delivery/pipeline.md.

    Fork the project repository to start working through the stages.

  • Make checks enforceable90 minutes (locked)

    How does the first GitHub Actions workflow prove Beacon still builds?

    You will be able to create .github/workflows/beacon-ci.yml without editing existing workflows.

    Fork the project repository to start working through the stages.

Phase 2Stages 3–40 of 2 stages verified

Protect the artifact

Attach supply-chain evidence and promote one immutable digest.

  • Prove what you ship2 hours (locked)

    How does CI earn trust without storing long-lived secrets?

    You will be able to add a supply-chain workflow that builds the image and produces an SBOM.

    Fork the project repository to start working through the stages.

  • Move the same bits90 minutes (locked)

    Why should environments receive the same image digest instead of rebuilding?

    You will be able to accept an OCI digest as the workflow input and never rebuild inside promotion jobs.

    Fork the project repository to start working through the stages.

Phase 3Stages 5–60 of 2 stages verified

Let Git drive the cluster

Use Argo CD and Kustomize so desired state is reviewed and reconciled.

  • Let the cluster pull2 hours (locked)

    Why does GitOps keep cluster credentials out of CI?

    You will be able to create an Argo CD Application manifest under deploy/gitops/.

    Fork the project repository to start working through the stages.

  • Shape manifests per place2 hours (locked)

    How can the same Kubernetes manifests fit dev, staging and production?

    You will be able to create a Kustomize base plus dev, staging and production overlays.

    Fork the project repository to start working through the stages.

Phase 4Stages 7–90 of 3 stages verified

Release and recover

Limit blast radius, recover from bad changes and make releases meaningful.

  • Release to a slice2 hours (locked)

    How do canaries and rollouts limit blast radius?

    You will be able to create an Argo Rollouts Rollout using argoproj.io/v1alpha1.

    Fork the project repository to start working through the stages.

  • Recover without guessing90 minutes (locked)

    What should happen when a release goes wrong?

    You will be able to write a rollback runbook under docs/delivery/rollback.md.

    Fork the project repository to start working through the stages.

  • Give releases meaning90 minutes (locked)

    How does a release tell users what changed and what promises now hold?

    You will be able to create a release workflow that accepts an explicit semantic version.

    Fork the project repository to start working through the stages.

About this path

Beacon can be built, containerized, scheduled on Kubernetes and provisioned with infrastructure code, but every production move still depends on a human running the right commands in the right order. This course turns delivery into a controlled system with evidence, promotion, reconciliation and recovery.

What you will learn: GitHub Actions pipelines, Software supply chain security, GitOps with Argo CD, Canary and progressive delivery, Rollback and release engineering. Build the project through cumulative challenges with beginner explanations and local verification.

Level
Complete beginner to independently building and operating the project
Format
9 cumulative stages. Every stage teaches the concept in full before any code, then gives you the thing to build and the run that proves it works
Before you start
A free GitHub account, Docker, kind and kubectl. GitHub Actions is free for public repositories, and Argo CD runs on the local kind cluster. There is zero cloud cost for this course.
Official documentation (opens in a new tab)