Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium
A DevOps team is managing a critical application deployed to Azure Kubernetes Service (AKS). They need to ensure that all deployments to production follow a strict approval process and that automated checks are performed before the deployment proceeds. Specifically, they need to ensure that a senior engineer approves the deployment and that an external security scan completes successfully. Which feature in Azure DevOps release pipelines should be used to enforce these controls?
- ARelease triggers with branch policies
- BEnvironments with deployment conditions
- CPre-deployment approvals and pre-deployment gates
- DPost-deployment approvals and post-deployment gates
Show answer & explanationAnswer & explanation
Correct answer: C. Pre-deployment approvals and pre-deployment gates
Pre-deployment approvals enforce manual sign-off by designated users, while pre-deployment gates enable automated checks (like external security scans) to run and pass before a stage can begin, directly fulfilling both requirements for controlling production deployments.
Why the other options are wrong
- A. Release triggers and branch policies control when a pipeline starts or code is merged, not the specific pre-deployment controls within a release stage.
- B. Environments with deployment conditions define when a stage can run but don't inherently provide the specific manual approval or automated gate functionality required.
- D. Post-deployment approvals and gates occur after the deployment, which doesn't prevent a flawed deployment from starting.
Pre-deployment Approvals & Gates
Mechanisms in Azure DevOps release pipelines that enforce manual sign-off (approvals) and automated checks (gates) before a deployment stage can begin, ensuring control and quality.
- Approvals require designated users to manually sign off.
- Gates perform automated checks (e.g., external service health, security scans).
- Both must pass for the stage to proceed.
- Crucial for controlling deployments to sensitive environments like production.
Memory trick: Before you enter the production 'stage', you need a ticket (approval) and to pass security (gates).