Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium

A DevOps team is managing a critical application deployed to Azure Kubernetes Service (AKS). They need to ensure that all deployments to production follow a strict approval process and that automated checks are performed before the deployment proceeds. Specifically, they need to ensure that a senior engineer approves the deployment and that an external security scan completes successfully. Which feature in Azure DevOps release pipelines should be used to enforce these controls?

  1. ARelease triggers with branch policies
  2. BEnvironments with deployment conditions
  3. CPre-deployment approvals and pre-deployment gates
  4. DPost-deployment approvals and post-deployment gates
Show answer & explanation

Correct answer: C. Pre-deployment approvals and pre-deployment gates

Pre-deployment approvals enforce manual sign-off by designated users, while pre-deployment gates enable automated checks (like external security scans) to run and pass before a stage can begin, directly fulfilling both requirements for controlling production deployments.

Why the other options are wrong

  • A. Release triggers and branch policies control when a pipeline starts or code is merged, not the specific pre-deployment controls within a release stage.
  • B. Environments with deployment conditions define when a stage can run but don't inherently provide the specific manual approval or automated gate functionality required.
  • D. Post-deployment approvals and gates occur after the deployment, which doesn't prevent a flawed deployment from starting.

Pre-deployment Approvals & Gates

Mechanisms in Azure DevOps release pipelines that enforce manual sign-off (approvals) and automated checks (gates) before a deployment stage can begin, ensuring control and quality.

  • Approvals require designated users to manually sign off.
  • Gates perform automated checks (e.g., external service health, security scans).
  • Both must pass for the stage to proceed.
  • Crucial for controlling deployments to sensitive environments like production.

Memory trick: Before you enter the production 'stage', you need a ticket (approval) and to pass security (gates).

More Design and implement pipelines questions