CI/CD Engineering Stack
Reusable CI workflows, verifiable delivery contracts and a pinned install of the official GitHub Actions runner with separated trust boundaries.
CI Workflows
Fifty reusable GitHub Actions workflows: language CI, security scanning, release supply chain and repository hygiene — together with a fixture set of repositories that proves each of them runs.
Programmes are separated by repository visibility and paid GitHub capabilities: public OSS, private without paid add-ons, and private with separately enabled products.
CD Workflows
Open delivery contracts for agents: an immutable plan, approval binding, state transitions, verification evidence, resume and exact rollback. Environment topology and secrets stay with the calling repository.
Actions light
An install of the official actions/runner, pinned by checksum, with systemd units and registration in an organisation or a repository. It is not a scheduler: the queue, permissions and statuses stay in GitHub, and public and fork pull request code does not run on private hardware.
Licences: CI Workflows — AGPL-3.0, CD Workflows and Actions light — MIT.
Discuss an implementation
Tell us about the task, existing systems and constraints — we will propose the next step.
We reply within 24 h

