CI/CD Integration: Git as the Source of Truth
A real pipeline spec, written and committed. Every git event mapped to a real automated response.
Git is not just where code lives — every real event it produces (a push, a merge, a tag) is a genuine, reliable trigger a real CI/CD system can react to. This repository already has one real piece of this in place: the pre-receive hook installed back in Block 2.5, genuinely rejecting any direct, non-merge commit pushed straight to master.\n\nThis final lab writes down the rest of the real picture — a concrete, committed spec mapping specific git events (a push to a feature branch, a merge to master, a real release tag) to the specific automated actions a team would wire up around them, closing the loop with the branch protection already enforced server-side.
The Real Piece Already in Place
cat ../recipes-origin.git/hooks/pre-receive
A real, server-side hook, installed back in Block 2.5 — genuinely rejecting any direct, non-merge commit pushed straight to master. This is CI/CD's most fundamental real building block: a git event (a push) triggering an automated, real decision (accept or reject).
Writing the Rest of the Real Picture
push to any feature/* branch -> run recipe format checks
merge to master (reviewed PR only) -> deploy docs site to staging
tag matching v*.*.* -> deploy docs site to production
push directly to master -> rejected (real, already enforced)
A real, concrete spec — not abstract theory — naming the exact real git event and the exact real automated response for each.
Committing the Real Spec
git add CI-PIPELINE.md
git commit -m "RECIPE-308: Document the CI/CD pipeline spec"
A real, permanent, committed reference — the same real discipline as every other document this curriculum has written directly into the repository.
Git events as CI/CD triggers
Real, reliable signals — a push, a merge, a tag — that a real CI/CD system watches and reacts to automatically. Confirmed directly across this entire certificate: the pre-receive hook (Block 2.5), branch structure (Block 2.2), and tags (Block 3.5) are all real building blocks CI/CD systems build on.
🔍 Inspect the Real Piece Already Installed
The branch-protection hook has been enforcing this since Block 2.5.
cd ~/team-recipes && cat ../recipes-origin.git/hooks/pre-receivestudent@lab:~$ cd ~/team-recipes && cat ../recipes-origin.git/hooks/pre-receive #!/bin/sh while read oldrev newrev refname; do branch=$(echo "$refname" | sed "s|refs/heads/||") if [ "$branch" = "master" ] && [ "$oldrev" != "0000000000000000000000000000000000000000" ]; then for commit in $(git rev-list --first-parent "$oldrev..$newrev"); do parents=$(git rev-list --parents -n 1 "$commit" | wc -w) if [ "$parents" -lt 3 ]; then echo "error: direct commit $commit rejected on protected branch master" echo "master only accepts merge commits from a reviewed pull request" exit 1 fi done fi done exit 0
📋 Write the Real Pipeline Spec
A real, concrete map from git events to automated actions.
cd ~/team-recipes && printf 'CI/CD Pipeline Specification\n\npush to any feature/* branch -> run recipe format checks\nmerge to master (via reviewed pull request only - see server-side hook) -> deploy docs site to staging\ntag matching v*.*.* -> deploy docs site to production\npush directly to master -> rejected by the real pre-receive hook already installed on origin\n' > CI-PIPELINE.mdcd ~/team-recipes && git add CI-PIPELINE.mdcd ~/team-recipes && git commit -m "RECIPE-308: Document the CI/CD pipeline spec"cd ~/team-recipes && cat CI-PIPELINE.mdstudent@lab:~$ cd ~/team-recipes && printf 'CI/CD Pipeline Specification\n\npush to any feature/* branch -> run recipe format checks\nmerge to master (via reviewed pull request only - see server-side hook) -> deploy docs site to staging\ntag matching v*.*.* -> deploy docs site to production\npush directly to master -> rejected by the real pre-receive hook already installed on origin\n' > CI-PIPELINE.md student@lab:~$ cd ~/team-recipes && git add CI-PIPELINE.md student@lab:~$ cd ~/team-recipes && git commit -m "RECIPE-308: Document the CI/CD pipeline spec" [master 775ec30] RECIPE-308: Document the CI/CD pipeline spec 1 file changed, 6 insertions(+) create mode 100644 CI-PIPELINE.md student@lab:~$ cd ~/team-recipes && cat CI-PIPELINE.md CI/CD Pipeline Specification push to any feature/* branch -> run recipe format checks merge to master (via reviewed pull request only - see server-side hook) -> deploy docs site to staging tag matching v*.*.* -> deploy docs site to production push directly to master -> rejected by the real pre-receive hook already installed on origin
Lab 3.6.5 complete — Block 3.6 complete — Certificate 3 complete. A real, concrete pipeline spec, tying it all together:\n\n\n Real branch protection : ✅ inspected (Block 2.5)\n Real pipeline spec : ✅ written and committed\n
Enable JavaScript to run the live terminal and track your progress.