1. Security by Default, Not by Accident
2. Docker Registries Are Not Always Necessary
- Build Docker image in CI
- Push to GitLab container registry
- EC2 pulls from registry
- Run container
3. "Trigger and See" Doesn't Work for Production
- Test locally
- Verify CI builds pass
- Discuss deployment plan as a team
- Then deploy to production
4. GitLab CI OIDC Federation — Powerful but Strict
5. SSH from CI Runners — Network Matters
6. Terraform and Ansible Are Separate Concerns
Yaml
7. Gate New Pipelines Before Merging
Yaml
8. The "Just Run site.yml" Gap
The Underlying Theme
- Deployment coordination — even if it's just a Slack message
- Auth on every endpoint — no exceptions, no "we'll add it later"
- Clear separation between build and deploy tools — Terraform ≠ Ansible ≠ application CI
- CI jobs for every operational action — if you'd SSH in to do it, it should be a pipeline job
Building infrastructure for a small team? I write about backend engineering, DevOps lessons, and AI-assisted development. Connect on LinkedIn or subscribe to the newsletter for more.