Audit Azure DevOps Pipelines untuk agency dengan Claude Code
Alur agency untuk PR, ManualValidation, approval production, dan rollback evidence.
Di agency web, pull request, staging URL, approval klien, dan Azure Pipelines run sering ada di tab berbeda. Perubahan copy kecil bisa masuk production karena semua orang mengira orang lain sudah mengecek. Artikel ini mengubah branch policies, ManualValidation, dan approvals menjadi tabel rilis.
Di mana release agency gagal
- Pisahkan PR approval, staging review, client approval, dan production approval.
- Gunakan branch policies untuk melindungi main atau release sebelum merge.
- Gunakan ManualValidation untuk pause saat staging URL dan rollback diperiksa.
- Gunakan environment approvals sebagai gate sebelum production.
- Claude Code merangkum YAML dan diff; klien, harga, legal, waktu, rollback tetap manusia.
The source base is Microsoft Learn for pipeline deployment approvals, ManualValidation@1, release approvals, branch policies, and the tasks reference. For an internal release-flow pattern, see the agency cloud release article.
Bagian Claude Code dan bagian approval manusia
Di agency web, pull request, staging URL, approval klien, dan Azure Pipelines run sering ada di tab berbeda. Perubahan copy kecil bisa masuk production karena semua orang mengira orang lain sudah mengecek. Artikel ini mengubah branch policies, ManualValidation, dan approvals menjadi tabel rilis. Claude Code should read pipeline YAML, PR template, diff summary, staging checklist, branch policy notes, and environment approval notes. It should output a release table that names branch, build, staging deploy, manual validation, production environment, approver, timeout, rollback note, and evidence link.
Humans keep client acceptance, ad claims, pricing, legal copy, publish timing, emergency exceptions, and rollback decision. This distinction keeps the agent from acting like the release owner. The agent prepares evidence; the agency decides.
Tiga use case
Use case 1
Input: PR URL, diff, build result, reviewers, branch policy, target page. Output: tabel PR, production, client. Human check: harga, legal copy, iklan, client OK, publish time, rollback.
Use case 2
Input: staging URL, reviewer email, screenshot, diff, rollback note, deadline. Output: ManualValidation@1 instructions dan checklist. Human check: mobile, form, image, link, analytics, client OK.
Use case 3
Input: production environment, approvers, branch control, business hours, exclusive lock, channel. Output: order, owner, timeout, failure contact. Human check: bukan self-approval, rilis malam, iklan, rollback owner.
Prompt siap pakai
You are auditing an Azure DevOps release flow for a web agency.
Inputs: azure-pipelines.yml, PR template, branch policy memo, production environment approvals memo, staging URL checklist, and a recent rollback or rework note.
Output:
1. Three-column table: PR review, staging/client review, production approval.
2. ManualValidation@1 instruction text with staging URL, diff, rollback note, owner, and deadline.
3. Production environment approvals and checks proposal.
4. Branch policy list: reviewer, build validation, comment resolution, status check.
5. One first action that can be done in 30 minutes.
Rules: do not let the agent approve client acceptance, pricing, legal wording, publish timing, or production release.
Kode pengecekan
const pipelineText = [
"trigger:",
" branches:",
" include:",
" - main",
"stages:",
" - stage: Build",
" jobs:",
" - job: build",
" steps:",
" - script: npm ci && npm run build",
" - stage: DeployStaging",
" jobs:",
" - job: deploy_staging",
" steps:",
" - script: echo deploy staging",
" - stage: ClientCheck",
" jobs:",
" - job: wait_for_client",
" pool: server",
" steps:",
" - task: ManualValidation@1",
" inputs:",
" notifyUsers: [email protected]",
" instructions: Check staging URL, PR diff, rollback note, and client approval.",
" - stage: DeployProduction",
" jobs:",
" - deployment: production",
" environment: production",
" strategy:",
" runOnce:",
" deploy:",
" steps:",
" - script: echo deploy production"
].join(String.fromCharCode(10));
const required = [
{ name: "main branch trigger", pattern: /- main/ },
{ name: "staging stage", pattern: /DeployStaging/ },
{ name: "manual validation", pattern: /ManualValidation@1/ },
{ name: "server pool for manual validation", pattern: /pool:\s*server/ },
{ name: "production environment", pattern: /environment:\s*production/ },
{ name: "rollback note in approval text", pattern: /rollback/i }
];
const findings = [];
for (const rule of required) {
if (!rule.pattern.test(pipelineText)) {
findings.push({ item: rule.name, fix: "add this gate before production release" });
}
}
const productionIndex = pipelineText.indexOf("DeployProduction");
const validationIndex = pipelineText.indexOf("ManualValidation@1");
if (productionIndex !== -1 && validationIndex !== -1 && validationIndex > productionIndex) {
findings.push({
item: "approval order",
fix: "place client/manual validation before production deployment"
});
}
console.table(findings);
if (findings.length > 0) process.exitCode = 1;
Pitfall: kesalahan umum
The first cause is treating PR approval as production approval. The fix is to separate code review, staging review, client acceptance, and production approval by name and owner.
The second cause is relying on notification recipients as if they were approvers. The fix is to inspect environment approval and project permissions separately from notifyUsers.
The third cause is approving without a rollback note. The fix is to add rollback commit, previous artifact, owner, and contact path to the approval text.
The fourth cause is bypassing branch policy under pressure. The fix is to define an emergency exception path with time limit, approver, evidence, and follow-up review.
FAQ
Q. Should we use ManualValidation or environment approval? A. Use ManualValidation for an in-stage pause such as staging URL review. Use environment approvals and checks as the production gate.
Q. Should client approval live inside Azure DevOps? A. If the client does not use Azure DevOps, store the approval URL or message link in the release memo and tie it to the pipeline run.
Q. Does a small content change need branch policy? A. Yes. Pricing pages, hiring pages, and ad landing pages can affect leads and revenue even when the code diff is small.
Q. Can Claude Code approve the release? A. No. It can summarize diff, list missing evidence, and draft checklists. Humans approve production.
Jalur konsultasi
Untuk agency, nilai bukan YAML panjang. Nilainya adalah rilis salah yang lebih sedikit dan bukti klien yang jelas. Bawa PR, YAML, checklist staging, dan rollback memo ke konsultasi. Use Claude Code training and consultation if the team needs help turning PRs, pipeline YAML, staging checks, and rollback memos into a repeatable release workflow.
Yang saya verifikasi
Saya memeriksa Microsoft Learn untuk approvals, ManualValidation@1, release approvals, branch policies, dan task reference. Kode lokal mengecek ManualValidation, server pool, production environment, dan rollback note. Langkah pertama adalah tabel tiga kolom: PR, staging, production.
Artikel terkait
Setup CI/CD Claude Code: GitHub Actions aman untuk PR, deploy, dan rollback
Bangun CI/CD aman dengan Claude Code, GitHub Actions, test gate, Secrets, deploy, dan rollback.
GitHub Actions Lanjutan dengan Claude Code: permission, OIDC, cache, dan matrix CI
Rancang GitHub Actions yang aman dengan Claude Code: permission, OIDC, cache, matrix, dan YAML siap pakai.
Workflow Codex untuk Agency: Review Diff, PR, Staging, dan Rilis
Panduan agency memakai Codex Desktop untuk review diff, PR, dan staging tanpa menyerahkan approval rilis kepada agen.
PDF gratis: cheatsheet Claude Code
Masukkan email dan unduh satu halaman berisi command, kebiasaan review, dan workflow aman.
Kami menjaga datamu dan tidak mengirim spam.
Tentang penulis
Masa
Engineer yang berfokus pada workflow Claude Code praktis dan adopsi tim.