stdsquare²
🎓 Kelas
stdsquare / materi / slides / pertemuan-12
Tema
Japan
Arcade
Dark Retro
Font
‹ Daftar slide Pertemuan 12: DevOps & CI/CD (Pipeline, GitOps, Argo CD, Observability, SRE)
PEBD6027 · RPS minggu 13 · 2x50 menit

DevOps & CI/CD

Pipeline · GitHub Actions · GitLab CI · Argo CD GitOps · Observability

Peta Pembelajaran Hari Ini

Sub-CPMK 12: merancang pipeline CI/CD untuk aplikasi cloud. Empat indikator capaian.

Jam ke-1
  • DevOps culture & CALMS
  • CI: build, test, scan otomatis
  • GitHub Actions & GitLab CI
Jam ke-2
  • CD: deploy staging/prod otomatis
  • Argo CD GitOps untuk K8s
  • Observability: logging, metric, tracing
Posisi 14P: setelah K8s P11, hari ini DevOps CI/CD. P13 FinOps cost management.

Mengapa DevOps & CI/CD?

DevOps = culture + practice + tool. Hasilnya: speed, stability, dan developer happiness.

Deploy Frequency Elite
Multiple/hari
DORA 2023 — Tokopedia 1000+/hari, Gojek 200+/hari
MTTR Elite
less than 1 hour
DORA 2023 — elite vs low performer gap 2,554x
Studi DORA: elite performer 973x lebih sering deploy dengan change failure rate 7x lebih rendah. Budaya kunci.
Bagian 1 · 1/4
DevOps Culture & CALMS
Diskusi: bila tim dev dan tim ops sering konflik (dev salin cepat, ops salin stabil), bagaimana solve?

CALMS Framework

CALMS = Culture, Automation, Lean, Measurement, Sharing. Framework adopsi DevOps.

LetterAspekPraktik Konkret
CCultureBlameless post-mortem, shared responsibility
AAutomationCI/CD pipeline, IaC, test otomatis
LLeanEliminasi waste, small batch, flow
MMeasurementDORA metrics, SLI/SLO/SLA
SSharingCross-functional team, knowledge sharing, open doc
CALMS = checklist adopsi DevOps. Tanpa salah satu, transformasi gagal. Culture paling sulit.

DORA Metrics

Empat metric DORA untuk ukur maturity DevOps. Standard industri.

MetricEliteLow
Deployment FrequencyMultiple per dayBetween once per month and 6 months
Lead Time for ChangesLess than 1 hour1-6 months
Change Failure Rate0-15%46-60%
MTTR (Mean Time to Restore)Less than 1 hourMore than 6 months
Bank Indonesia traditional: low performer (monthly deploy, MTTR hari). Bank digital (Jago, BNC): elite/stable performer.

Studi Kasus: Tokopedia CI/CD 1000+ Deploy/Hari

Tokopedia deploy 1000+ kali per hari dengan CI/CD otomatis. Bagaimana architecture?

Public case study Tokopedia CI/CD (dihedge): GitHub Enterprise monorepo raksasa, Jenkins + Spinnaker pipeline, CanARCanary deployment ke K8s, automated testing ribuan test per PR, feature flag via OpenFeature, observability via Datadog. Engineer push commit → CI run 5-10 menit → auto-deploy canary 1% traffic → validation metric → ramp up 100%. Manual intervensi hanya saat incident.
Komponen Pipeline
  • Lint + static analysis (SonarQube)
  • Unit + integration test
  • Build Docker image
  • Security scan (Snyk, Trivy)
Deployment Strategy
  • Canary 1% → 10% → 100%
  • Feature flag untuk rollback cepat
  • Blue-green untuk DB migration
  • Auto-rollback bila error spike
Pelajaran: 1000+ deploy/hari mungkin karena automation total + canary + feature flag + observability real-time.
Bagian 2 · 2/4
CI Pipeline Anatomi
Diskusi: bila developer push kode berbahaya (misal SQL injection), di tahap mana CI harus tangkap?

Anatomi CI Pipeline

CI Continuous Integration: setiap commit trigger pipeline otomatis. Quality gate.

TahapToolsOutput
1. LintESLint, Black, PrettierCode style konsisten
2. Static AnalysisSonarQube, Snyk CodeCode smell + SAST
3. Unit TestJest, pytest, Go testCoverage report
4. Integration TestTestcontainers, Docker ComposeService interaction OK
5. BuildDocker, Maven, npmArtifact (image, jar)
6. Container ScanTrivy, Snyk ContainerImage no CVE critical
7. Push RegistryECR, GHCRImage available untuk deploy
Pipeline fail-fast: tahap pertama gagal → skip sisanya. Hemat CI compute. Feedback cepat ke developer.

GitHub Actions vs GitLab CI vs Jenkins

Tiga tool CI populer. Trade-off: integration, cost, learning curve.

AspekGitHub ActionsGitLab CIJenkins
HostingSaaS (GitHub)SaaS atau self-hostSelf-host (biasanya)
ConfigYAML di .github/workflowsYAML di .gitlab-ci.ymlGroovy Jenkinsfile
EcosystemMarketplace besarBuilt-in registry & securityPlugin 1800+
CostGratis publik, $ untuk privateGratis hingga tier menengahOpen-source + infra cost
Best ForGitHub repo, modern teamAll-in-one GitLabEnterprise legacy, kompleks
Pilihan tergantung strategi Git. GitHub → Actions. GitLab → CI. Legacy → Jenkins migrasi pelan-pelan.

Hitung dari Nol: ROI CI/CD Manual vs Automated

Startup 5 engineer, deploy manual 4 jam per release, 4 release/minggu. Berapa saving?

KomponenManualCI/CD Otomatis
Time per release4 jam × 5 engineer30 menit × 1 engineer
Release per minggu4 release20 release (5x lebih)
Engineer hours/minggu80 jam10 jam
Cost @ $50/jam$4,000/minggu$500/minggu
Hemat mingguan$3,500 ($182K/tahun)
Initial setup CI/CD2 minggu × 5 eng = $20K
Net benefit tahun-1$160K+
Plus: less human error10% rollback2% rollback (hemat lebih)
Harga engineering $50/jam (dihedge). ROI CI/CD dalam 2 bulan. Bonus: 5x release frequency = fitur lebih cepat ke user.
3/4
CD & GitOps
Diskusi: bila deploy ke produksi harus manual approval dari VP, apakah masih bisa CD?

CD: Continuous Delivery vs Deployment

CD = Continuous Delivery atau Deployment. Beda tipis tapi signifikan untuk compliance.

AspekContinuous DeliveryContinuous Deployment
DefinisiSetiap commit SIAP deploySetiap commit OTOMATIS deploy
Approval prodManual gateNo manual gate
RiskRendah (human review)Tinggi (tanpa gate)
Best ForBank, fintech regulatedStartup, web consumer
ToolsArgo CD + manual syncArgo CD auto-sync
AuditApproval trail via PRPR + auto-deploy
Bank compliance POJK: Continuous Delivery dengan 4-eyes approval prod. Continuous Deployment berisiko.

Argo CD GitOps untuk K8s

Argo CD = continuous delivery tool untuk K8s. Git sebagai source of truth.

Cara Kerja
  • Git repo sebagai source of truth
  • Argo CD sync ke cluster
  • Auto atau manual sync mode
  • Drift detection real-time
Manfaat
  • Audit trail Git history
  • Rollback mudah via Git revert
  • Multi-cluster central
  • Developer friendly PR workflow
Argo CD open-source CNCF graduated. Gojek, Bank Jago, Red Hat pakai. Flux alternatif.

Deployment Strategy

Empat strategi deployment. Trade-off: complexity vs zero-downtime vs rollback.

StrategiCaraUse Case
Rolling UpdatePod lama replace bertahapDefault K8s, no extra infra
Blue-Green2 env identik, switch trafficDB migration, instant rollback
Canary1% traffic → 10% → 100%Risk-sensitive, validate metric
Feature FlagToggle fitur tanpa redeployA/B test, dark launch
Bank & fintech: canary + feature flag standard. Memungkinkan rollback cepat tanpa redeploy.
4/4
Observability & SRE
Diskusi: bila produksi incident, bagaimana cara tahu root cause dengan cepat?

Three Pillars of Observability

Observability = logs + metrics + traces. Tiga pilar wajib produksi.

Logging
  • Event diskrit
  • stdout aplikasi
  • ELK, Loki, CloudWatch
  • Search & filter
Metrics
  • Time-series numeric
  • CPU, latency, error rate
  • Prometheus, Datadog
  • Dashboard & alert
Tracing
  • Request journey across service
  • Distributed tracing
  • Jaeger, Zipkin, X-Ray
  • Root cause analysis
Tiga pilar saling melengkapi. Bila incident: alert metric → cari trace → baca log. Workflow debugging.

SRE & Error Budget

SRE Site Reliability Engineering Google. Error budget = 1 - SLO. Trade-off speed vs reliability.

Konsep Inti
  • SLI: indicator (latency, availability)
  • SLO: target (99,9% availability)
  • SLA: contract dengan customer
  • Error budget = 1 - SLO
Implementasi
  • 99,9% SLO = 43,2 menit downtime/bulan
  • Bila budget habis: freeze fitur
  • Fokus reliability
  • Budget renewal tiap bulan/kuartal
Error budget = shared KPI dev (speed) vs ops (reliability). Tanpa budget: dev pakai budget untuk fitur. Habis: ops kunci deploy.

Feature Flag & Dark Launch

Feature flag = decouple deploy dari release. Dark launch = production test tanpa user lihat.

Feature Flag
  • Toggle fitur on/off via config
  • Tanpa redeploy aplikasi
  • Targeting: per-user, per-cohort, per-region
  • Tools: LaunchDarkly, OpenFeature, Unleash
Dark Launch
  • Deploy fitur ke prod tanpa ekspos user
  • Route traffic test ke feature
  • Validate metric real-world
  • Gojek: dark launch payment baru
Feature flag standard Tokopedia & Gojek. Memungkinkan rollback instan tanpa redeploy (cuma toggle off).

Ringkasan Kunci Pertemuan 12

Hari ini Anda menguasai DevOps culture, CI/CD pipeline, GitOps, observability, dan SRE.

CALMS Culture
Culture + Automation + Lean + Measurement + Sharing.
CI/CD Pipeline
Lint-test-scan-build-deploy. GitOps via Argo CD untuk K8s.
Observability
Logs + Metrics + Traces. SRE error budget untuk trade-off speed-reliability.

Tiga lensa P12: CALMS culture · pipeline otomatis · observability 3 pilar.

Persiapan P13: FinOps cost management. Baca FinOps Framework FinOps Foundation. Kuis 5 menit soal DORA metrics.