WARQLINE
WQL.PLATFORM.DEVOPS.ASSURANCE// ONLINE
/ 01 — DEVOPS ASSURANCE

DevOps Assurance

How delivery actually works, measured: branch protection, security gates, release practice and deployment maturity.

Runs today, on Google Cloud

Connect a Google Cloud project and this module reads it. Today that means:

  • Artifact Registry cleanup policies
  • Cloud Build triggers, and whether any exist

It reads Google Cloud only, not AWS or Azure, and it does not track remediation. Everything further down this page is where the module is going, not what it does now. The wider review is work we do as an engagement — DevOps Maturity Assessment.

THE PROBLEM

Why this module exists

Delivery practice is usually described in a wiki page written two years ago. What the pipelines actually enforce today is a different question, and nobody audits it.

INTENDED SIGNALS

What it is being built to surface

Descriptions of intent. No findings exist yet, because nothing is connected yet.

Pipeline reality

What the pipelines genuinely run, versus what the process document claims.

Branch protection

Which repositories can be pushed to directly, and by whom.

Security gates

Where checks exist, where they are advisory, and where they are routinely bypassed.

Delivery metrics

Lead time, deployment frequency, change failure rate and recovery time, measured rather than estimated.

SCOPE

What the module covers

  • CI/CD maturity across GitHub, GitLab, Azure DevOps and Jenkins
  • GitOps and Terraform practice
  • Branch protection and security gates
  • Engineering delivery metrics

Tell us what this would need to catch

We are designing this against real environments. If this is a problem you have, the fastest way to shape it is a conversation with the engineers building it.

Talk to an Engineer