DevOps Assurance
How delivery actually works, measured: branch protection, security gates, release practice and deployment maturity.
Runs today, on Google Cloud
Connect a Google Cloud project and this module reads it. Today that means:
- Artifact Registry cleanup policies
- Cloud Build triggers, and whether any exist
It reads Google Cloud only, not AWS or Azure, and it does not track remediation. Everything further down this page is where the module is going, not what it does now. The wider review is work we do as an engagement — DevOps Maturity Assessment.
Why this module exists
Delivery practice is usually described in a wiki page written two years ago. What the pipelines actually enforce today is a different question, and nobody audits it.
What it is being built to surface
Descriptions of intent. No findings exist yet, because nothing is connected yet.
Pipeline reality
What the pipelines genuinely run, versus what the process document claims.
Branch protection
Which repositories can be pushed to directly, and by whom.
Security gates
Where checks exist, where they are advisory, and where they are routinely bypassed.
Delivery metrics
Lead time, deployment frequency, change failure rate and recovery time, measured rather than estimated.
What the module covers
- CI/CD maturity across GitHub, GitLab, Azure DevOps and Jenkins
- GitOps and Terraform practice
- Branch protection and security gates
- Engineering delivery metrics
Tell us what this would need to catch
We are designing this against real environments. If this is a problem you have, the fastest way to shape it is a conversation with the engineers building it.
Talk to an Engineer