Score
Designs and builds automated systems that produce, package, and deploy runtime environments and container images—including infrastructure-as-code templates, image build artifacts (e.g., Dockerfiles/OCI images), CI/CD pipelines, image registries, and deployment manifests or Helm charts. Implements and analyzes automation for provisioning, rollout and rollback, configuration and secrets management, testing and promotion workflows, and integration with orchestration platforms to ensure repeatable, reproducible deployments.
This paper addresses the conceptual ambiguity, ill-defined boundaries, and lack of implementation standards between Infrastructure-as-Code (IaC) and Pipeline-as-Code in DevOps practice. To resolve these issues, we systematically delineate their respective roles and synergistic mechanisms within the DevOps ecosystem and propose a reusable, standardized IaC-driven CI/CD implementation framework. Our approach integrates Terraform for infrastructure provisioning, Ansible for configuration management, GitLab CI for pipeline orchestration, and Docker/Kubernetes for containerized deployment—enabling an end-to-end automated delivery pipeline. Empirical evaluation demonstrates 99.8% configuration change accuracy, reduces environment provisioning time from hours to minutes, and significantly improves deployment consistency and delivery efficiency.
Traditional Jenkins controllers suffer from resource overloading and reduced reliability due to direct execution of build tasks. To address this, we propose a lightweight CI/CD architecture that containerizes the Jenkins controller and offloads all build execution to remote Docker hosts via secure SSH connections—effectively decoupling orchestration from build execution. The architecture incorporates atomic deployments, timestamped artifact backups, immutable artifact packaging, and automated notification mechanisms. Technically, it integrates persistent volumes, containerized build environments, and declarative pipelines. Experimental evaluation demonstrates a significant reduction in controller CPU and memory utilization, a 32% increase in build throughput, and a 41% decrease in artifact delivery latency. The solution delivers high stability, scalability, and low operational overhead, making it particularly suitable for small- to medium-scale DevOps environments.
To address the challenges of prolonged CI pipeline deployment cycles, error-prone manual configuration, and poor cross-project consistency, this paper proposes an automated pipeline configuration framework grounded in Infrastructure-as-Code (IaC) principles and templated configuration. The framework enables declarative definition and one-click generation of CI/CD pipelines via reusable YAML templates, a parameterized pipeline engine, and an integrated automation toolchain. Compared to conventional manual approaches, our method reduces average pipeline deployment time by 72% and decreases human configuration errors by 91%, while substantially improving consistency in build logic and execution environments across projects. Empirical validation across six open-source projects demonstrates the framework’s engineering practicality and methodological generality. It provides a reusable implementation model and actionable methodology for CI/CD automation, advancing scalable, maintainable, and reproducible software delivery practices.
Traditional code coverage metrics and test generation techniques fail for Dockerfiles due to their lack of explicit control-flow constructs, rendering syntactic analysis insufficient for meaningful testing. Method: This paper proposes the first image-layer–driven automated test generation method for Dockerfiles. Instead of relying on syntactic structure, it defines semantic test objectives based on the actual post-build state of Docker image layers—such as file existence, permissions, and content. The approach integrates Dockerfile instruction parsing, static layer analysis, and target file identification to guide a heuristic search for validating test cases. Contribution/Results: Evaluated on real-world projects, the generated tests reproduce over 80% of developers’ manually written tests, significantly enhancing the maintainability and reliability verification of Dockerfiles. By grounding test objectives in observable layer semantics rather than abstract syntax, the method bridges a critical gap in containerized application testing and provides a principled foundation for Dockerfile validation.
This study presents the first empirical investigation into the evolution of CI/CD configurations in machine learning (ML) projects. Addressing the lack of understanding regarding how CI/CD configurations co-evolve with ML components, the authors analyze 508 open-source ML projects, 343 manually annotated commits, and 15,634 automated CI/CD commits. They propose a novel 14-category taxonomy capturing synergistic changes between CI/CD and ML components, develop a dedicated clustering tool to identify recurrent evolutionary patterns, and establish an empirically grounded model linking developer experience to CI/CD configuration modification behavior. Results show that 61.8% of CI/CD-related commits involve build strategy modifications; common anti-patterns—including dependency hardcoding and missing test frameworks—are identified; and senior developers modify CI/CD configurations more frequently and effectively than juniors, confirming the critical role of experience in CI/CD maintenance.
While large language models (LLMs) can generate executable multi-service application environments, they often deviate from the architectural and security requirements essential for production deployment. This work proposes a method to automatically generate Dockerfiles and Docker Compose configurations solely from code repositories, evaluating deployment fidelity through end-to-end HTTP testing and structural comparison. It explicitly distinguishes between functional correctness and fidelity to deployment intent, deriving a minimal set of explicit deployment specifications that cannot be inferred automatically from source code alone. Experiments successfully reproduce the topology and dependencies of three heterogeneous multi-service systems, confirming functional feasibility; however, critical production-grade features—such as network isolation and multi-stage builds—are consistently absent, revealing fundamental limitations in current LLMs’ ability to model deployment intent.
This work addresses the challenge developers face in efficiently authoring CI/CD configurations due to limited DevOps expertise by proposing a large language model (LLM)-based, context-aware generation approach. The method leverages both natural language descriptions and repository structure to automatically produce accurate and executable pipeline configurations for platforms such as GitHub Actions and GitLab CI/CD. Integrated with automated validation and human-in-the-loop feedback mechanisms, this framework is the first to combine repository context understanding with natural language-driven configuration synthesis. Experimental results demonstrate that the approach significantly lowers the barrier to DevOps adoption, markedly improves the accuracy and validity of generated configurations, and substantially reduces manual configuration effort.
This work addresses the fragility, inefficiency, and strong platform coupling commonly found in CI/CD pipelines for legacy COBOL systems, which often result in high maintenance costs and vendor lock-in. To overcome these challenges, the authors propose a portable CI/CD architecture tailored for highly secure and compliance-driven environments. The approach leverages OCI-compliant container images preloaded with COBOL toolchains, introduces a platform abstraction layer, integrates multiple repositories, and employs Groovy script refactoring to achieve platform-agnostic continuous integration and delivery. Empirical evaluation demonstrates that the proposed solution significantly enhances efficiency—reducing pipeline execution time by 82%—while simultaneously improving system portability, security, and maintainability. This architecture offers a reusable paradigm for modernizing legacy COBOL applications within regulated domains.
This work addresses the growing complexity of CI/CD pipelines and the lack of structured analysis capabilities in existing tools for understanding their behavior, failures, and version evolution. The authors propose an innovative approach that uniquely integrates digital twin technology with BPMN-based modeling in DevOps contexts. By automatically parsing raw CI configurations and execution logs, the method constructs structured, high-level process models that enable pipeline visualization, failure traceability, and cross-version comparison. Evaluated across multiple open-source projects, the approach demonstrates effectiveness in monitoring, evolutionary analysis, and fault diagnosis, offering a modular and extensible foundational framework for the analysis and optimization of CI/CD pipelines.
This work addresses the vulnerability of containerized CI/CD pipelines to supply chain attacks, where compromise at a single stage can lead to widespread distribution of malicious images. To mitigate this risk, the authors propose a verifiable container image distribution architecture that enforces integrity and compliance during admission control through policy-as-code mechanisms. The design leverages identity-bound one-time signing keys, an append-only transparency log, and verifiable inclusion proofs to ensure that only validated and compliant artifacts are deployed. Integrated with GitHub Actions and GitLab Runners, the prototype implementation demonstrates effective defense against representative supply chain attacks while maintaining practical deployability.