- Home
- Skills
- Code Quality & Review
- Quality Gate Enforcement and Build-Breaker Automation
Quality Gate Enforcement and Build-Breaker Automation
Enforces CI/CD quality gates: non-bypassable branch protection, automated build breakers, and latency baselines.
$5
Works with the AI tools you already use
Quality Gate Enforcement and Build-Breaker Automation
Example session with this skill installed
Configure and enforce automated CI/CD quality gates, branch protections, and promotion criteria for Core Payment Engine.
- Subject: core-payment-engine v3.2 (run-id: pay-gate-001) processing 42,000 transactions/second across 16 microservices.
- Deciders: Lead Platform Architect (David O'Reilly) and Head of Payment Quality Engineering (Elena Rostova).
- Scope: Enforcing 4 automated gates: test coverage (>= 85%), static CVE vulnerabilities (zero critical/high), ArchUnit boundary rules, and latency benchmarks (p99 <= 80ms at 10,000 TPS).
- Tension: Developers bypassed test suites during hotfixes using
--skip-tests; in incident GAT-4919, deploying an un-tested null-pointer bug dropped 12,500 checkouts and caused $1.8M in lost sales. Elena Rostova and David O'Reilly mandate non-bypassable CI/CD branch protections: automated build-breakers, disabled bypass flags, and strict dual-signature waiver protocols.
Write the quality gate rule config under docs/.
- Read your context and instructions
- Compiled the quality gate enforcement
- Generated the document
Wrote docs/architecture/tasks/pay-gate-001/quality-gate-enforcement/quality-gate-rule-config.md. Complete quality gate enforcement configuration establishing automated CI/CD gating rules, promotion criteria, branch protections, and bypass prevention.
skill: quality-gate-enforcement
Quality Gate Rule Config: Core Payment Engine [GATE-PAY-001]
Summary
This specification establishes the automated quality gate enforcement configuration, promotion criteria, threshold policies, and build-breaker gates for core-payment-engine v3.2 under run ID pay-gate-001. It governs deployment pipelines across 16 microservices processing 42,000 transactions/second. It decisively resolves the production outages demonstrated in incident GAT-4919 (where developers bypassed test suites during an emergency hotfix using --skip-tests, deploying an un-tested null-pointer bug into the credit card authorization path that dropped 12,500 active checkouts and caused $1.8M in lost sales). The configuration enforces
non-bypassable CI/CD branch protection gates, mandates
minimum 85.0% line and branch test coverage, requires zero high-severity static analysis vulnerabilities (SonarQube Quality Gate), validates
sub-80ms p99 latency fitness benchmarks, and establishes a
strict dual-signature release waiver protocol.
Detailed Description
Quality gates that rely on voluntary developer adherence or manual checklist reviews inevitably get bypassed when release pressure mounts. Quality Gate Enforcement automates the promotion boundary between development, staging, and production environments: it translates architecture policies into executable build rules, evaluates inspectable telemetry artifacts at pull-request gates, and physically halts pipeline progression if any quality threshold is breached.
Developer Pull Request Ingress (42,000 TPS Target Estate)
│
▼
[ Automated CI/CD Quality Gate Pipeline: GitHub Actions & ArgoCD ]
├── Gate 1: Static Code Quality ──► SonarQube (Coverage >= 85%, Zero High CVEs)
├── Gate 2: Architecture Linter ──► ArchUnit (Zero Cyclic Module Dependencies)
├── Gate 3: Automated Latency ──► k6 Benchmark (p99 <= 80 ms at 10,000 TPS)
└── Gate 4: Security Scan ──► Snyk Container Image Vulnerability Audit
│
┌─────────────────┴─────────────────┐
▼ (All Gates: PASSED) ▼ (Any Gate Fails: INCIDENT GAT-4919)
[ Production Promotion Authorized ] [ Automated Build Breaker: BLOCKED ]
└── Cryptographic Receipt Signed ├── Pipeline Terminates with Exit Code 1
└── Diagnostic: `ERR_QUALITY_GATE_BREACH`
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Non-Bypassable Automated Enforcement | Skipping tests caused incident GAT-4919 ($1.8M lost sales, 12.5k dropped checkouts). | 0.40 | David O'Reilly (Lead Platform Architect) |
| Test Coverage & Branch Completeness (>= 85%) | High-throughput payment authorization cannot tolerate un-tested conditional branches. | 0.30 | Elena Rostova (Head of Payment Quality) |
| Latency Fitness Benchmark (p99 <= 80 ms) | Performance regressions in authorization code breach merchant bank SLAs. | 0.15 | Core Payment Gateway SLA |
| Static Vulnerability & CVE Zero-Tolerance | Un-patched vulnerabilities in payment container images violate PCI-DSS v4.0. | 0.15 | Corporate Information Security Policy |
Comparison
| Quality Gate Mechanism | Enforcement Rigor | Bypass Vulnerability | Release Traceability | Evaluation |
|---|---|---|---|---|
| Option A: Voluntary Developer Checklists | Very Poor (Easily skipped under deadline) | Extreme (Caused GAT-4919 outage) | Opaque (Un-audited PR merges) | Rejected: Caused GAT-4919 disaster; unviable. |
| Option B: Advisory PR Comments (Non-blocking) | Low (Developers merge over warning comments) | High (Warnings ignored as noise) | Low (Fails to block artifacts) | Rejected: Fails to enforce architectural boundaries. |
| Option C: Automated Hard Build-Breaker Gates (Chosen) | Absolute (Zero merge without gate pass) | Zero (Protected GitHub branches) | Complete (Cryptographic tokens) | Selected: 100% automated enforcement, zero bypass. |
Result
Option C is selected. All quality gates are configured as blocking preconditions in GitHub Actions and ArgoCD; branch protections prohibit merging code failing gate verification; manual --skip-tests flags are disabled at the runner level.
Required Mechanisms
1. Quality Gate Configuration Matrix [MC-GM-01]
| Gate ID | Verification Domain | Evaluation Tool | Target Threshold Rule | Failure Action |
|---|---|---|---|---|
| GATE-01 | Unit & Integration Test Coverage | JaCoCo / SonarQube | Line Coverage $\ge 85.0%$; Branch Coverage $\ge 80.0%$ | Build Break (Exit 1) |
| GATE-02 | Security Vulnerability Scanning | Snyk / Trivy Container | Zero Critical or High CVEs in dependencies or base images | Build Break (Exit 1) |
| GATE-03 | Architectural Dependency Linter | ArchUnit JVM | Zero circular package dependencies; zero direct DB calls | Build Break (Exit 1) |
| GATE-04 | Performance Latency Benchmark | k6 / Staging Runner | Under 10,000 TPS load: p99 latency $\le 80.0\text{ ms}$ | Promotion Block (Exit 1) |
2. Bypass Prevention & Branch Protection Rules [MC-BP-01]
- The GAT-4919 Remediation Rule:
- GitHub repository branch protection is locked on
mainandrelease/*. - Direct pushes and administrator override merges (
force-push) are physically disabled. - CI runners execute within isolated ephemeral environments where maven flag
-DskipTestsor-Dmaven.test.skip=truetriggers immediate pipeline termination.
- GitHub repository branch protection is locked on
3. Dual-Signature Emergency Exception Protocol [MC-EX-01]
- If a critical zero-day patch requires deploying code with degraded non-critical test coverage:
- Requires cryptographic digital signatures from both David O'Reilly (Platform Architect) and Elena Rostova (Head of Quality).
- Exception is time-bounded: expires automatically after
72 hours, generating an automated Sev-1 ticket for full remediation.
Invariants and Contracts
Mandatory Automated Build Break Invariant [INV-GATE-01]
Any pull request failing a certified quality gate threshold must terminate the CI pipeline with exit code 1.
Promoting artifacts that failed gate verification to staging or production environments is strictly prohibited.
Prohibition of Administrative Bypass [INV-GATE-02]
Repository branch protection rules must disallow administrator bypass of required status checks.
Merging pull requests without passing CI status checks is barred.
Strict Latency Regression Defense [INV-GATE-03]
Pull requests introducing code that degrades p99 authorization latency beyond 80 ms are rejected.
Performance benchmarks are executed automatically against staging replicas prior to promotion.
Explicit Unknowns
- Runner execution latency overhead when executing 4,500 integration tests on concurrent pull requests (G-1).
- Flaky test false-positive rates during third-party sandbox gateway maintenance windows (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 42,000 authorizations/sec across 16 services | provided | Payment gateway capacity intake | Current |
| Incident GAT-4919 $1.8M sales loss and dropped checkouts | provided | Historical post-mortem incident report | Historical |
| 85% line coverage and 80ms p99 latency target | provided | Quality engineering specification | Current |
| Automated hard build-breaker gates selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Prohibition of administrative bypass invariant | decided | Architectural invariant INV-GATE-02 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against quality gate enforcement standards:
- Enforcement Rigor: PASS. 4 blocking gates cover Coverage, Security, Architecture, and Latency.
- Bypass Defense: PASS. Eliminates manual bypass flags; root cause of incident GAT-4919 closed.
- Exception Discipline: PASS. Strictly bounds emergency waivers to 72 hours with dual executive signatures.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-GATE-01: Elena Rostova to determine whether mutation test coverage (PITest score >= 65%) should be added as a mandatory Gate 5 in Q1 (Owner: Elena Rostova).
Next steps
- Platform DevOps configures GitHub Actions workflow rules enforcing GATE-01 through GATE-04.
- Enable branch protection rules on all 16 payment microservice repositories disallowing admin bypass.
- Conduct staging game day testing synthetic PR failures to confirm 100% build-breaker reliability.
quality-gate-enforcement-and-build-break.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill defines how one authority-backed gate consumes check evidence, aggregates results, obtains a decision and controls a workflow transition. It does not invent criteria, execute specialist checks, approve the subject, fix failures or claim outcomes.
Use it when
Use when a previously defined gate must be bound to exact workflow decision points, evidence, failure behavior, exceptions and enforcement effects.
For example: “A broken build bypassed CI checks and deployed to production because the security scanner timed out and the pipeline defaulted to success.”
What you get
- Quality Gate Rule Config
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/quality-gate-enforcement/.
What it will not do
Do not use for gate/checklist/policy definition, test execution, checklist validation, release approval or remediation.
How it works
- Check quality gate enforcement is required.
- Bind gate objective and workflow boundary.
- Map criteria to check intake pipelines.
- Configure result aggregation and decision logic.
- Establish enforcement effects and bypass routes.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install