Case study 11 · Engineering Lifecycle Services

A controlled three-environment release pipeline on Azure

Branch-based releases to development, staging and production, with secrets applied at deploy time and security findings posted on every pull request.

Partner
A global advisory firm
Period
October 2024 to January 2026
Photo: Laurent Etourneau on Unsplash
Environments
3
Development, staging and production
Scanners
2
SonarQube analysis and Trivy vulnerability scans
Secrets
Per env
Held in Doppler, applied at deploy time

The challenge

A platform used across a large organization needed predictable releases, clear separation between environments, and security checks that reviewers could not miss.

What we built

GitHub Actions workflows that map branches to environments, build and push a Docker image to Azure Container Registry, write secrets from Doppler into App Service settings, and deploy two web apps per environment. Every pull request receives SonarQube analysis and a Trivy scan.

What was delivered

  • Branch to environment mapping for dev, stage and main
  • Secrets managed in Doppler per environment and applied at deploy time
  • Critical and high vulnerabilities reported as a pull request comment

Partner background

Our partner is a global advisory firm whose teams work with large volumes of documents, spreadsheets, databases and email. It wanted one internal platform where those teams could build data pipelines and AI agents themselves, instead of commissioning a new application for each need. The platform had to run inside the partner's Microsoft 365 and Azure environment, keep each team's work separate, and move work from experiment to production through controlled environments.

The challenge

Environments drift

Manual releases make it hard to know what is running where, and configuration differences between environments go unnoticed.

Secrets in the wrong places

Credentials copied into files or pipeline variables are hard to rotate and easy to leak.

Findings nobody sees

Security reports stored outside the review process are rarely read before a merge.

Objectives

  • Release by merging to a branch, with no manual deployment steps
  • Keep secrets out of the repository and per environment
  • Put code quality and vulnerability findings in front of reviewers
  • Catch formatting and lint issues before code is committed

Our role

CharCentric provided technical leadership and architecture within a multidisciplinary engineering team, and contributed directly to implementation. The platform was built over 16 months, from October 2024 to January 2026, as a Python and FastAPI backend on Azure.

Scope and timeline

The release and scanning workflows were built between December 2024 and March 2025.

Delivery timeline from the project history, against the overall platform build
Delivery timeline from the project history, against the overall platform build

Approach

Branches as environments

Pushing to dev, stage or main selects the development, staging or production environment, its GitHub environment rules and its secrets configuration.

Secrets applied at deploy time

Doppler holds secrets per environment. The pipeline writes them into Azure App Service settings during deployment, so they never live in the code.

Findings where decisions are made

Trivy scans for critical and high vulnerabilities and updates a single comment on the pull request. SonarQube analyses every push and pull request.

Implementation

Release pipeline from commit to deployment
Release pipeline from commit to deployment

Commit checks

Pre-commit hooks lint and format only the changed code and check YAML, trailing whitespace and large files.

Build

Each release builds a fresh Docker image, tags it for its environment and pushes it to Azure Container Registry.

Deploy

A matrix job configures and updates two Azure web apps per environment in parallel.

Branch, environment, secrets configuration and deployed web apps
Branch, environment, secrets configuration and deployed web apps

Tools and technologies

ToolPurpose
GitHub ActionsBuild, scan and deploy workflows
DockerApplication images
Azure Container RegistryImage storage
Azure App ServiceHosting
DopplerSecrets per environment
SonarQubeCode quality analysis
TrivyVulnerability scanning
pre-commitLocal checks

What was delivered

Environments
3
Apps per environment
2
Scanners
2
Secrets source
Doppler
  • Branch-driven releases to three environments
  • Secrets managed centrally and applied at deploy time
  • Vulnerability findings posted on each pull request
  • Consistent formatting enforced before commit

Why it matters

Release discipline is cheapest to establish early. A clear path from branch to environment, with secrets and security checks built in, keeps a growing platform predictable.

If your organization is planning a platform of this kind, or needs a specific part of one designed and delivered, we would be glad to discuss it.