
A controlled three-environment release pipeline on Azure
Branch-based releases to development, staging and production, with secrets applied at deploy time and security findings posted on every pull request.
- Partner
- A global advisory firm
- Period
- October 2024 to January 2026
- Environments
- 3
- Development, staging and production
- Scanners
- 2
- SonarQube analysis and Trivy vulnerability scans
- Secrets
- Per env
- Held in Doppler, applied at deploy time
The challenge
A platform used across a large organization needed predictable releases, clear separation between environments, and security checks that reviewers could not miss.
What we built
GitHub Actions workflows that map branches to environments, build and push a Docker image to Azure Container Registry, write secrets from Doppler into App Service settings, and deploy two web apps per environment. Every pull request receives SonarQube analysis and a Trivy scan.
What was delivered
- Branch to environment mapping for dev, stage and main
- Secrets managed in Doppler per environment and applied at deploy time
- Critical and high vulnerabilities reported as a pull request comment
Partner background
Our partner is a global advisory firm whose teams work with large volumes of documents, spreadsheets, databases and email. It wanted one internal platform where those teams could build data pipelines and AI agents themselves, instead of commissioning a new application for each need. The platform had to run inside the partner's Microsoft 365 and Azure environment, keep each team's work separate, and move work from experiment to production through controlled environments.
The challenge
Environments drift
Manual releases make it hard to know what is running where, and configuration differences between environments go unnoticed.
Secrets in the wrong places
Credentials copied into files or pipeline variables are hard to rotate and easy to leak.
Findings nobody sees
Security reports stored outside the review process are rarely read before a merge.
Objectives
- Release by merging to a branch, with no manual deployment steps
- Keep secrets out of the repository and per environment
- Put code quality and vulnerability findings in front of reviewers
- Catch formatting and lint issues before code is committed
Our role
CharCentric provided technical leadership and architecture within a multidisciplinary engineering team, and contributed directly to implementation. The platform was built over 16 months, from October 2024 to January 2026, as a Python and FastAPI backend on Azure.
Scope and timeline
The release and scanning workflows were built between December 2024 and March 2025.

Approach
Branches as environments
Pushing to dev, stage or main selects the development, staging or production environment, its GitHub environment rules and its secrets configuration.
Secrets applied at deploy time
Doppler holds secrets per environment. The pipeline writes them into Azure App Service settings during deployment, so they never live in the code.
Findings where decisions are made
Trivy scans for critical and high vulnerabilities and updates a single comment on the pull request. SonarQube analyses every push and pull request.
Implementation

Commit checks
Pre-commit hooks lint and format only the changed code and check YAML, trailing whitespace and large files.
Build
Each release builds a fresh Docker image, tags it for its environment and pushes it to Azure Container Registry.
Deploy
A matrix job configures and updates two Azure web apps per environment in parallel.

Tools and technologies
| Tool | Purpose |
|---|---|
| GitHub Actions | Build, scan and deploy workflows |
| Docker | Application images |
| Azure Container Registry | Image storage |
| Azure App Service | Hosting |
| Doppler | Secrets per environment |
| SonarQube | Code quality analysis |
| Trivy | Vulnerability scanning |
| pre-commit | Local checks |
What was delivered
- Environments
- 3
- Apps per environment
- 2
- Scanners
- 2
- Secrets source
- Doppler
- Branch-driven releases to three environments
- Secrets managed centrally and applied at deploy time
- Vulnerability findings posted on each pull request
- Consistent formatting enforced before commit
Why it matters
Release discipline is cheapest to establish early. A clear path from branch to environment, with secrets and security checks built in, keeps a growing platform predictable.
If your organization is planning a platform of this kind, or needs a specific part of one designed and delivered, we would be glad to discuss it.