Produce an evidence-backed release verdict that distinguishes code quality, CI success, deployment success, and live runtime health. The skill prevents a green pipeline or successful deploy event from being treated as proof that a service is usable in its target environment.
Do not use this skill as a substitute for feature acceptance, security review, load testing, disaster-recovery exercises, or regulatory approval.
Agree on these inputs before testing:
If the target, authorization, or success criteria are ambiguous, stop and request clarification. Never probe an unrelated environment, expose credentials in output, or modify production data merely to obtain a passing result.
Record every gate as one of:
BLOCKED is not PASS. An overall certification can be GREEN only when every required gate passes. Any required failure produces RED; any required blocked gate with no failure produces BLOCKED.
Capture the immutable source revision and intended runtime artifact. Confirm that the deployed artifact maps to that revision. A branch name, local working tree, or “latest deployment” label is not immutable evidence.
Run the repository's current validation and test commands on the pinned revision. Inspect the required CI jobs for the same revision, including conclusion and timestamp. Do not infer full CI success from one job or from an older run.
Confirm that the target environment reports the expected deployment, revision, or artifact digest. Record the environment and deployment identifiers without copying secrets or sensitive configuration values.
Use the application's supported migration status or a read-only schema-version query. Confirm migrations completed on the target database and that the application is not running against an unexpected database or schema.
Do not apply, roll back, repair, or stamp migrations unless the user separately authorizes that mutation and a recovery plan exists.
Test liveness and readiness separately when both exist:
Record timestamp, target, status code, bounded response summary, and latency. Redact tokens, cookies, internal hostnames, database addresses, and response fields that contain secrets or personal data.
Run the smallest authorized smoke suite that proves the agreed critical journeys. Prefer synthetic or test records and read-only probes. For authenticated routes, use designated test identities with least privilege and never place credentials in commands, logs, or the report.
Inspect the bounded deployment window for crash loops, unhandled exceptions, dependency failures, elevated error rates, or resource exhaustion. Absence of log access is BLOCKED, not proof of health.
Publish the evidence matrix, unresolved risks, and exact overall verdict. Keep observations separate from inference. Include enough identifiers and timestamps for another engineer to reproduce the decision without exposing sensitive data.
PRODUCTION RUNTIME CERTIFICATION
Environment: <target>
Source revision: <immutable revision>
Deployment/artifact: <immutable identifier>
Observed at: <UTC timestamp>
SOURCE VALIDATION: PASS | FAIL | BLOCKED | NOT APPLICABLE
CI: PASS | FAIL | BLOCKED | NOT APPLICABLE
DEPLOYMENT IDENTITY: PASS | FAIL | BLOCKED | NOT APPLICABLE
DATABASE MIGRATIONS: PASS | FAIL | BLOCKED | NOT APPLICABLE
LIVENESS: PASS | FAIL | BLOCKED | NOT APPLICABLE
READINESS: PASS | FAIL | BLOCKED | NOT APPLICABLE
CRITICAL ROUTES: PASS | FAIL | BLOCKED | NOT APPLICABLE
OPERATIONAL SIGNALS: PASS | FAIL | BLOCKED | NOT APPLICABLE
OVERALL: GREEN | RED | BLOCKED
Evidence: <commands/checks, run IDs, timestamps, bounded results>
Unresolved risks: <none or explicit list>
SOURCE VALIDATION: PASS — revision 8f31c2a, tests 146/146
CI: PASS — required run 72814 completed at 2026-09-12T10:06:00Z
DEPLOYMENT IDENTITY: PASS — artifact maps to revision 8f31c2a
DATABASE MIGRATIONS: BLOCKED — target database access unavailable
LIVENESS: FAIL — HTTP 503 at 2026-09-12T10:14:22Z
READINESS: FAIL — HTTP 503 at 2026-09-12T10:14:24Z
CRITICAL ROUTES: BLOCKED — smoke checks stopped after readiness failure
OPERATIONAL SIGNALS: BLOCKED — log access unavailable
OVERALL: RED
Unresolved risks: runtime cause and database state remain unverified
SOURCE VALIDATION: PASS
CI: PASS
DEPLOYMENT IDENTITY: PASS
DATABASE MIGRATIONS: PASS
LIVENESS: PASS
READINESS: PASS
CRITICAL ROUTES: PASS
OPERATIONAL SIGNALS: PASS
OVERALL: GREEN
Unresolved risks: none within the agreed certification scope
Problem: CI is green, so the release is declared healthy. Solution: Verify deployment identity, migrations, readiness, routes, and operational signals independently.
Problem: A liveness response is treated as readiness. Solution: Test dependency-aware readiness criteria or record readiness as BLOCKED when none exist.
Problem: Smoke tests accidentally create or alter customer data. Solution: Use non-destructive probes or designated synthetic records with an explicit cleanup policy.
Problem: Missing access is reported as success because no error was observed. Solution: Mark the affected gate BLOCKED and keep the overall verdict BLOCKED unless another required gate fails.
Problem: Credentials or internal configuration are copied into evidence. Solution: Record identifiers and bounded outcomes; redact secrets, personal data, and sensitive topology.
@verification-before-completion — verifies that any completion claim has fresh supporting evidence; use this skill for the production-specific gate model and verdict.@deployment-procedures — use for executing a deployment; return here afterward to certify the deployed runtime.