CI concurrency groups limit how many workflow runs or jobs in the same group execute at once. They are useful for serializing changes to one environment, but cancellation settings matter: replacing a pending run can skip an intermediate deployment, and canceling a running deployment can interrupt a mutation after some resources have changed. A passing status check applies to a particular commit and workflow result, not to every later commit on the branch.
CI deployment concurrency: serialize mutations without losing change evidence
Operational decision
A parcel API deploys from a protected branch. Keep build and test jobs tied to each commit, and place the production deployment job in a group unique to that environment. The YAML fragment belongs under a job, not at the workflow root. It avoids canceling a running deployment, but the team's queue behavior still needs review in its current CI configuration. Require checks and the deployment approval rule appropriate to the repository. After each run, read back the deployed image digest and attach it to the exact commit. Re-run required checks when the merge base changes under a merge queue; do not carry forward a green result from a stale head. If a queued run is replaced, record which commit was skipped and verify that the final artifact includes its intended change. A lock does not make infrastructure changes atomic.
concurrency:
group: parcel-api-production-deploy
cancel-in-progress: false
environment: production
steps:
- name: Deploy reviewed image
run: ./scripts/deploy-reviewed-digest.shCost and verification
Serializing deployments increases queue time but reduces races between two writers to the same environment. A single broad group can block unrelated services, so scope it to the actual shared resource. A cancelled run may leave its build artifact intact while its deployment state is partial. Examine CI history, deployment-controller state, and the running digest before retrying. Branch protection and deployment concurrency solve separate problems: one gates a merge, the other orders environment mutations.
Common Mistakes
- Do not use one concurrency group for unrelated environments.
- Do not cancel an in-progress stateful deployment without a recovery plan.
- Do not equate a green check on an older commit with proof of the deployed digest.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Continuous integration: test the merge candidate
- GitHub Actions: narrow tokens and cloud trust
- Immutable artifacts and release provenance
- Release evidence: tie one deployed digest to one approval decision
