An ephemeral environment is a temporary deployment tied to a change or review period. It can expose integration faults before promotion, but it is still an environment with network access, data, and cost. A preview should have a known owner, expiration, access boundary, synthetic test data, and cleanup verification.
Ephemeral environments: keep preview access and cost bounded
Operational decision
A billing API pull request needs a temporary namespace to exercise a new route and migration. Build the exact image digest under test and provision a namespace with a unique change identifier. Use a synthetic ledger dataset and a test-only database identity. The manifest is a namespace marker, not a complete isolation policy: add quota, network policy, RBAC, and a scoped deploy identity before untrusted code runs. Never expose production Secrets to pull-request workflows. Record the deployment URL only in the approved review surface, limit ingress to reviewers, and destroy the environment after merge or timeout. Check that PVCs, snapshots, load balancers, and DNS entries were removed; deleting a namespace may not remove every external resource. Measure cost by review ID so lingering previews are visible.
apiVersion: v1
kind: Namespace
metadata:
name: billing-review-47
labels:
app.kubernetes.io/part-of: billing-api
ai-trove-owner: billing-platform
ai-trove-purpose: pull-request-reviewCost and verification
Preview environments spend compute, database, edge, and log capacity while they exist. Shared dependencies lower cost but can make tests interfere with each other, so decide what must be isolated. A broad public preview URL can expose unfinished features or synthetic-but-sensitive metadata. Use an expiration controller or scheduled cleanup with an audit trail. A cleanup job that reports success while leaving cloud load balancers behind has not met the cost boundary.
Common Mistakes
- Do not give untrusted pull-request code production credentials.
- Do not assume namespace deletion cleans up every external asset.
- Do not present a preview as a production-equivalent test without naming shared dependencies.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- GitHub Actions: narrow tokens and cloud trust
- Namespace quotas: reserve room for a safe rollout
- Kubernetes NetworkPolicy: permit only required flows
- Cloud cost and capacity: assign an owner to each recurring resource
