Hardened delivery pipeline
CI/CD case study
Took a Go service from manual deploys and a root-running ~1GB image to an ~8MB non-root distroless image shipped by a tested, Trivy-scanned pipeline. Build → scan → push → deploy, with the vulnerability scan gating the release.
