The pipeline
A DAG of typed steps, declared in release.yaml and validated against a registry of 42 of them before anything is scheduled.
- Matrix expansion, dependency edges and job-level concurrency groups
- Line-accurate diagnostics with stable codes, so an error is searchable
- An escape hatch for shell, deliberately unergonomic and blocked where it would be dangerous
Refuses: No expression language in credential requirements. A job’s credential set must be computable by reading the file, not by evaluating it.