Project challenges / verified progress
Beacon: ship it without fear

The engineering notebook

Release to a slice

How do canaries and rollouts limit blast radius?

Loading statusStage 7 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Release and recover

Step 01 of 06

Learn the concept

A deployment is not the same as a release. You can put new code in the cluster and still expose it to only five percent of users. Progressive delivery buys time for metrics to disagree with optimism.

CANARY TRAFFIC SCHEDULEtraffic weight5%smoke metrics5 min25%watch errors10 min50%watch latency10 min100%promote stabledone
The pauses are not superstition. They are windows where metrics can reject a bad version while most users still run the stable one.
Step 01

The ideas this is made of

Rolling update controls capacity, not correctness

A Kubernetes Deployment rolling update limits unavailable and extra Pods. It does not know whether the new version returns wrong answers. It will happily roll out a fast, broken service.

Blue/green makes rollback simple at infrastructure cost

Blue/green keeps two complete versions ready and moves traffic from one to the other. Rollback can be a traffic switch. The price is duplicated capacity and compatibility with shared dependencies.

A canary needs real metrics

Sending five percent of traffic to a new version helps only if something evaluates the result. Error rate, latency and saturation should decide whether the rollout continues. Otherwise it is just a slow rollout.

Feature flags decouple deploy from release

A flag lets code be deployed while behavior remains disabled for most users. That gives finer control. It also creates debt: old flags need owners and removal dates.

Opening one checkout lane
5% shoppers -> new lane
watch: queue time and failed payments
if failures > 2%: close lane
else: 25%, 50%, 100%

The lane exists before every shopper uses it. Release means sending traffic there, and the metric decides whether that traffic grows.

Release strategies compared

StrategyTraffic shapeRollbackCost

Rolling

Pod by Pod

ReplicaSet

Low

Blue/green

All at switch

Switch back

High capacity

Canary

Small to large

Abort early

Needs metrics

Feature flag

Per cohort

Turn off

Code complexity

What these are called on the job

  • Canary — Partial release to a small traffic share before wider rollout.

  • Blue/green — Two complete versions with traffic switched between them.

  • AnalysisTemplate — Argo Rollouts object that defines metric checks for a rollout.

  • Feature flag — Runtime switch that changes behavior without a new deploy.