Project challenges / verified progress
Beacon: ship it without fear

The engineering notebook

Recover without guessing

What should happen when a release goes wrong?

Loading statusStage 8 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Release and recover

Step 01 of 06

Learn the concept

Rollback is a tempting word because it sounds like time travel. It is not. Sometimes the safest repair is rolling forward, especially after a database migration changed the ground under the old code.

TWO RECOVERY PATHSDecisionone input splitsRoll backold artifact worksminutesRoll forwardstate changedfix aheadFreezestop normal flowaudit
Bad releases split into recovery paths. Compatibility decides whether old code is safe, forward repair is safer, or a freeze is needed while humans regain facts.
Step 01

The ideas this is made of

Rollback is fast only when compatibility was preserved

If version N+1 changed only application code, returning to version N may restore service quickly. If it migrated a database column or emitted new queue messages, version N may not understand the world anymore.

Expand/contract keeps both versions alive

First expand the schema so old and new code both work. Then deploy code that reads the new shape. Only after old code is gone do you contract. It feels slower and prevents louder nights.

A freeze is not panic tape

A deployment freeze stops routine releases during high-risk periods or incidents. It should name scope, approvers, expiry and the break-glass path. 'Nobody deploys until further notice' is not a policy.

Time to restore measures the whole loop

The timer starts when the service is impaired and ends when users are healthy again. It includes detection, decision, rollback or forward fix, verification and communication.

Moving a library catalog
bad change: new shelf IDs
old map: points to empty shelves
forward fix: update signs and catalog
freeze: stop moves until counts match

Once the shelves moved, yesterday's map may be dangerous. Software state has the same memory, especially databases.

Roll forward or roll back

ConditionRoll backRoll forward

State unchanged

Usually best

Possible

DB schema changed

Risky

Often best

Bad config

Revert commit

Fix commit

Security hotfix

Maybe unsafe

Usually forward

What these are called on the job

  • Time to restore — Elapsed time from user-impacting failure to verified recovery.

  • Break-glass — Emergency path that bypasses normal gates with narrow scope and audit.

  • Freeze — Temporary restriction on routine changes during risk or incidents.

  • Expand/contract — Migration pattern that keeps old and new code compatible across rollout.