Identify irreversible edges

A binary can be replaced quickly, but a destructive schema migration, changed message format, or one-way data transform may not reverse. Mark these edges during design and use expand-and-contract changes when old and new versions must overlap.

Configuration belongs to the release model. Record defaults, secret references, feature states, and the expected behavior when a dependency is missing.

  • Backward-compatible schema
  • Message version tolerance
  • Feature kill switch
  • Previous artifact retained

Rehearse from a production-like state

Deploy the candidate, create representative writes, then return to the previous version. Verify that old code can read new data and that queued work is not duplicated or abandoned.

Rollback is one recovery option. If the release changes external state, a forward fix or compensating action may be safer. Name the decision owner before deployment.

Verification checkpoint

Perform the rollback rehearsal after representative writes and confirm data, queues, caches, and clients remain consistent.