The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Professional · Module 2: Reliability, capacity and resilience

Error Budgets as Delivery Decisions

Error budgets turn the reliability-versus-features argument into arithmetic. Healthy budget ships, exhausted budget freezes and repairs, and every exception is a written decision with a repayment plan.

10 min reading

Objectives

  • Explain how budget health gates releases: green ships, red freezes
  • Read burn rate and decide ship, slow or freeze with the numbers quoted
  • Spend budget deliberately on risky changes and record the spend
  • Refuse the freeze exception without a written reason and a budget plan

Why this matters

A service burns its quarterly budget by February, and releases continue because stopping feels like losing. By April the SLO is fiction and the outages arrive weekly; the team then freezes in panic, which is also a decision made without arithmetic. Both halves of the year shared one missing habit: reading the budget before deciding. Budgets do not slow delivery; unbudgeted failure does, all at once, at the worst time.

Concepts

The policy is a table, agreed before it is needed. Budget above half: ship normally. Budget low but positive: ship carefully, risky changes wait or carry explicit approval. Budget exhausted: freeze features, reliability work only, until the budget recovers. The thresholds are numbers in a document, not moods in a meeting; the L52-adjacent habit from M15 (quoting burn) now gates the release train.

Spend deliberately. A risky migration during healthy budget is a budgeted expense: record the expected burn, watch the actual, stop if it exceeds the plan. This makes risk-taking explicit and bounded instead of sneaky and unlimited. Exceptions follow the same shape: who approved, what burn was accepted, what repayment (reliability work, rollback plan) follows. An exception without repayment is just spending someone else's reliability.

Freezes end by arithmetic too. Recovery work ships (fixes, guardrails, capacity), the budget refills with good operation, and releases resume when the number says so, not when patience runs out. The freeze postmortem records what consumed the budget and which guard would have caught it earlier: the next cycle starts better instrumented.

Worked example

A fictional service enters the quarter healthy, burns half on a migration (planned, recorded), then a bad deploy eats the rest. The learner reads the budget at each point and applies the policy: ship, ship-carefully, freeze. The freeze lifts after two reliability wins refill the budget, with the numbers quoted at every transition.

Common wrong move

Freezing by panic after ignoring the budget for months, then unfreezing by impatience before recovery. Both ends bypass the arithmetic and teach the organization that numbers are decoration. Follow the table, both directions.

Quick check

An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.

Lesson feedback

No published feedback yet.

Log in and complete the lesson to leave feedback.

Exercise

Take a fictional service through a quarter of budget events, apply the policy table at each transition, and quote the numbers behind ship, slow and freeze.

Pass criteria

The record shows budget readings at each event, the policy decision per reading, and the freeze exit with recovery numbers quoted.

Sources

Log in to track progressFree account: stores only your lesson progress and quiz results.