DevOps Professional · Module 3: Migration, restore and disaster recovery
Migration and Cutover: Two Systems, One Truth at a Time
Migrations move the truth from one system to another without losing it on the way. Copy first, run both, verify equality, cut over at a checkpoint, and keep a way back until the new truth proves itself.
10 min reading
Objectives
- Explain the migration arc: copy, dual-run, verify, cut, retire
- Plan a cutover with a checkpoint and a way back before moving traffic
- Rehearse the migration on fixtures before touching anything real
- Retire the old system explicitly instead of letting it linger
Why this matters
A team migrates a database over a weekend with no rehearsal: the copy takes twice as long as guessed, the cutover lands mid-inconsistency, and Monday starts with two systems disagreeing about money. The rollback fails because the old system kept accepting writes after the copy. Every migration disaster shares one shape: the truth lived in two places with no rule saying which one counted, at exactly the moment it mattered. Checkpoints and rehearsals exist so Monday starts with one truth.
Concepts
The arc has five stations. Copy moves data without stopping the old system (snapshots, replication, bulk load). Dual-run operates both systems with writes mirrored or shadowed, so behavior compares live. Verify proves equality: row counts, checksums, sampled reads against both sides until the differences are zero and understood. Cut switches traffic at a declared checkpoint with the old path kept warm. Retire decommissions the old system explicitly, with its data archived, never left running as a silent second truth.
The checkpoint is the contract. It names the moment (traffic percentage, timestamp, transaction ID) after which the new system is authoritative, and the way back that stays valid until confidence holds: reverse replication, retained old system, tested re-cut procedure. A cutover without a way back is a jump, not a migration; jumps belong in no professional plan.
Rehearsal is non-negotiable and fixture-first. The L56 lab rehearses with checkpoints on small data; production rehearsals follow on copies, never on live systems. Each rehearsal measures what the plan guessed: copy duration, lag under load, verification time. The plan's numbers come from rehearsal, not from vendor slides or hope.
Worked example
A fixture store migrates from file to database across the five stations. The learner copies, dual-writes, verifies to zero diff, cuts at a checkpoint with the file path warm, then retires the file after a soak period. The checkpoint document names the moment, the verification quotes equality, and the way back stays tested until retirement.
Common wrong move
Migrating and cutting in one motion with no dual-run. The first comparison of old and new happens after the old is gone, when differences are mysteries instead of fixable gaps. Separate the copy from the cut by verification, always.
Quick check
An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Lesson feedback
No published feedback yet.
Log in and complete the lesson to leave feedback.
Exercise
Migrate a fixture store across copy, dual-run, verify, cut and retire with a written checkpoint, and quote the equality proof and the tested way back.
Pass criteria
The record shows all five stations with evidence, the checkpoint document, the quoted zero-diff verification, and the retirement note.