FDE Foundations · Module 9: Production
Rollout and Rollback Plans
Every customer deploy needs a written plan: what ships, how it ramps, what aborts it, and how you back out. The rollback you have not tested is a wish, not a plan.
11 min reading
Objectives
- Choose rollout strategies that fit the customer's risk
- Make rollback a tested procedure, not an intention
- Define the go/no-go criteria before the deploy
Strategies
| Strategy | Fit | Cost |
|---|---|---|
| Direct deploy | Low-risk internal tools, easy rollback | Brief downtime |
| Blue-green | Fast rollback, parity hardware | Double capacity during switch |
| Canary | High-risk changes, observable traffic | Routing complexity |
| Feature flag | Decoupling deploy from release | Flag debt to manage |
Pick by the customer's tolerance and infrastructure, not by preference. A hospital batch system at 2 a.m. is a direct deploy with a tested rollback; a customer-facing API is a canary.
Rollback is a procedure
Write it as steps someone can run under stress: command or click sequence, expected duration, data implications (does the old version read the new schema?), and who verifies what afterward. Test it in staging on every significant release. Migrations deserve special care: backward-compatible changes (expand, migrate, contract) let old and new versions coexist, which is what makes rollback possible at all.
Go/no-go
Before the deploy, write the criteria: health checks green for N minutes, error rate below threshold, the key business metric not regressing. Abort thresholds decided in advance remove the judgment call from the worst moment.
Quick check
An optional 2-3 question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Exercise
Write the rollout plan for a fictional pricing-service deploy: strategy choice with reason, five go/no-go criteria, and the rollback steps including the migration consideration.
Pass criteria
Strategy justified by customer risk, criteria numeric and checkable, rollback steps concrete with duration, and migration compatibility addressed.