Concept and mechanism
A CloudFormation change set previews proposed changes before execution. If it predicts replacing a resource containing data, analyze retention, migration, and recovery. Preview does not guarantee runtime success. For a Lambda application using SAM, versions and aliases support gradually shifting traffic and using configured hooks and alarms to react to problems. Callers must invoke the controlled alias; directly invoking the new version bypasses distribution. Define failure criteria that measure relevant behavior because a function can return technical success while producing an incorrect business outcome.
Guided application
A rollback plan should state what it reverses and what remains. Returning to the previous version does not remove sent messages, external records, or completed data migrations. In a reconciliation service, preserve identities and confirm states before repeating requests with uncertain outcomes. Recovery rehearsals include previous-version compatibility with current state. For APS handover, document alarm signals, criteria for stopping progression, decision ownership, and how to confirm stability. These elements make the release usable by shift teams and support reporting residual risk to the PM without depending on the code author.
A canary fails and the alias returns to the previous version. Confirm service health and reconcile the five requests already sent; rollback success does not establish their outcomes.
Common pitfalls
Alarms unrelated to the objective; invocations bypassing the alias; change sets treated as guarantees; rollback treated as undoing every effect.
Related topics: Diagnosis, capacity, and cost · Events, retries, and idempotency
A controlled deployment must limit exposure and explain state recovery.
Reference: Gradual SAM deployments · DVA-C02; exam guide 2.1