Concept and mechanism
A release involves more than a new image. Code version, environment parameters, the identity used to access dependencies, and routed traffic must remain consistent. In App Service, check which settings follow content and which remain attached to the slot. Managed identities do not move during a swap. In Container Apps, a revision represents an immutable version, but application-level configuration can affect several revisions. A reused registry tag does not necessarily identify the same content at two different times.
Guided application
Before the window, prepare a table of approved artifact, destination database, identity, health criteria, and rollback. Validate connections without generating improper real operations. A direct Container Apps secret change requires handling its use by existing revisions, for example through a controlled restart. When reverting code, confirm compatibility with already-written data. The PM should obtain operational evidence and an explicit proceed-or-defer decision instead of treating a staging test as a universal guarantee.
New code passes in staging, but the production identity cannot read the vault. Correct and validate that authorization before swapping.
Common pitfalls
Using latest as release identity; confusing swap with data restoration; assuming immediate secret propagation.
Related topics: Functions, failures, and safe repetition · Data, concurrency, and history
Deploy a coherent set of code, configuration, and access.
Reference: App Service deployment slots · AZ-204 archived objectives 2026-01-14; retired 2026-07-31