← Change management: production decisions
09 / 12 · 70 MIN

Published configuration and active process

Distinguish validation, disk selection and loaded configuration using local processes and actual files.

Three states the plan must distinguish

The lab creates versions in a temporary directory and starts actual Python processes. Each worker reads configuration once and receives requests through pipes. Version v1 calculates ten times one plus two, returning 12. Switching the current pointer to v2 changes disk selection, but the old process retains v1. A new instance reads v2 configuration and returns 22. Record artifact presence, current selection and loaded configuration separately. This distinction helps during a middleware change where copying a file does not imply reload. WebSphere, service-manager or other product behavior must be confirmed for the relevant version; the teaching worker does not define those contracts.

Validate the document and reviewed bundle

Preflight runs the worker with a validation option. Incomplete JSON is rejected with code 2; a readable document whose fee is text is rejected with code 3. These codes belong to the script and are not operational standards. In another step, adding a newline preserves document validity but changes its hash. The fictional rule compares code and configuration hashes and the target, preventing that promotion until content is reconciled. Document validity is not byte identity, and neither check authenticates the approver. For the change request, retain the assessed bundle and explain any drift before using evidence produced for different content.

Local replacement and atomicity boundaries

The script creates a temporary symlink and replaces current using os.replace on the same filesystem. It then resolves selection once to start code and configuration from the same directory. The local operation does not update already-running process memory, route traffic or coordinate multiple nodes. It also does not make selected-directory files immutable. If another actor can modify them between checking and use, a condition exists that this sequential script does not protect. In a real plan, identify who can modify artifacts, how concurrency is controlled and how mixed states are observed. The exercise includes no power failure and cannot establish crash durability from a successful replacement.

Observe failed startup without losing previous state

In a negative test, the script deliberately bypasses preflight and selects invalid configuration. The new process ends with code 2 while an existing v1 instance still returns 12. This is mixed state: new disk selection, failed startup and still-functional earlier execution. Before repeating commands, identify these facts and apply recovery conditions. Ending the healthy instance without a confirmed replacement can increase impact. The lab controls its five child processes and awaits all their termination before removing the temporary directory. It stops no existing services. A real change plan must address in-flight work, access, capacity and accountability for deciding whether to retain or retire each instance.

python3 content/labs/change-runtime/run.py --output /tmp/dr-change-runtime.json
# Compare pointerDoesNotReloadProcess and newProcessLoadsCandidate.
# The worker reads configuration once at startup; no implicit reload.
IN PRACTICE

current changes to v2; the old process still returns v1 and 12, while a new instance returns v2 and 22.

Common pitfalls

Treating an exit code as completed deployment, using version names as identity or assuming automatic reload after changing files.

Related topics: Identity and authorization · Recovery and handover

Take this idea with you

Effective state depends on the process loading contract; validate files and instance behavior separately.

Create account

Reference: Release Engineering · BigSavant Change Management 2026.1; independent technical curriculum