Describe the rehearsed state
Start by identifying binary, configuration, schema, consumers, and activation conditions. In a fictional position service, the same binary works in rehearsal, but target configuration activates another consumer. A matching hash establishes file identity without establishing equivalence of that combination. Request evidence for affected paths and record what remains missing. A small matrix can show old and new application versions against prior, expanded, and contracted schemas. Each cell should identify the exercised operation: reading, writing, replaying, or recovering. A green cell based only on a read query does not cover a batch insert. The release manager uses the matrix to coordinate decisions and owners while relying on specialists who understand the data contracts.
Separate expansion and contraction
The lab creates positions with id and amount and adds nullable currency. The old writer explicitly specifies id and amount and still works. A client omitting the column list needs its own test: statement shape may depend on the number of columns. A second table represents only the contracted-state shape, where currency is mandatory without a default; the old write is rejected. This is not a production migration recipe. Before contracting a real schema, confirm writers, readers, infrequent jobs, and existing data. A 21:00 backfill can become stale if an old writer creates new NULLs. Check meaning too: retaining an integer type does not make a switch from whole to minor units compatible.
Connect intent to execution
In the generation exercise, J1 read seven and J2 already advanced to eight. J1’s update with WHERE generation=7 changes zero rows. That result calls for rereading state and revisiting intent. It does not prove J1’s intended version is already installed. SQL protection also ends at the local transaction: a later remote command still needs coordination and verification. If the script ignores zero rows and installs an old package, metadata and environment diverge. Review should identify this boundary, handling of a failed precondition, and how actual version is observed. Deliberate rollback needs a current target and authorization; allowing a stale job to finish accidentally is not a recovery strategy.
Decide using exposure and available time
The fictional canary has six errors in 150 requests: 4%. Control has nine in 9,850, and the total is fifteen in ten thousand: 0.15%. A 2% stop threshold applied to the canary has been breached even though the aggregate looks favorable. If both use the same database, the change can degrade both groups; assess absolute health and the load mechanism before assigning cause. Connect the decision to remaining time. For validated service at 23:00, twenty recovery minutes, fifteen reconciliation minutes, and ten validation minutes require starting by 22:15 in the no-slack model. This arithmetic boundary does not recommend waiting. At 22:25 the rehearsed path lacks ten minutes; communicate the mismatch and supported options while preserving outcome criteria.
UPDATE target
SET generation = 8, version = 'v8'
WHERE id = 'test' AND generation = 7;
-- Check changed-row count and actual state.
-- This protects only this local metadata update, not remote commands.Expanded state: the old explicit-column write passes. Contracted state: the mandatory field rejects that same write. The experiment covers those operations, not every consumer.
Common pitfalls
SQL shape as meaning; backfill as completion; metadata transaction as atomic installation; aggregate errors as canary health.
Related topics: Readiness and gradual exposure · Sequence and dependencies
A release passes through intermediate states; every progression needs applicable evidence and a recovery option that remains executable.
Reference: Safe deployment practices · Google SRE release and canary guidance; GitHub immutable releases and GitLab release evidence and deployment safety; DORA five-metric model; inspected 2026-10-01