What a deploy actually does
Build, upload, switch, verify, and the moment where two versions run at once.
A deploy is not one action, it is four, and knowing which one failed tells you what to do about it.
- Build
Turn source into something runnable. Fails here mean nothing changed, so you are safe. - Upload
Move the result to where it will run. - Switch
Point traffic at the new version. This is the risky instant. - Verify
Confirm it actually works with real traffic.
During the switch, both versions are briefly live at once. Someone will load a page from the old version and have their next request served by the new one. This is precisely why the expand-then-contract pattern from the Data track exists: both versions must be able to coexist for a few seconds.
The safest shape is small and frequent. A deploy containing one change has one suspect when something breaks. A deploy containing three weeks of work has forty, and you will be bisecting them at the worst possible time.
What to remember
- Build, upload, switch, verify: failures at each stage mean different things.
- Two versions run simultaneously during the switch.
- Rolling back code does not roll back data or side effects.
Terms in this lesson
Field notes
Loaded from a deliberately slow source. The lesson above was already readable while this was still travelling. That is streaming, and it is the same trick a chat interface uses.
The digest that stopped for five weeks
A weekly email job silently stopped running after an infrastructure change. Nobody noticed, because a job that does not run produces no error. It was discovered when a customer asked whether they had been unsubscribed.
Why you alert on missing success
Everyone retried at once
A service had a brief wobble. Every client retried immediately, then again, then again. The retries were far more traffic than the original load, and the service never got a quiet moment to recover. The outage lasted forty minutes longer than the fault did.
The thundering herd
resolved in 900ms · region iad1
Hide field notes toggles a search param the loader reads. With it off, the slow promise is never created, so nothing streams.