Status: Recommended guidance. Release controls vary by environment, impact, deployment model, contract, and operational maturity. No release process guarantees uninterrupted service. See DISCLAIMER.md.
Before a consequential release, establish proportionate confidence in:
- approved scope and known limitations;
- build and dependency integrity;
- required automated and manual verification;
- configuration, secrets, migrations, and infrastructure;
- security, privacy, accessibility, and performance risks;
- monitoring, support, and ownership;
- rollout, rollback, and recovery; and
- stakeholder communication.
Use the release checklist and production-readiness template.
Use a versioning model appropriate to consumers. Document material changes, migration steps, deprecations, and known limitations. Semantic versioning is useful for compatible libraries but does not guarantee that every consumer will be unaffected.
Choose based on architecture and risk:
- direct deployment for low-impact reversible changes;
- progressive rollout or feature flags for uncertain behavior;
- blue/green or canary deployment where infrastructure supports it;
- scheduled migration windows for coordinated or irreversible changes; and
- parallel operation when validating replacement systems.
Feature flags need owners and removal dates. Rollback plans must account for data written after deployment.
Observe health signals, user impact, error patterns, cost, and support channels. Define who decides whether to continue, pause, roll back, or mitigate.
Record important learning and follow-up work. A successful deployment is not the same as a successful product outcome.