Deployment Rollback and State Recovery Design

    1

    Designs automated rollback systems: decision tripwires, state unwinding, traffic drainage, and schema compatibility.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Deployment Rollback and State Recovery Design

    Example session with this skill installed

    Design automated rollback and recovery architecture specifications for our Core Payment Ingress Service.

    • Subject: payment-core v4.2.0 (run-id: payment-rollback-001) operating across 50 Kubernetes pods on AWS EKS fronted by ALBs.
    • Deciders: Lead SRE Architect (Marcus Vance) and Payment Reliability Director (Elena Rostova).
    • Scale: Peak 3,600 payment transactions/sec; max in-flight transaction duration 25s; PostgreSQL Aurora 15 database.
    • Tension: Release team proposed forward-only hotfixes where defective builds stay in production while developers write emergency patches; Elena Rostova and Marcus Vance strictly reject forward-only rollouts in financial paths, citing INC-4911 where an un-reverted memory leak caused a 42-minute blackout costing $180k. They mandate automated 10-second rollback tripwires triggered by error spikes (HTTP 5xx > 0.08% or p99 latency > 180 ms for 2 consecutive 15s checks), automated Helm revision revert (N-1), 30-second in-flight transaction draining, and backward-compatible database schema gates preventing data corruption during rollback.

    Write the rollback architecture specification under docs/.

    • Read your context and instructions
    • Compiled the deployment rollback
    • Generated the UI component

    Wrote docs/architecture/tasks/payment-rollback-001/rollback-design/rollback-architecture-spec.md. Complete automated rollback and state recovery specification establishing 10-second metric tripwires, Helm revision reverts, 30-second transaction draining, and expand/contract database schema safety.

    ---
    skill: rollback-design
    ---
    
    # Rollback Architecture Spec: Core Payment Ingress Service [ROLLBACK-PAY-001]
    
    ## Summary
    
    This specification establishes the automated deployment rollback, decision tripwires, and state unwinding architecture for `payment-core v4.2.0` under run ID `payment-rollback-001`, managing 50 Kubernetes pods across 3,600 peak transactions/second on AWS EKS. It decisively rejects forward-only hotfix policies that caused a 42-minute customer checkout blackout in incident INC-4911 ($180,000 loss). The design enforces automated metric tripwires (triggering when HTTP 5xx errors breach 0.08% or p99 latency exceeds 180 ms for two consecutive 15-second checks), automated sub-10-second Helm revision reverts (`N-1`), a 30-second graceful connection draining window to allow in-flight financial transactions to settle, and strict expand/contract database schema compatibility ensuring the previous binary functions without errors against migrated PostgreSQL 15 tables.
    
    ## Detailed Description
    
    Relying on forward-only patching during high-severity production incidents traps customers in broken software while engineers scramble to write, test, and build emergency commits under pressure. Financial processing engines require automated, deterministic reversion to the known-good previous revision (`N-1`) without human terminal intervention.
    
    

    Incoming Payment Ingress (3,600 TPS)
    │
    ▼
    [ Automated Metric Tripwire Watchdog (Datadog / Prometheus) ]
    ├── Check 1: HTTP 5xx Error Rate > 0.08% (3 errors / 3,600 req)
    └── Check 2: p99 Transaction Latency > 180 ms
    │
    ▼ (Tripped across 2 consecutive 15s windows)
    [ Automated Rollback Controller (Argo / Helm Rollback) ] (sub-10s Execution)
    ├── 1. Trigger Webhook: Executes helm rollback payment-core 81 (N-1)
    ├── 2. Shift ALB Target Weights: Divert 100% new traffic to Stable v4.1.9
    └── 3. Bounded Drain: Retain v4.2.0 pods for 30s to commit in-flight ledgers
    │
    ▼
    [ Aurora PostgreSQL 15 Database ]
    └── Phase 1 Expand Schema: Columns remain dual-compatible with v4.1.9 & v4.2.0

    
    ### Criteria and weights
    
    | Criterion | Why it matters here | Weight | Source of the weight |
    |---|---|---|---|
    | Automated Reversion Speed (< 10s Trigger) | Human triage delays multiply financial revenue loss during payment outages (INC-4911). | 0.40 | Elena Rostova (Payment Reliability) |
    | Transaction In-Flight Safety (< 25s Drain) | Abrupt pod terminations corrupt active payment captures and require manual reconciliation. | 0.25 | Marcus Vance (Lead SRE Architect) |
    | Database Schema Reversion Parity | Rolling back the application binary must not fail due to missing database columns. | 0.20 | Core Database Engineering |
    | Blast Radius Quarantine & Forensic Capture | Defective candidate pods must be cordoned for diagnostic memory dumping rather than wiped blindly. | 0.15 | Information Security & QA Standard |
    
    
    ### Comparison
    
    | Rollback Architecture Candidate | Decision Authority | Execution Speed | In-Flight Transaction Handling | Evaluation |
    |---|---|---|---|---|
    | Option A: Forward-Only Hotfix (Legacy) | Human Incident Commander | 40 to 90 minutes (write & build patch) | Dropped during crash loops | Rejected: Triggered INC-4911 42-minute blackout ($180k loss). |
    | Option B: Manual CLI Rollback (`helm rollback`) | SRE on-call manual execution | 5 to 15 minutes (triage + terminal login) | Abrupt `SIGKILL` | Rejected: Subject to operator panic and SSH token delays. |
    | Option C: Automated Tripwire + Helm Revert (Chosen) | Automated Prometheus watchdog | <= 10.0 seconds | 30-second graceful connection drain | Selected: Zero human delay, zero transaction loss. |
    
    
    ### Result
    
    Option C is selected. Telemetry tripwires trigger automated Helm revision rollbacks, shifting load balancer traffic while draining in-flight payments cleanly.
    
    ---
    
    ### Required Mechanisms
    
    #### 1. Decision Trigger Matrix & Metric Tripwires [MC-TM-01]
    
    | Signal Identifier | Threshold Condition | Evaluation Window | Action Executed | Escalation Channel |
    |---|---|---|---|---|
    | **TRIP-01 (HTTP 5xx)** | HTTP 5xx error rate > 0.08% | 2 consecutive 15s checks | Automated Rollback to N-1 | PagerDuty P1 `#payment-alerts` |
    | **TRIP-02 (Latency p99)** | Authorization latency p99 > 180 ms | 2 consecutive 15s checks | Automated Rollback to N-1 | PagerDuty P1 `#payment-alerts` |
    | **TRIP-03 (Process Panic)** | Container restart count > 5 pods | Instantaneous (10s window) | Automated Rollback to N-1 | PagerDuty P1 `#payment-alerts` |
    
    
    #### 2. Automated Rollback Executor & Traffic Drainage [MC-RE-01]
    - **Execution Seam**: Kubernetes controller / AWS Lambda triggered by Alertmanager webhook:
      ```bash
      helm rollback payment-core 81 --wait --timeout 60s --namespace payments-prod
    
    • Connection Draining Protocol:
      1. Old deployment pods (v4.2.0) receive SIGTERM.
      2. Kubelet removes pod IPs from active EndpointSlices within 1,000 ms.
      3. PreStop hook executes a 5-second pause to allow ALB routing tables to update.
      4. Workload executes a 25-second graceful transaction drain (terminationGracePeriodSeconds = 35).
    3. Database State Unwinding & Schema Safety [MC-DB-01]
    • Backward-Compatible Schema Invariant: Releases must strictly follow the expand/contract database evolution pattern:
      • Phase 1 (Expand): Only additive, non-breaking schema changes (nullable columns, new tables).
      • Both revision N (v4.2.0) and revision N-1 (v4.1.9) must run simultaneously against the same PostgreSQL database schema without error.
    • Rollback Guarantee: Because database DDL changes in Phase 1 are additive, rolling back the application binary from N to N-1 requires zero database schema rollbacks, eliminating destructive table locking.
    4. Post-Rollback Quarantine & Forensic Capture [MC-FC-01]
    • Rather than terminating all failing pods, the rollback controller labels 1 failed pod quarantine=true and detaches it from the Service.
    • Automatically generates a 60-second heap dump and thread dump to an encrypted S3 bucket (s3://bank-forensics/incidents/...) before pod termination.

    Invariants and Contracts

    Zero Forward-Only Deployment Invariant [INV-ROL-01]
      Production payment services must maintain automated rollback readiness throughout every release.
      Forward-only deployment models that disable or omit revision rollback paths are strictly prohibited.
    
    Ten-Second Automated Trigger Ceiling [INV-ROL-02]
      If production error rates breach the 0.08% ceiling across the 30-second observation window,
      the rollback executor must actuate within 10 seconds without requiring human approval.
    
    Expand-Contract Schema Decoupling [INV-ROL-03]
      Application deployments must not require synchronous database schema rollbacks upon binary revert.
      Database schemas must remain fully backward-compatible with revision N-1 for at least 48 hours.
    

    Explicit Unknowns

    • PostgreSQL foreign key constraint check overhead during rapid rollback transaction rerouting (G-1).
    • CloudWatch metric alarm propagation latency variance across secondary AWS regions (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    Peak 3,600 payment transactions/secprovidedTraffic profile intakeCurrent
    Max in-flight transaction duration 25sprovidedWorkload intakeCurrent
    Incident INC-4911 42-minute blackout ($180k)providedPost-mortem evidenceHistorical
    Automated rollback to N-1 (< 10s)decidedElena Rostova (Payment Reliability)2026-09-15
    Error tripwire: HTTP 5xx > 0.08%decidedArchitectural invariant INV-ROL-022026-09-15
    30-second connection draining budgetderived25s max transaction duration + 5s network buffer2026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against rollback architecture standards:

    • Decision Speed: PASS. Automated 10-second tripwire triggers without human intervention.
    • Transaction Safety: PASS. 30-second connection draining protects in-flight payments.
    • Database Safety: PASS. Expand/contract schema decoupling eliminates destructive database rollbacks.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-ROL-01: Elena Rostova to determine whether automated rollback triggers should be suspended during scheduled payment gateway partner maintenance windows (Owner: Elena Rostova).

    Next steps

    1. Marcus Vance configures Datadog webhook alert linked to the automated Helm rollback executor.
    2. Platform team implements the 5-second preStop sleep and 35-second termination grace period in Helm templates.
    3. Conduct staging game day injecting 0.2% synthetic HTTP 500 errors to verify sub-10s automated revision rollback.

    deployment-rollback-and-state-recovery-d.tsx

    TSX · React component

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Define automated breach triggers and metric tripwires.Audit database schema for rollback compatibility.Formulate ordered recovery sequences for service restoration.Draft state reconciliation plans for failed deployments.

    About this skill

    What it does

    This skill maps an accepted change into explicit recovery options, compatible targets, ordered actions, residual effects and verification. It separates restoring service behavior from reverting artifacts, data or external effects without executing rollback.

    Use it when

    Use before or during a deployment-related degradation when an owned rollback/forward-fix decision requires a reproducible, bounded recovery contract.

    For example: “Our patient scheduling API deployment caused a spike in HTTP 500 errors because of a missing environment variable. We had to manually revert Kubernetes deployments while users suffered 25 minutes of downtime. We need an automated rollback specification with concrete threshold triggers and database safety checks.”

    What you get

    • Automated Rollback Spec

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/rollback-design/.

    What it will not do

    Do not use for incident command, backup/DR architecture, blue-green/canary/feature-flag policy, product command generation or generic Git undo.

    How it works

    1. Check deployment rollback is required.
    2. Identify target artifact and revision custody.
    3. Audit database schema and state compatibility.
    4. Establish breach detection and trigger signals.
    5. Formulate ordered rollback execution sequence.
    6. Define residual state and post-rollback reconciliation.
    7. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions