Skip to content

deployment: a rolling deploy, and the rollback that is not always there - #7

Closed
sajonaro wants to merge 1 commit into
agent-guardrailsfrom
deployment
Closed

sajonaro wants to merge 1 commit into
agent-guardrailsfrom
deployment

Conversation

@sajonaro

@sajonaro sajonaro commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Stacked on #6 (base agent-guardrails).

Adds deployment/: three instances rolled from r1 to r2 behind a health gate, then a migration to v2 that r1 cannot read and that cannot be undone. Faults are one at a time, which the README explains.

  • The safe plan exits 1, and that is the finding. It is never dark, and the release can finish, but can-roll-back fails. The witness is the runbook done right in eight steps; it ends at a finished release from which r1 is unreachable for good. The runbook's rollback section stops being true at step 8.
  • one-way from ct.rules, asked with no goal in mind, names exactly one move that cannot be taken back: migrate.
  • The shortcut drops the health gate: target-r2 → replace a → replace b → replace c, and production is dark. It still finishes the release.
  • writ found a race in my first draft. migrate was guarded on "all instances on r2 and healthy", so finishing the rollout, deciding to roll back, and then migrating anyway left the rollback starting r1 on v2. one-way named eleven moves instead of one, and that is how it showed. migrate now also requires target r2. The README tells the story.

Cross-check: 49 → 52 properties (50 compared). ./run-tests.sh all: 301 checks, 0 failed.

🤖 Generated with Claude Code

Three instances rolled r1 -> r2 behind a health gate, then a one-way migration.
The safe plan fails can-roll-back: the runbook done right, eight steps, ends
where r1 is unreachable for good; ct.rules one-way names `migrate` and nothing
else. The shortcut drops the health gate and goes dark in four steps.

Writing it, writ found a race in the first draft: finish the rollout, decide to
roll back, and the migration (guarded on the instances only) runs anyway; the
rollback then starts r1 on v2. migrate now also requires target r2.

Cross-check 49 -> 52 properties (50 compared); 301 checks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sajonaro

sajonaro commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Superseded: reached main through #10.

@sajonaro sajonaro closed this Oct 3, 2026
@sajonaro
sajonaro deleted the deployment branch October 3, 2026 17:52
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant