Shipping without breaking things.
WHAT TO AUTOMATE
Build Tests Deployment
WHY
Manual deployment is inconsistent and eventually goes wrong under pressure.
WHAT TO DEPLOY
Small changes, frequently.
WHY SMALL
Failures are easier to locate and reverse, and each carries less risk.
WHAT TO AVOID
Large releases containing many changes Deploying on Friday afternoon Deploying without a way back
WHAT A ROLLBACK REQUIRES
The previous version deployable immediately Database changes that do not prevent it
WHY DATABASE CHANGES ARE THE HARD PART
A removed column cannot be restored by redeploying code.
WHAT TO DO
Make schema changes in stages: add, migrate, switch, then remove later.
WHAT FEATURE FLAGS PROVIDE
Deploying code without enabling behaviour, and disabling instantly.
WHAT THEY ALSO ENABLE
Releasing to a subset of customers first.
WHY THAT MATTERS
Problems are found by few rather than all.
WHAT TO MONITOR AFTER EVERY DEPLOYMENT
Error rate Response times The core journey still working
WHAT TO DO ON A SPIKE
Reverse first, investigate afterwards.
WHAT TO MAINTAIN
A record of what was deployed and when.
WHY
It is the first question during any incident.