Working on live systems.
WHAT TO ESTABLISH
What will be affected, and for how long.
WHAT TO COMMUNICATE
The window, in advance, to anyone affected.
WHEN TO SCHEDULE
When your users are least active.
HOW TO KNOW WHEN THAT IS
Traffic by hour, from the access logs.
WHAT TO PREPARE
The exact commands, written down A way to verify success A way to revert A persistent session
WHY WRITTEN COMMANDS
Improvising under pressure produces mistakes.
WHAT TO DO FIRST
Take a backup or snapshot.
WHAT TO PREFER OVER RESTART
Reload, where the service supports it.
WHAT TO DO FOR LENGTHY WORK
A maintenance page, so visitors see an explanation rather than an error.
WHAT THAT PAGE SHOULD SAY
That work is in progress, and when it will finish.
WHAT STATUS CODE IT SHOULD RETURN
One indicating temporary unavailability, so search engines do not treat it as permanent.
WHAT TO CHECK BEFORE DECLARING COMPLETION
Every service Every site Logs, for new errors
WHAT TO DO IF IT OVERRUNS
Say so, rather than staying silent.
WHAT TO RECORD AFTERWARDS
What was done, and anything unexpected.