Changing what is running.
WHAT A ROLLING UPDATE DOES
Replaces pods gradually, keeping the service available.
WHAT CONTROLS THE PACE
How many may be unavailable, and how many extra may exist.
WHAT TO SET
Values ensuring enough capacity remains.
WHY
Replacing too many at once causes an outage under load.
WHAT MAKES A ROLLING UPDATE SAFE
Readiness probes.
WHY
Without them, traffic reaches pods that are not ready.
WHAT ELSE IT REQUIRES
The application handling shutdown gracefully.
WHAT GRACEFUL SHUTDOWN MEANS
Stopping acceptance of new work, finishing current work, then exiting.
WHAT HAPPENS WITHOUT IT
Requests in flight are dropped on every deployment.
WHAT SIGNAL THE APPLICATION RECEIVES
A termination request, followed by a forced kill after a grace period.
WHAT TO IMPLEMENT
Handling of that signal.
WHAT A ROLLBACK DOES
Returns to the previous version.
WHY IT IS FAST
The previous configuration is retained.
WHAT TO CHECK BEFORE RELYING ON IT
That database changes do not prevent it.
WHY THAT IS THE HARD PART
Code can be reverted; a migrated schema cannot, easily.
WHAT TO DO
Make schema changes in stages, compatible with both versions.
WHAT TO MONITOR DURING ANY ROLLOUT
Error rates and latency.