Page 2 of 8~112 min topic

Canary deploy lab

Create the runnable skeleton and contracts

Types and env contracts make **containerized answer API releasing image v2 at 5%→25%→100% weights** fail closed before any provider or cluster call.

~14 min this pageRunnable setup

1Try it yourself

Decision drill

Canary deploy desk

Split traffic, watch metrics, rollback or promote — never big-bang without a safety net.

Release safety72%

1/3You routed 10% of traffic to v2. Smoke looks fine so far.

2Learn the idea

Read

Define trusted borders

Implement types or schemas around POST /answer so illegal states are unrepresentable at the boundary. For containerized answer API releasing image v2 at 5%→25%→100% weights, trusted inputs come from sessions, signatures, pinned digests, or workload identity — not from free-form model text. release commander watching revision-sliced error rate should be able to read the contract and know which fields are optional, which are enumerated, and which abort the request. Constructors and boot paths must not perform provider side effects; injection points keep tests honest.

Read

Environment and secrets contract

Document required env vars in .env.example with placeholders only. Rotation story belongs later, but the contract already forbids printing secrets and forbids defaulting to fail-open when a dependency is missing. Invariant to encode in types/tests: promote only if canary error_rate ≤ baseline+0.5pp and groundedness ≥ baseline−1pp for two 10m windows. If a config number lacks units, fix the name (timeout_ms, rpm_hard) before writing logic.

Read

Implementation artifact

Read

both revisions expose /answer /live /ready and emit revision, request_id, latency_ms, groundedness

Read

Fixture kit

Create fixtures for the golden path and for CANARY-PROMOTE-BLIND-6. Name files after the behavior (429-retry-after.json, cross-tenant.json, empty-citation.json) rather than test1. Each fixture carries expected status/code. This kit is the shared language for validation and failure pages.

Read

Stage depth

Compatibility promise: additive fields may appear only if readers ignore unknowns safely; breaking changes bump a version visible on the wire. For AI payloads, size limits arrive before JSON parse when hostile blobs are a risk. Document how clock skew, idempotency keys, and tracing headers travel through containerized answer API releasing image v2 at 5%→25%→100% weights. If you use feature flags later, the contract already states that flags are not authorization. Link each config knob to a unit and a failure mode (“0 means disabled” vs “0 means divide-by-zero”). A peer reviewing the PR should find CANARY-PROMOTE-BLIND-6 named in a comment on the adversarial fixture.

Read

Field notes for `canary-deploy-lab` / `setup-and-contract`

Generate OpenAPI or a typed client only after the hand schema is stable for one fixture round-trip. Record how errors look on the wire — problem+json, envelope, or bare status — and stick to one. Clock sources must be injectable for skew tests. If webhooks appear later, document signature header names now even as TODOs. Keep sample payloads UTF-8 and free of real emails. Add a makefile or npm script that validates schemas without network. In this chapter the product is containerized answer API releasing image v2 at 5%→25%→100% weights, the human stakeholder is release commander watching revision-sliced error rate, and the incident id you design against is CANARY-PROMOTE-BLIND-6. Re-state the oracle in your notes — 5% canary healthy 20m → promote to 25%; guardrail breach → weight 0 in < 2m — and keep the invariant visible: promote only if canary error_rate ≤ baseline+0.5pp and groundedness ≥ baseline−1pp for two 10m windows. Track canary_weight, error_rate_by_revision, grounded_rate_by_revision as the scoreboard. Surface under change control: POST /answer. If you only have forty minutes, finish the fixture for automation promotes while scrape_up{revision=v2}==0 before polishing UI. Promotion language stays ternary: promote, hold, or roll back based on evidence, not hope.

Go deeper

Before you start

Why this matters

For Canary deploy lab, sketch the request and response shapes that cross POST /answer without naming a framework. Mark which fields are trusted (session, signatures, digests) versus untrusted (user text, model JSON, webhook bodies). If a field can change authorization, it does not belong in model output. Predict one 422/401 you will assert before coding adapters for containerized answer API releasing image v2 at 5%→25%→100% weights.

In the wild

See how this idea shows up as a product and a company — then come back to the lesson. Skills transfer across vendors.

Check your understanding

Page assessment

Answer from memory. Completion is saved from this evidence, not from opening the next page.

1. Can a newcomer list trusted vs untrusted fields?
2. Does boot avoid external side effects?
3. Are fixtures named after CANARY-PROMOTE-BLIND-6-class failures?

All responses are required.