A shared composition or controller template translates a higher-level service claim into concrete cloud resources. Its revision is part of the effective infrastructure release identity. Some controllers can follow the newest revision automatically; others allow claims to stay pinned until explicitly moved. Either mode needs a target inventory, rendered or planned diff, compatibility check, health gate, and rollback rule. Reverting a definition may not reverse a provider-side migration, deletion, or data-format change.
Platform API revisions: control changes to managed resources
Operational decision
A managed database claim is used by 34 services. Revision 8 adds backup retention and changes a network rule. List every claim and the revision it currently observes, then partition consumers by environment and failure tolerance. Promote one disposable claim, inspect its resulting managed resources and external provider state, and run a backup-and-restore check. Advance a small production cohort only after both the controller's observed revision and application connectivity agree with the intended change. A consumer with a custom network policy must be reported as a conflict, not silently coerced. During a negative drill, make revision 9 invalid and confirm later claims stay pinned or the rollout controller stops further updates. If automatic update is enabled, control its blast radius through claim selection or revision policy before publishing the new composition. Record which claims remain on revision 8 and why; a global definition version alone does not prove fleet convergence.
Managed database revision rollout
Claim inventory: 34 service IDs and observed revisions
Candidate: revision 9 plus resource diff
Cohorts: disposable, small production, remaining
Gate: provider state, backup restore, app connectivity
Conflict: custom network policy requires owner review
Stop: failed cohort blocks later revisions
Rollback: provider-side effects evaluated separatelyCost and verification
Inventory and status checks scale O(C) for C claims; external reconciliation can be far slower and may be rate-limited by the provider. Smaller cohorts extend rollout time but bound simultaneous change. Measure claims on unsupported revisions, unexpected provider diffs, failed migrations, and time from definition publication to verified consumer adoption. A green controller condition does not substitute for a data restore or application connection check.
Common Mistakes
- Do not change a shared composition without enumerating its consumers.
- Do not assume reverting a definition undoes provider-side changes.
- Do not treat desired revision as proof every claim observed it.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Terraform modules: small interfaces and explicit state owners
- Provider quota preflight: reserve capacity for rollback and recovery
- Backups and disaster recovery: prove the restore path
- Fleet promotion: bound the number of clusters changed at once
