This project assembles a release path for a ledger API that records invoice adjustments. The deliverable is a reviewable release packet, not a screenshot of a green pipeline. Use a disposable environment and sample records; the exercise should never require production credentials.
Project: release and recover a ledger API
Build the packet
Choose one commit. Run formatting, unit tests, and an integration test against an isolated database. Build an image once, record its full digest, and promote that digest to a staging namespace. Store the commit, test run, image digest, schema revision, and operator name in a release record. Configure readiness separately from liveness and prove that a deliberately unhealthy new Pod receives no normal traffic. Verify the deployment controller reaches its expected available replica count before exposing more users.
service: ledger-api
commit: 6b21d37
artifact: registry.internal/ledger-api@sha256:9a09c4f113a2
schemaRevision: ledger_047
stagingCheck: pending
canaryCheck: pending
rollbackDigest: sha256:4b66e1a2217c
restoreDrill: pendingBreak it on purpose
Inject a predictable server error into one endpoint and send a small, representative traffic slice to the candidate. Set an error-rate stop rule and require enough requests to make the comparison useful. When the rule fires, pause promotion and route traffic to the earlier verified digest. Record how long detection and recovery took. Then restore a sample backup into a fresh environment and verify both a row count and one user-facing read. The packet is complete only when another engineer can repeat the release, rollback, and restore from the recorded steps.
Cost and verification
The canary needs extra capacity, and an isolated restore needs storage and time. Budget both before starting. The shortened digests above are illustrative and must be replaced by full registry digests in a real packet. A code rollback does not undo schema or data changes, so keep the previous reader compatible until the exercise's rollback window ends. Review the packet for leaked credentials and remove temporary resources after preserving the evidence.
Common Mistakes
- Do not rebuild the image between staging and production.
- Do not count missing canary samples as success.
- Do not skip the restore drill after a successful backup job.
