Release one receipt-quality model to a mixed device fleet, reject an incompatible runtime and reconcile late telemetry before expansion.
Project: stage a receipt-quality model on offline handhelds
Freeze the package and fleet
The new package contains a receipt-quality classifier, image resize rule and policy that sends unreadable images to manual capture. Pin every digest, supported input shape, runtime requirement, minimum app version and previous known-good package. Split handhelds into stable site cohorts and record assigned, downloaded, installed and serving states. The package gate should reject one older handset before activation while leaving its current classifier available.
Exercise installation and offline use
Download to a temporary slot and verify bytes, runtime and smoke input before swapping the active pointer. Disconnect three devices; let them process receipts and queue compact decision events locally. Force one candidate crash loop and confirm its local rollback selects the previous complete package, not just the previous model file. Keep events from both digests with local sequence and observation time. Offline recovery must work without a server round trip.
Reconcile delayed evidence
Reconnect the devices after the nominal rollout checkpoint. Compute serving coverage and failure rate by observation window and device class. The late events reveal a crash on a device class absent from the online sample; hold expansion. Do not rewrite the earlier dashboard as if the events arrived on time. Compare expected sequence ranges with uploaded events to expose queue overflow. Coverage rules distinguish missing events from sampled diagnostic traces.
Publish the release decision
Deliver manifest identities, activation failures, actual exposure count, reporting coverage, crash and rollback events, estimated local queue loss and next cohort decision. Record the device class that remains on the old package and its owner. A successful download is not a successful rollout, and a passing online sample cannot settle risk for devices that have not reported. Link any manual capture load to the receipt service target before widening the cohort.
Implementation
def fleet_expansion(assigned, serving, reported, crashes):
if min(assigned, serving, reported, crashes) < 0:
raise ValueError("negative fleet count")
if serving > assigned or reported > serving or crashes > reported:
raise ValueError("inconsistent fleet count")
if serving == 0 or reported / serving < 0.85:
return "hold:missing-telemetry"
if crashes:
return "hold:crash"
return "expand"
assert fleet_expansion(47, 40, 31, 0) == "hold:missing-telemetry"
assert fleet_expansion(47, 40, 36, 1) == "hold:crash"
assert fleet_expansion(47, 40, 36, 0) == "expand"
Performance and operating cost
The gate is O(1) time and space; maintaining old and new packages costs device storage proportional to both artifact sizes. Real rollout expense includes downloads, battery use, telemetry buffering and support for mixed versions. The sample coverage rule is illustrative and must be set from fleet reporting latency and acceptable release risk.
Common Mistakes
- Swapping active model bytes before verifying the preprocessor and runtime.
- Removing the previous package before the candidate is stable.
- Counting assigned devices as exposed devices.
- Expanding before late offline crash events are reconciled.
Read next
- Edge model releases: pin runtime, preprocessing and cohort
- Offline edge telemetry: late events, coverage and rollback
- Project: run a receipt-model incident drill with honest mitigation
- Project: operate receipt scoring with a deadline and overload path
- Model artifacts: verify digest, origin and loading format
