Build a release path for the case dashboard used by reviewers 47 and 62. A source change updates the package manifest and lockfile together. Continuous integration uses a pinned package manager and a clean install; it fails on a mismatch instead of repairing the graph. A dependency admission record explains new packages, install scripts, publisher changes, browser bytes, and a maintenance owner. The build runs with narrow credentials and emits one immutable artifact set. Its manifest records final asset paths, sizes, digests, and toolchain identity. External browser assets use matching integrity metadata and a visible text fallback if they fail; import-map paths are tied to the same release. The deployment uploads all hashed assets to both regions before switching the HTML pointer. Release 47 assets remain available while release 48 rolls out, because an open release-47 tab may lazy-load a report chunk later. Rollback restores a compatible HTML and API contract without deleting release-48 assets needed by open tabs. A release record links the source revision, resolved graph, manifest digest, and promotion event.
Project: frontend artifact promotion and rollback
Build contract
- Fail release installation when the manifest and lockfile disagree.
- Surface new lifecycle scripts and dependency changes in review.
- Block promotion when a manifest asset is missing in either region.
- Keep both old and new tabs functional across rollout and rollback.
Implementation checkpoint
function canSwitchDocument(manifest, regionalAssets) {
return regionalAssets.every(region => manifest.assets.every(asset => region.has(asset.path)));
}
console.log(canSwitchDocument({ assets: [{ path: '/assets/case-48.js' }, { path: '/assets/report-48.js' }] }, [new Set(['/assets/case-48.js', '/assets/report-48.js']), new Set(['/assets/case-48.js'])]));
// Output: falseCost and boundaries
Clean installation can add network and filesystem work, but avoids unrecorded local state. Archive caching can reduce repeat downloads without treating an installed directory as release evidence. Dependency review has a fixed human cost; concentrate it on graph changes and install-time code. Retaining multiple hashed releases consumes storage, usually far less than broken open sessions. A manifest verification pass is O(number of assets times number of target regions); sample noncritical assets only when the critical path remains fully checked. Measure failed chunk requests, build duration, parse cost, oldest active client version, and rollback time.
Failure drill
Alter the declared parser version but leave the lockfile unchanged; the release job must fail before bundling. Add a package with a new postinstall command and verify the review surfaces it before any privileged build step. Change one byte of an external chart script; the browser must block it and keep its text summary. Delete a lazy chunk from the second region before promotion and require the gate to stop. Then roll back while one release-48 tab stays open and another release-47 tab requests a delayed chunk. Both should keep working inside the supported compatibility window. Record any regional or API mismatch with the manifest digest that produced it.
Acceptance checks
- The source revision maps to one resolved graph and one artifact manifest.
- Final browser bytes match recorded integrity values.
- The HTML pointer changes only after all critical assets exist.
- Rollback keeps supported open tabs and API calls working.
Common Mistakes
- Rebuilding independently in each region.
- Accepting a clean vulnerability scan as approval of install scripts.
- Deleting prior hashed assets when a new document goes live.
Related lessons
Locked Dependency Resolution and Clean Installs; Dependency Admission, Install Scripts, and Provenance; External Asset Integrity and Module Resolution; Artifact Manifest, Rollout, and Rollback Coherence.
