feat: canary models, adapters, and policies separately with automatic rollback - #34
Merged
Merged
Conversation
… rollback Section 13 canaries models, adapters, and router policies separately, and the design targets require rollback to be automatic once readiness or canary criteria fail. There was one combined plan that listed rollback triggers as text, and nothing acted on them. A staged adapter with the larger measured gain simply took all of the traffic. Each track now has its own plan naming what it rolls back to, and one rule decides them all: failed readiness rolls back at once; error rate, latency, and quality roll back once enough requests have been seen. Error rate and latency only count against a canary when the stable baseline does not share the problem, so an engine outage that degrades both arms is not blamed on the change. The adapter track runs inside the gateway. A staged adapter is offered a fixed share of eligible requests, bucketed by tenant and prompt so a retry cannot flip between adapters, and is suspended the moment it fails. Its responses are never cached, so nothing it produced outlives a rollback. Model and policy canaries are rollouts, so the plan is evaluated through the same rule by a command whose exit code says promote, hold, or roll back. Promotion is never automatic on any track. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Seventh PR closing gaps between the design spec and the implementation.
Gap this closes
§13 "Canary models, adapters and router policies separately" and the design target "Automatic rollback after failed readiness or canary criteria". Previously there was one combined plan whose rollback triggers were four strings, and nothing evaluated them.
Behaviour change
A
stagingadapter used to compete with theproductionone on measured quality delta, so a staged adapter with the larger gain took 100% of traffic. It now takescanary_traffic_percent(default 10). ARouterbuilt without a monitor gives a staged adapter no traffic at all.What changed
canary.py: oneCanaryPlanper canary on its own track (model,adapter,policy), with criteria derived from the catalog: the strictest tier latency objective among the models served, and their benchmarked quality less a tolerance.evaluate(): failed readiness rolls back with no sample; after 50 requests, error rate, p95, or quality over the line rolls back. Error rate and latency are compared with the stable arm, so a shared outage does not roll back an innocent change.GET /v1/registry/canaries, plusrouter_canary_requests_totalandrouter_canary_rollbacks_total.python -m llm_router.canaryprints the plans; with--planand--observationit exits 0/2/3 for promote/hold/rollback. CD now renders all plans instead of one.RoutePolicygainsprevious_version, canary settings, and per-tier latency objectives.serving.canary_configis removed in favour of the per-track plans.Not done
Test plan
ruff format --check .,ruff check .,mypycleanpytest tests/unit tests/integration: 314 passed, coverage 98%🤖 Generated with Claude Code