feat: roll back a failed model or policy canary without a person - #44
Merged
Merged
Conversation
Deploy atomically so Helm undoes a release that never becomes ready, and turn a canary rollback verdict into the helm rollback that carries it out. A plan with no recorded target runs nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Closes the spec's design target "automatic rollback after failed readiness or canary criteria" (§16) for the model and policy tracks. Until now their rollback was decided and printed, and nothing acted on it.
How
llm_router.rollout:deployrunshelm upgrade --install --atomic, so a release whose workloads never become ready is restored by Helm itself.evaluatejudges one canary plan with the existing rule and, on a rollback verdict for the model or policy track, runshelm rollbackto the previous release. Exit codes:0promote,2hold,3rolled back,4the rollback command failed.--execute.CD renders the atomic deploy command as an artifact.
Tests
tests/unit/test_rollout.py(16 tests): verdict-to-command for each track; dry run changes nothing;--executeruns the rollback and reports a failed one; a shared outage with a baseline is not blamed on the canary; and a check against the realhelmbinary that every flag used exists.Limits
evaluate; that loop belongs to whatever runs the rollout.helm rollbackrestores the previous Helm release, which is the recorded target only if releases were made in catalog order.🤖 Generated with Claude Code