cloud-platform-skills / skills
mchittineni/cloud-platform-skills/.cursor/rules/skills/zero-downtime-release-strategies.mdc
Progressive delivery: Argo Rollouts and Flagger canaries with automated Prometheus analysis, blue-green cutover, Istio traffic shifting, and automatic rollback. Use when releasing to a small percentage of traffic first while watching error rate and latency, when a bad deploy must roll back automatically without a human, or when choosing between canary, blue-green and rolling deployment.
What's in it
- Progressive Delivery & Zero-Downtime Deployment Strategies
- When to Use This Skill
- 1. Automated Canary with Argo Rollouts & Prometheus Analysis
- Automated Metric Analysis Template (AnalysisTemplate)
- 2. Strategy Selection Guide
- 3. Flagger with Istio Traffic Shifting
---
description: "Progressive delivery: Argo Rollouts and Flagger canaries with automated Prometheus analysis, blue-green cutover, Istio traffic shifting, and automatic rollback. Use when releasing to a small percentage of traffic first while watching error rate and latency, when a bad deploy must roll back automatically without a human, or when choosing between canary, blue-green and rolling deployment."
globs:
alwaysApply: false
---
# Progressive Delivery & Zero-Downtime Deployment Strategies
## When to Use This Skill
**Triggers — load this skill when:**
- A release must ship gradually with automated metric-based abort
- Blue-green vs canary vs rolling must be chosen for a specific workload
- A rollout needs rollback automation or traffic-shifting configuration
**Route elsewhere when:**
- Mesh-level routing and mTLS policy -> `api-gateway-service-mesh`
- Continuous delivery plumbing that triggers the rollout -> `gitops-multi-cluster-argo-flux`
- Analysis metric definition -> `sli-slo-error-budget-design`
## 1. Automated Canary with Argo Rollouts & Prometheus Analysis
```yaml
apiVersion: argoproj.io/v1alpha1
kind: Rollout
metadata:
name: order-service
namespace: production
spec:
replicas: 10
strategy:
canary:
analysis:
templates:
- templateName: success-rate-metric
args:
- name: service-name
value: order-service
steps:
- setWeight: 5
- pause: { duration: 5m }
- setWeight: 20
- pause: { duration: 10m }
- setWeight: 50
- pause: { duration: 10m }
```
### Automated Metric Analysis Template (`AnalysisTemplate`)
```yaml
apiVersion: argoproj.io/v1alpha1
kind: AnalysisTemplate
metadata:
name: success-rate-metric
namespace: production
spec:
metrics:
- name: http-success-rate
interval: 1m
successCondition: result[0] >= 0.999
failureLimit: 2
provider:
prometheus:
address: http://prometheus-k8s.monitoring:9090
query: |
sum(rate(http_requests_total{service="order-service",status!~"5.*"}[2m]))
/
sum(rate(http_requests_total{service="order-service"}[2m]))
```
---
## 2. Strategy Selection Guide
- **Blue/Green**: Best for workloads that cannot tolerate version coexistence or require instant atomic rollbacks.
- **Canary with Step Analysis**: Ideal for customer-facing high-throughput microservices where real-user metrics validate regression risk.
- **Shadow/Dark Traffic**: Forward duplicate production read traffic to candidate versions to test performance under true load without user impact.
---
## 3. Flagger with Istio Traffic Shifting
Argo Rollouts owns the workload; Flagger drives the mesh and works well when Istio already
carries the traffic policy:
```yaml
apiVersion: flagger.app/v1beta1
kind: Canary
metadata: { name: checkout, namespace: prod }
spec:
provider: istio
targetRef: { apiVersion: apps/v1, kind: Deployment, name: checkout }
service:
port: 8080
gateways: [istio-system/public-gateway]
hosts: [checkout.example.com]
retries: { attempts: 3, perTryTimeout: 2s }
analysis:
interval: 1m
threshold: 5 # failed checks before rollback
maxWeight: 50
stepWeight: 5 # 5% -> 10% -> ... automatic weighted shift
metrics:
- name: request-success-rate
thresholdRange: { min: 99 }
interval: 1m
- name: request-duration
thresholdRange: { max: 500 }
interval: 1m
webhooks:
- name: load-test
url: http://flagger-loadtester.prod/
metadata: { cmd: "hey -z 1m -q 10 -c 2 http://checkout-canary:8080/" }
```
Flagger generates and owns the Istio `VirtualService`; do not hand-edit it or the next
reconciliation reverts the change. Under the hood both approaches do the same thing — shift a
weight, evaluate metrics over a window, promote or roll back — so choose by which control plane
already owns routing, not by feature lists.
More agent context in mchittineni/cloud-platform-skills
167 other files this repository gives its agents, the first 60 shown.
AGENTS.md
CLAUDE.md
Copilot instructions
Cursor rule
- .cursor/rules/00-index.mdc
- .cursor/rules/skills/ai-agent-security-llm-threats.mdc
- .cursor/rules/skills/api-gateway-service-mesh.mdc
- .cursor/rules/skills/aws-cloud-migration-strategies.mdc
- .cursor/rules/skills/aws-eks-enterprise-patterns.mdc
- .cursor/rules/skills/aws-iam-zero-trust-policies.mdc
- .cursor/rules/skills/azure-aks-enterprise-landing-zones.mdc
- .cursor/rules/skills/azure-cloud-engineering-patterns.mdc
- .cursor/rules/skills/backup-and-disaster-recovery.mdc
- .cursor/rules/skills/chaos-engineering-resilience-testing.mdc
- .cursor/rules/skills/cicd-pipeline-design.mdc
- .cursor/rules/skills/cloud-native-microservices-patterns.mdc
- .cursor/rules/skills/cloud-security-posture-cspm-cis.mdc
- .cursor/rules/skills/configuration-management-ansible.mdc
- .cursor/rules/skills/container-runtime-security-falco.mdc
- .cursor/rules/skills/database-devops-lifecycle.mdc
- .cursor/rules/skills/detection-engineering-threat-hunting.mdc
- .cursor/rules/skills/devops-metrics-dora-kpis.mdc
- .cursor/rules/skills/docker-containerization-basics.mdc
- .cursor/rules/skills/enterprise-iac-governance-terragrunt.mdc
- .cursor/rules/skills/finops-framework-inform-optimize-operate.mdc
- .cursor/rules/skills/gcp-cloud-engineering-patterns.mdc
- .cursor/rules/skills/gcp-gke-autopilot-multi-tenant.mdc
- .cursor/rules/skills/git-branching-merge-strategies.mdc
- .cursor/rules/skills/gitops-multi-cluster-argo-flux.mdc
- .cursor/rules/skills/helm-kubernetes-deployment.mdc
- .cursor/rules/skills/incident-management-and-postmortem.mdc
- .cursor/rules/skills/infrastructure-host-monitoring.mdc
- .cursor/rules/skills/internal-developer-portal-backstage.mdc
- .cursor/rules/skills/linux-sysadmin-troubleshooting.mdc
- .cursor/rules/skills/performance-load-testing.mdc
- .cursor/rules/skills/policy-as-code-opa-kyverno.mdc
- .cursor/rules/skills/prometheus-grafana-otel-tracing.mdc
- .cursor/rules/skills/scalability-high-availability-patterns.mdc
- .cursor/rules/skills/scripting-and-automation.mdc
- .cursor/rules/skills/secops-incident-triage-forensics.mdc
- .cursor/rules/skills/secrets-management-vault-kms.mdc
- .cursor/rules/skills/serverless-event-driven-architecture.mdc
- .cursor/rules/skills/shift-left-security-sast-sca.mdc
- .cursor/rules/skills/sli-slo-error-budget-design.mdc
- .cursor/rules/skills/supply-chain-security-slsa-sigstore.mdc
- .cursor/rules/skills/terraform-iac-modules.mdc
- .cursor/rules/skills/write-a-skill.mdc
Skill
- ai-agent-security-llm-threats.agents/skills/ai-agent-security-llm-threats/SKILL.md
- api-gateway-service-mesh.agents/skills/api-gateway-service-mesh/SKILL.md
- aws-cloud-migration-strategies.agents/skills/aws-cloud-migration-strategies/SKILL.md
- aws-eks-enterprise-patterns.agents/skills/aws-eks-enterprise-patterns/SKILL.md
- aws-iam-zero-trust-policies.agents/skills/aws-iam-zero-trust-policies/SKILL.md
- azure-aks-enterprise-landing-zones.agents/skills/azure-aks-enterprise-landing-zones/SKILL.md
- azure-cloud-engineering-patterns.agents/skills/azure-cloud-engineering-patterns/SKILL.md
- backup-and-disaster-recovery.agents/skills/backup-and-disaster-recovery/SKILL.md
- chaos-engineering-resilience-testing.agents/skills/chaos-engineering-resilience-testing/SKILL.md
- cicd-pipeline-design.agents/skills/cicd-pipeline-design/SKILL.md
- cloud-native-microservices-patterns.agents/skills/cloud-native-microservices-patterns/SKILL.md
- cloud-security-posture-cspm-cis.agents/skills/cloud-security-posture-cspm-cis/SKILL.md
- configuration-management-ansible.agents/skills/configuration-management-ansible/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

