Canary releases: Safeguards and recovery
Aborts a canary automatically when named error, latency, or saturation metrics breach soak-window thresholds, keeps sticky canary identity, and forbids silent promotion to full traffic.
Defines typed feature flags with default-safe values, audited tenant and user targeting, an always-reachable kill-switch, and a cleanup date after which the flag must be removed.