Canary releases: Safeguards and recovery
Aborts a canary automatically when named error, latency, or saturation metrics breach soak-window thresholds, keeps sticky canary identity, and forbids silent promotion to full traffic.
Rolling deploys follow expand-migrate-contract phases with an explicit mixed-version compatibility window and rollback rules so old and new binaries coexist safely during schema and API changes.