Canary releases: Safeguards and recovery
Aborts a canary automatically when named error, latency, or saturation metrics breach soak-window thresholds, keeps sticky canary identity, and forbids silent promotion to full traffic.
Defines one user-journey SLO with burn-rate alerts, a feature-freeze when the error budget is exhausted, and exclusion of documented maintenance from the burn calculation.