Shipping And Launch

作者 addyosmani1401c8b8030e無授權條款103K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫5 天前更新

Prepares production launches. Use when preparing to deploy to production, or when asking what needs to be in place before shipping. Use when you need a pre-launch checklist, when setting up monitoring, when planning a staged rollout, or when you need a rollback strategy.

僅含說明DevOps & Cloud
AI 產生的概覽

透過上線前檢查清單、分階段發布、監控與回復方案,指導安全的生产環境發布。

功能
此技能提供一套結構化的軟體正式環境發布流程。它提供涵蓋程式碼品質、安全性、效能、無障礙、基礎架構與文件的上市前檢查清單,以及功能旗標策略、附決策門檻的分階段發布順序、監控指引、錯誤預算發布閘門與回復方案範本。產出是檢查清單、發布計畫與回復文件,而非程式碼。
適用情境
適用於準備將功能或重大變更部署到正式環境、需要上市前檢查清單,或需要設定監控、分階段發布與回復策略的情況。也適合資料或基礎架構移轉以及封測或搶先體驗發布。
執行需求
不需要指令碼或工具,僅為說明性內容。依清單執行時假設專案已有測試、版本控制與監控或錯誤回報服務,但技能本身除代理外不需要其他條件。

Shipping and Launch

Overview

Ship with confidence. The goal is not just to deploy — it's to deploy safely, with monitoring in place, a rollback plan ready, and a clear understanding of what success looks like. Every launch should be reversible, observable, and incremental.

When to Use

  • Deploying a feature to production for the first time
  • Releasing a significant change to users
  • Migrating data or infrastructure
  • Opening a beta or early access program
  • Any deployment that carries risk (all of them)

The Pre-Launch Checklist

Code Quality

  • All tests pass (unit, integration, e2e)
  • Build succeeds with no warnings
  • Lint and type checking pass
  • Code reviewed and approved
  • No TODO comments that should be resolved before launch
  • No console.log debugging statements in production code
  • Error handling covers expected failure modes

Security

  • No secrets in code or version control
  • The ecosystem's dependency audit (npm audit, pip-audit, cargo audit, ...) shows no critical or high vulnerabilities
  • Input validation on all user-facing endpoints
  • Authentication and authorization checks in place
  • Security headers configured (CSP, HSTS, etc.)
  • Rate limiting on authentication endpoints
  • CORS configured to specific origins (not wildcard)

Performance

  • Core Web Vitals within "Good" thresholds
  • No N+1 queries in critical paths
  • Images optimized (compression, responsive sizes, lazy loading)
  • Bundle size within budget
  • Database queries have appropriate indexes
  • Caching configured for static assets and repeated queries

Accessibility

  • Keyboard navigation works for all interactive elements
  • Screen reader can convey page content and structure
  • Color contrast meets WCAG 2.1 AA (4.5:1 for text)
  • Focus management correct for modals and dynamic content
  • Error messages are descriptive and associated with form fields
  • No accessibility warnings in axe-core or Lighthouse

Infrastructure

  • Environment variables set in production
  • Database migrations applied (or ready to apply)
  • DNS and SSL configured
  • CDN configured for static assets
  • Logging and error reporting configured
  • Health check endpoint exists and responds

Documentation

  • README updated with any new setup requirements
  • API documentation current
  • ADRs written for any architectural decisions
  • Changelog updated
  • User-facing documentation updated (if applicable)

Feature Flag Strategy

Ship behind feature flags to decouple deployment from release:

typescript
// Feature flag checkconst flags = await getFeatureFlags(userId);
if (flags.taskSharing) {  // New feature: task sharing  return <TaskSharingPanel task={task} />;}
// Default: existing behaviorreturn null;

Feature flag lifecycle:

1. DEPLOY with flag OFF     → Code is in production but inactive2. ENABLE for team/beta     → Internal testing in production environment3. GRADUAL ROLLOUT          → 5% → 25% → 50% → 100% of users4. MONITOR at each stage    → Watch error rates, performance, user feedback5. CLEAN UP                 → Remove flag and dead code path after full rollout

Rules:

  • Every feature flag has an owner and an expiration date
  • Clean up flags within 2 weeks of full rollout
  • Don't nest feature flags (creates exponential combinations)
  • Test both flag states (on and off) in CI

Staged Rollout

The Rollout Sequence

1. DEPLOY to staging   └── Full test suite in staging environment   └── Manual smoke test of critical flows
2. DEPLOY to production (feature flag OFF)   └── Verify deployment succeeded (health check)   └── Check error monitoring (no new errors)
3. ENABLE for team (flag ON for internal users)   └── Team uses the feature in production   └── 24-hour monitoring window
4. CANARY rollout (flag ON for 5% of users)   └── Monitor error rates, latency, user behavior   └── Compare metrics: canary vs. baseline   └── 24-48 hour monitoring window   └── Advance only if all thresholds pass (see table below)
5. GRADUAL increase (25% -> 50% -> 100%)   └── Same monitoring at each step   └── Ability to roll back to previous percentage at any point
6. FULL rollout (flag ON for all users)   └── Monitor for 1 week   └── Clean up feature flag

Rollout Decision Thresholds

Use these thresholds to decide whether to advance, hold, or roll back at each stage:

MetricAdvance (green)Hold and investigate (yellow)Roll back (red)
Error rateWithin 10% of baseline10-100% above baseline>2x baseline
P95 latencyWithin 20% of baseline20-50% above baseline>50% above baseline
Client JS errorsNo new error typesNew errors at <0.1% of sessionsNew errors at >0.1% of sessions
Business metricsNeutral or positiveDecline <5% (may be noise)Decline >5%

When to Roll Back

Roll back immediately if:

  • Error rate increases by more than 2x baseline
  • P95 latency increases by more than 50%
  • User-reported issues spike
  • Data integrity issues detected
  • Security vulnerability discovered

Monitoring and Observability

What to Monitor

Application metrics:├── Error rate (total and by endpoint)├── Response time (p50, p95, p99)├── Request volume├── Active users└── Key business metrics (conversion, engagement)
Infrastructure metrics:├── CPU and memory utilization├── Database connection pool usage├── Disk space├── Network latency└── Queue depth (if applicable)
Client metrics:├── Core Web Vitals (LCP, INP, CLS)├── JavaScript errors├── API error rates from client perspective└── Page load time

Error Reporting

typescript
// Set up error boundary with reportingclass ErrorBoundary extends React.Component {  componentDidCatch(error: Error, info: React.ErrorInfo) {    // Report to error tracking service    reportError(error, {      componentStack: info.componentStack,      userId: getCurrentUser()?.id,      page: window.location.pathname,    });  }
  render() {    if (this.state.hasError) {      return <ErrorFallback onRetry={() => this.setState({ hasError: false })} />;    }    return this.props.children;  }}
// Server-side error reportingapp.use((err: Error, req: Request, res: Response, next: NextFunction) => {  reportError(err, {    method: req.method,    url: req.url,    userId: req.user?.id,  });
  // Don't expose internals to users  res.status(500).json({    error: { code: 'INTERNAL_ERROR', message: 'Something went wrong' },  });});

Post-Launch Verification

In the first hour after launch:

1. Check health endpoint returns 2002. Check error monitoring dashboard (no new error types)3. Check latency dashboard (no regression)4. Test the critical user flow manually5. Verify logs are flowing and readable6. Confirm rollback mechanism works (dry run if possible)

Error Budget Release Gate

Your service's error budget — the fraction of requests or time your SLO allows to fail — determines whether it's safe to ship. Use it as an objective gate — not a negotiation:

Budget remaining > 20%  →  Ship normally; monitor closelyBudget remaining 0–20%  →  Slow rollouts only; no high-risk changesBudget exhausted        →  Freeze feature work; focus entirely on reliabilityBudget resets           →  Resume normal pace; bake in the fix that recovered it

A high burn rate during a canary (consuming budget faster than the baseline pace) is a hold signal in the rollout thresholds table above — treat it the same as an elevated error rate.

Rollback Strategy

Every deployment needs a rollback plan before it happens:

markdown
## Rollback Plan for [Feature/Release]
### Trigger Conditions- Error rate > 2x baseline- P95 latency > [X]ms- User reports of [specific issue]
### Rollback Steps1. Disable feature flag (if applicable)   OR1. Deploy previous version: `git revert <commit> && git push`2. Verify rollback: health check, error monitoring3. Communicate: notify team of rollback
### Database Considerations- Migration [X] has a rollback: <verified command or runbook link>- Data inserted by new feature: [preserved / cleaned up]
### Time to Rollback- Feature flag: < 1 minute- Redeploy previous version: < 5 minutes- Database rollback: < 15 minutes

See Also

  • For the project-wide Definition of Done that every change must clear before this checklist, see ../../references/definition-of-done.md
  • For security pre-launch checks, see ../../references/security-checklist.md
  • For performance pre-launch checklist, see ../../references/performance-checklist.md
  • For accessibility verification before launch, see ../../references/accessibility-checklist.md
  • For the alerting rules and SLO-tied thresholds, see observability-and-instrumentation

Common Rationalizations

RationalizationReality
"It works in staging, it'll work in production"Production has different data, traffic patterns, and edge cases. Monitor after deploy.
"We don't need feature flags for this"Every feature benefits from a kill switch. Even "simple" changes can break things.
"Monitoring is overhead"Not having monitoring means you discover problems from user complaints instead of dashboards.
"We'll add monitoring later"Add it before launch. You can't debug what you can't see.
"Rolling back is admitting failure"Rolling back is responsible engineering. Shipping a broken feature is the failure.
"The error rate looks fine, let's keep shipping"Check the burn rate, not just the current error rate. Consuming budget faster than baseline is a hold signal even when individual thresholds are green.

Red Flags

  • Deploying without a rollback plan
  • No monitoring or error reporting in production
  • Big-bang releases (everything at once, no staging)
  • Feature flags with no expiration or owner
  • No one monitoring the deploy for the first hour
  • Production environment configuration done by memory, not code
  • "It's Friday afternoon, let's ship it"
  • Error budget exhausted but feature work continues unchanged

Verification

Before deploying:

  • Pre-launch checklist completed (all sections green)
  • Feature flag configured (if applicable)
  • Rollback plan documented
  • Monitoring dashboards set up
  • Team notified of deployment

After deploying:

  • Health check returns 200
  • Error rate is normal
  • Latency is normal
  • Critical user flow works
  • Logs are flowing
  • Rollback tested or verified ready

For every shipped service:

  • Error budget policy in place: know what action to take when budget drops below 20% and when it's exhausted

來源與署名

來源:addyosmani/agent-skills位於skills/shipping-and-launch提交1401c8b

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架