Feature Rollout Lifecycle: merged is not the same as launched

Feature Rollout Lifecycle: merged is not the same as launched A lifecycle diagram generated by Archify. 01 / Exposure phases 02 / Guardrail response 03 / Terminal exits Merged · flag off in production · Exposure phases · shipped, not live 01 Merged flag off in production shipped, not live Internal Only · staff accounts · Exposure phases · dogfood 02 Internal Only staff accounts dogfood Ramping · 1% to 50% · Exposure phases · guardrails watched 03 Ramping 1% to 50% guardrails watched Fully Enabled · 100% of traffic · Exposure phases · soaking 04 Fully Enabled 100% of traffic soaking Flag Removed · one code path · Exposure phases · done 05 Flag Removed one code path done Flag Disabled · exposure back to 0% · Guardrail response · recoverable Flag Disabled exposure back to 0% recoverable Held · guardrail alert · Guardrail response · needs a decision Held guardrail alert needs a decision Abandoned · flag and code removed · Terminal exits · terminal Abandoned flag and code removed terminal Stale Flag · no owner, no decision · Terminal exits · terminal Stale Flag no owner, no decision terminal guardrail trips give up metric regresses nobody removes it Legend start active state waiting decision terminal success failure / exit

Exposure is a separate axis

  • • Merging changes the code; the flag changes who runs it
  • • Each phase widens the blast radius on purpose
  • • The release is finished only when the flag is gone

Guardrails, not vibes

  • • Ramping advances on metrics, not on elapsed time
  • • A held rollout still needs an owner and a decision
  • • Disabling a flag is instant; reverting a deploy is not

The endings nobody plans for

  • • Abandoned is an honest outcome: remove the flag and the dead path
  • • A stale flag is a permanent branch in production code
  • • Every flag you add is a cleanup task you owe