[{"data":1,"prerenderedAt":368},["ShallowReactive",2],{"navigation":3,"\u002Foperations\u002Fdeploy-rollback":250,"\u002Foperations\u002Fdeploy-rollback-surround":363},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":150,"body":252,"description":356,"extension":357,"links":358,"meta":359,"navigation":360,"path":151,"seo":361,"stem":152,"__hash__":362},"docs\u002F6.operations\u002F3.deploy-rollback.md",{"type":253,"value":254,"toc":346},"minimark",[255,266,271,274,278,306,310,313,317,334,338],[256,257,258],"warning",{},[259,260,261,265],"p",{},[262,263,264],"strong",{},"Procedure specification — not yet operationally validated."," Before pilot use, the operations owner must attach exact console\u002FAPI\u002FCLI actions, environment identifiers, access requirements, escalation contacts, and rehearsal evidence. No platform command names or completed drills are implied here.",[267,268,270],"h2",{"id":269},"preconditions","Preconditions",[259,272,273],{},"The requester, approver, organization, app, and target environment are identified. The exact source revision, artifact digest, runtime contract, policy, capability changes, and migration analysis are recorded. Required human approvals are current. The runtime cluster is healthy, backups are usable, and a prior healthy artifact is identifiable.",[267,275,277],{"id":276},"deploy","Deploy",[279,280,281,285,288,291,294,297,300,303],"ol",{},[282,283,284],"li",{},"Reauthorize the request and revalidate approval against the exact artifact, source, migration set, capability set, and material policy. Stop if any changed after approval.",[282,286,287],{},"Verify the artifact signature and digests through trusted platform services before executing it. Confirm that the cluster supports the pinned contract.",[282,289,290],{},"Confirm the isolated synthetic preview and required tests succeeded. Review application-level authorization as well as gateway access.",[282,292,293],{},"Acquire the environment migration lock. Create and verify the pre-migration snapshot before applying unapplied, checksum-verified migrations.",[282,295,296],{},"Apply migrations and validate schema. On failure, stop activation and assess compatibility with the serving revision. An unchanged route does not reverse database changes.",[282,298,299],{},"Start the verified candidate sandbox and initialize scoped bindings. Run readiness and request smoke checks.",[282,301,302],{},"Atomically change the route only after readiness passes. Drain the previous workload and retain it for the rollback window.",[282,304,305],{},"Verify Entra access, authorized workflow behavior, telemetry, and audit attribution. Record the active deployment and health result.",[267,307,309],{"id":308},"failure-handling","Failure handling",[259,311,312],{},"A failed signature, binding, or health check must prevent route activation. An incompatible migration requires incident handling and a reviewed recovery decision. Do not automatically restore a production database when an artifact fails. Retry orchestration using the existing command\u002Fidempotency identity rather than creating duplicate transitions.",[267,314,316],{"id":315},"artifact-rollback","Artifact rollback",[279,318,319,322,325,328,331],{},[282,320,321],{},"Select a prior healthy deployment by immutable ID\u002Fdigest.",[282,323,324],{},"Confirm that it can operate with the current schema and bindings. Stop for human review if compatibility is unknown.",[282,326,327],{},"Reauthorize rollback and verify the prior signed artifact; start or re-enable its workload.",[282,329,330],{},"Run health checks, switch the route atomically, and drain the failing revision.",[282,332,333],{},"Verify representative user operations and audit the requester, target revision, reason, and outcome.",[267,335,337],{"id":336},"completion-evidence","Completion evidence",[259,339,340,341,345],{},"Capture source and artifact identities, approval record, migration\u002Fsnapshot IDs, readiness result, old\u002Fnew route versions, actor, timestamps, and redacted smoke-test evidence. Database restore is a separate action in the ",[342,343,344],"a",{"href":155},"backup and restore runbook",".",{"title":347,"searchDepth":348,"depth":349,"links":350},"",1,2,[351,352,353,354,355],{"id":269,"depth":349,"text":270},{"id":276,"depth":349,"text":277},{"id":308,"depth":349,"text":309},{"id":315,"depth":349,"text":316},{"id":336,"depth":349,"text":337},"Operator procedure for approved immutable deployments and schema-aware artifact rollback.","md",null,{},true,{"title":150,"description":356},"eJCV8mWJNLvPUsac1L3NSVJDBwInX0O5IBgjiSfSvgQ",[364,366],{"title":146,"path":147,"stem":148,"description":365,"children":-1},"Cluster upgrades, key inventory, disaster recovery inputs, and pilot engineering objectives.",{"title":154,"path":155,"stem":156,"description":367,"children":-1},"Backup checks, isolated database restores, export, and reconstruction of runtime infrastructure.",1790019415368]