Rollback configuration by selecting a prior immutable snapshot
An operator attempts to repair a bad timeout by manually rewriting the active record, erasing the incident's configuration history.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Recovery · Auditability
Estimated field mix
- Platform engineering70%
- Site reliability30%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional internal reporting platform changes feature and timeout settings through environment edits. Partial rollouts leave API and worker processes interpreting different values.
Setup prerequisites
- Create local API and worker configuration consumers.
- Use fabricated settings without secrets.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- ACONFIG-101 · Inventory runtime settings with owners and restart requirements
- ACONFIG-102 · Reject invalid timeout combinations as one configuration unit
- ACONFIG-103 · Define an immutable configuration snapshot envelope
- ACONFIG-104 · Atomically adopt a validated configuration snapshot in each process
- ACONFIG-105 · Publish configuration only against the revision reviewed by the operator
- ACONFIG-106 · Keep incompatible consumers on their last valid configuration
- ACONFIG-107 · Stage a timeout revision for a named consumer cohort
- ACONFIG-108 · Report configuration staleness separately from application health
Acceptance criteria
- Rollback appends a selection event with reason and actor.
- Validate old snapshot compatibility before selection.
- Retain the bad revision and its adoption record.
Implementation constraints
- Use the same guarded publication boundary as forward changes.
Verification to include
- Select a compatible prior revision and observe consumer adoption.
- Attempt rollback to an incompatible schema and leave the target unchanged.
Deliverables
- Audited rollback command
Rollout and recovery
Rehearse on synthetic consumers; pin a known compatible revision if adoption stalls.
Value of the work
For the engineer: Practice configuration contracts, compatibility and failure recovery.
For the team: Review controlled configuration delivery with inspectable blast radius.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.