Building Software

Engineering Fundamentals for the Agent Era

Contents Section 7, Operations

Shipping Change Safely

Mistakes to catch in review

  1. A migration that locks a large table, or drops a column the running version still reads.

  2. A large agent-generated change that mixes refactoring with behavior changes, so nobody can review it properly.

  3. A deployment with no rollback path, or a rollback that can't undo the data migration that shipped with it.

  4. A configuration change applied by hand in production and lost on the next deploy.

Version control, deployment pipelines, migrations, feature flags and rollback: the machinery for changing a live system many times a day.

Topics

Version Control Discipline
Small commits, readable history, branches and reverts as the record of why the code changed and the way to undo it.
Deployment Strategies
Blue-green, canary and progressive rollouts that limit how many users see a bad change.
Feature Flags
Separating deploying code from releasing features, and removing flags before they become permanent branches.
Expand-and-Contract Migrations
Changing schemas in steps that keep old and new code working at the same time.
Rollback and Roll-Forward
Knowing in advance how to undo each change, and when fixing forward is the safer move.
Infrastructure and Configuration as Code
Keeping environments and settings in version control so they are reviewed, repeatable and recoverable.

You understand it when you can

  • Plan a column rename as a sequence of backward-compatible deployments.
  • Roll back a bad release and explain which state (data, flags, caches) the rollback did not undo.
  • Split a large change into small commits that can each be reviewed on their own.

Drill

An agent wrote one migration that renames the email column to email_address and deployed it in the same release as the code that reads the new name. Find what breaks for requests served by old instances during the rollout and what a rollback leaves behind, then rewrite it as expand-and-contract steps.

Start here

Watch

Jez Humble – Continuous Delivery

Jez Humble, 2013. 47-minute talk.

The co-author of Continuous Delivery explains the deployment pipeline, small batches, and separating deployment from release, the reasoning every rollout strategy builds on.

Read

Continuous Deployment: Enable Faster Feedback, Safer Releases, and More Reliable Software

Valentina Servile, 2024.

A current, hands-on treatment of shipping to production on every commit, with feature flags, dark launches, expand-and-contract changes and small incremental commits.

Infrastructure as Code: Designing and Delivering Dynamic Systems for the Cloud Age

Kief Morris, 2025, 3rd edition.

Explains why environments and configuration belong in version control and pipelines, and how to test and roll out infrastructure changes instead of editing production by hand.

Refactoring Databases: Evolutionary Database Design

Scott W. Ambler and Pramodkumar J. Sadalage, 2006.

The classic catalog of schema refactorings, each done with a transition period in which old and new schemas coexist, which is where expand-and-contract migrations come from.

Primary sources

  • Reference

    ParallelChange (Martin Fowler's bliki)

    Defines the expand, migrate, contract sequence for making a backward-incompatible change safely, with worked steps that apply directly to a column rename.

  • Manual

    PostgreSQL Documentation: ALTER TABLE

    Documents which ALTER TABLE forms take an ACCESS EXCLUSIVE lock or rewrite the table, the facts you check before a migration blocks production traffic.