Canary Deployment: The New Version Gets Part of the Traffic
- date
- category
- CI/CD
- also in
- Reliability Engineering
- reading
- 1 min / 240 words
Blue-green switches traffic quickly.
But it can still switch everyone at once.
Canary came from a more cautious question:
what if the new version receives 1% of traffic first?
The point is not to make deployment slower.
The point is to reduce the blast radius of a bug.
Minimal example
We have two application versions behind two Service objects.
api-v1
api-v2
Gateway API can split traffic with weights in HTTPRoute.
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: api
spec:
parentRefs:
- name: public
hostnames:
- api.example.com
rules:
- backendRefs:
- name: api-v1
port: 80
weight: 99
- name: api-v2
port: 80
weight: 1
The next steps may look like this:
99/1
95/5
75/25
50/50
0/100
That is the mechanics.
The strategy starts only when someone checks signals between those steps.
What to measure
Canary without observability is blind.
Minimum:
error rate
p95 latency
p99 latency
saturation
restart count
business metric
The business metric depends on the system.
It can be:
checkout completed
payment authorized
message sent
document generated
If api-v2 has the same error rate but breaks payments, infrastructure metrics are not enough.
What it is really for
Canary is useful when we want to test a new version on real traffic without risking the whole population immediately.
It works well for:
stateless API
backend for frontend
performance changes
new dependencies
integration changes
Canary is weaker when every version must see globally consistent state, or when a bug appears only after several days.
Where the name lies
Canary sounds like automatic safety.
In reality, it is only exposure to a small part of traffic.
If there are no metrics, alerts, and promotion decisions, canary is a slower rolling update.
If a user sometimes reaches v1 and sometimes v2, and the application needs session consistency, canary can create problems that neither version has alone.
Canary answers:
does the new version break the system under real traffic?
It does not answer by itself:
is the new version better for a specific user group?
That is closer to targeted rollout and A/B testing.