Konrad Kowalski (rootsher)Principal Platform & Reliability Architect010100110010011010010011001110001001110100111011

Canary Deployment: The New Version Gets Part of the Traffic

date
category
CI/CD
also in
Reliability Engineering
reading
1 min / 240 words

Blue-green switches traffic quickly.

But it can still switch everyone at once.

Canary came from a more cautious question:

text
what if the new version receives 1% of traffic first?

The point is not to make deployment slower.

The point is to reduce the blast radius of a bug.

Minimal example

We have two application versions behind two Service objects.

text
api-v1
api-v2

Gateway API can split traffic with weights in HTTPRoute.

yaml
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: api
spec:
  parentRefs:
    - name: public
  hostnames:
    - api.example.com
  rules:
    - backendRefs:
        - name: api-v1
          port: 80
          weight: 99
        - name: api-v2
          port: 80
          weight: 1

The next steps may look like this:

text
99/1
95/5
75/25
50/50
0/100

That is the mechanics.

The strategy starts only when someone checks signals between those steps.

What to measure

Canary without observability is blind.

Minimum:

text
error rate
p95 latency
p99 latency
saturation
restart count
business metric

The business metric depends on the system.

It can be:

text
checkout completed
payment authorized
message sent
document generated

If api-v2 has the same error rate but breaks payments, infrastructure metrics are not enough.

What it is really for

Canary is useful when we want to test a new version on real traffic without risking the whole population immediately.

It works well for:

text
stateless API
backend for frontend
performance changes
new dependencies
integration changes

Canary is weaker when every version must see globally consistent state, or when a bug appears only after several days.

Where the name lies

Canary sounds like automatic safety.

In reality, it is only exposure to a small part of traffic.

If there are no metrics, alerts, and promotion decisions, canary is a slower rolling update.

If a user sometimes reaches v1 and sometimes v2, and the application needs session consistency, canary can create problems that neither version has alone.

Canary answers:

text
does the new version break the system under real traffic?

It does not answer by itself:

text
is the new version better for a specific user group?

That is closer to targeted rollout and A/B testing.