Control Packs · CHG-002 · v1.0.0
Deployment Rollback and Recovery
Define how a production deployment detects failure, stops safely, rolls back, and reconciles state.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Make deployment failure states explicit through health checks, bounded rollout, rollback, reconciliation, and operator-visible escalation.
- Deployment failure leaves production in an unknown stateA change partially applies across services or dependencies without a tested rollback, reconciliation, or operator handoff.
Versioned applicability rule
{
"all": [
{
"characteristic": "PRODUCTION_MODIFICATION",
"equals": true
},
{
"characteristic": "EXTERNAL_DEPENDENCY",
"equals": true
}
]
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- What is the recovery path when a production deployment partially applies?Rollback, forward fix, and operator hold have different safety and data consequences.CHG-002-Q1 · choice
Requirements for the coding agent
- CHG-002-R1Use pre-deployment checks, staged rollout, health-based stop conditions, tested rollback or forward recovery, and reconciliation for dependent state.
Tests and evidence to retain
- DEPLOYMENT_ROLLBACK_TESTExercise preflight failure, staged failure, dependency outage, rollback, forward recovery, and reconciliation.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- CM-3 · Configuration Change ControlNIST_SP_800_53_5_2_0 · partially addressesStaged rollout and health-based stop conditions support controlled change; they do not cover complete configuration governance.
- CP-10 · System RecoveryNIST_SP_800_53_5_2_0 · partially addressesRollback, forward recovery, and reconciliation address a defined deployment-recovery scenario; they do not cover all contingencies.
- IR-4 · Incident HandlingNIST_SP_800_53_5_2_0 · informsDeployment failure handling informs incident response coordination; it is not an incident-handling program.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- Amazon Web Services Builders' Library — Timeouts, retries, and backoff with jitterGUIDANCE_RELIABILITY
- Internet Engineering Task Force — HTTP SemanticsRESEARCH_IDEMPOTENCY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0