Progressive delivery
Rolling, canary, and blue/green — limiting blast radius when the pipeline says go.
Shipping to 100% of traffic in one shot is optional. Seniors default to small blast radius.
Rolling updates
Replace instances gradually behind a service. Needs readiness probes and capacity so removing pods does not drop the service. Good default for many stateless APIs.
Canary
Send a slice of traffic to the new version; compare errors and latency; promote or abort. Needs real metrics and a clear abort condition — not vibes.
Blue/green
Two full environments; switch traffic when green looks healthy. Simple mental model; costs more capacity; watch sticky sessions and schema compatibility.
Feature flags
Decouple deploy from release. Dark-launch code behind flags, then open exposure. Flags need ownership, expiry, and cleanup — eternal flags are technical debt with a UI.
Database and contract changes
Progressive app delivery does not save you from incompatible schema changes. Expand/contract migrations and backward-compatible events still apply. Coordinate pipeline stages with migration order.
Abort criteria
Write them down: error-rate threshold, latency budget, key business KPI. A canary without an abort is a slow full deploy.