Why deploys break, and how we avoid it
Most outages during a release come from the gap between stopping the old version and starting the new one, or from a new version that starts but cannot serve requests. Zero-downtime deploys close that gap: the old version keeps serving until the new one proves it is healthy.
What happens on every deploy
You do not need to configure anything to get safe rollouts. A default health check runs against every web service, and you can point it at your own endpoint for a stricter check.
- New instances start before old ones stop
- Traffic shifts only after health checks pass
- Failed deploys never receive traffic
Rolling back
Every successful build is kept as a rollback target. Rolling back routes traffic to an existing image, so it takes seconds instead of a full rebuild. Database migrations are not reversed automatically, so keep them backward compatible.