Files
ModelForge/docs/architecture/CANARY_AND_TRAFFIC_SHIFT.md

15 lines
1006 B
Markdown

# Canary and Traffic Shift
M12 canaries are bounded evidence producers, not automatic promotion mechanisms. A successful run
ends in `READY_FOR_PROMOTION_REVIEW`; an operator must explicitly commit the plan.
Request-level canary is valid only for compatible stateless capability contracts and can be scoped
to explicit clients/projects, request count and traffic percentage. Gates include error rate, p95,
capability health, scheduler capacity, critical project failures, external pressure and worker
health. Health, error, latency, critical regression or capacity failure triggers automatic rollback.
Embedding spaces are never percentage-mixed inside an index. A `requires_reindex` plan accepts only
`SHADOW`, `DUAL_READ` or `EVALUATION_ROUTE` semantics against a separate index/space. The current
ExampleRAG alias is outside all M12 rehearsal targets. ExampleVision Vision cannot start a production
canary while owner-photo production validation is deferred; only an isolated LAB rehearsal is valid.