Pilot Ring Exit Criteria and Rollback Plan

This template defines proposed evidence gates for moving managed KMP from internal rehearsal to a small tenant pilot. It does not prove that an SLO, penetration test, restore, WORM control, or recovery drill has passed. Adopt thresholds only after the named owners approve how they are measured.

← Deployment and operations | Pilot migration | Go/no-go template

Implementation facts behind the gates

A gate depending on an external control must be not implemented until separate evidence exists.

Evidence gates before a real tenant

Gate Required evidence Proposed threshold
Image/release POC evidence, release tag/commit, immutable digest, production import result Production digest exactly matches POC-validated digest
Tenant isolation Two known tenant hosts plus unknown-host and cross-tenant ID/API/storage tests No misrouting or cross-tenant access
Migrations Exact managed application/platform/secret/key/tenant-fleet chain; suspended tenants included No failed/pending tenant and no skipped required stage
Platform Admin Allowed/disallowed hosts, password/TOTP, lockout/status, session host binding, privileged mutation auth/audit No tenant-host access or session/policy bypass
Worker/jobs Three-minute trigger, bounded args, one scheduling authority, queue/job error handling No duplicate authority or unowned P1/P2
Backups Fresh platform and affected-tenant artifacts, hashes, retention metadata, separate key custody Both scopes available and decrypt/restore plan approved
Restore Actual isolated platform pg_restore and tenant restore evidence, plus current non-destructive plans At least one measured end-to-end rehearsal before a real pilot
Audit Database hash-chain verification No unexplained chain discontinuity
External WORM Immutable storage/retention/continuity evidence, only if required or advertised Verified externally; application config alone never passes
Security/accessibility Penetration-test/finding status, regression checks, WCAG 2.2 AA evidence for changed UI Critical closed; other risks owned/approved
Legal/customer Residency, retention, DPA, support, window, rollback, communications Counsel and customer approvals recorded
Recovery Single-region risk acceptance and DR tabletop/rehearsal evidence No implied multi-region guarantee; actual RTO/RPO recorded

Ring 0 — internal rehearsal

Use only synthetic, scrubbed, or explicitly approved non-production data.

Entry:

Exit:

Ring 1 — first real tenant

Limit Ring 1 to one approved low-risk tenant with a named customer contact and rollback deadline.

Entry:

Proposed progression evidence:

Ring 2 — expanded pilot

Add one tenant at a time unless a written risk decision permits a batch. A candidate cohort is three to five tenants with varied size/workflows.

Entry:

Proposed GA evidence:

Candidate SLIs/SLOs

These are planning values, not instrumented guarantees. The owner must name the query/dashboard, sample population, exclusions, alert, and evidence location. Missing telemetry is a failed measurement.

Area Candidate measure Candidate pilot target / stop threshold
Login Successful interactive logins / attempts, per tenant 99.9% rolling 7 days; investigate tenant cluster; page on severe spike
Tenant routing Known-host successful resolution and cross-tenant mismatch 99.99% rolling 7 days; any mismatch is immediate stop
Migration Duration/failure by rehearsal and live tenant p95 inside approved window; no unresolved live failure
Worker Expected versus completed three-minute cycles; queue/job backlog No prolonged missing cycles, duplicate claims, or unowned failure
Tenant backup Latest completed backup age versus configured daily/weekly policy Warn after one cadence; critical after three cadence windows
Platform backup Latest explicit completed platform backup and usable key Threshold set by recovery policy; stale/missing blocks cutover
Restore Last actual isolated restore plus non-destructive plan freshness Actual rehearsal before Ring 1 and after material format/process change
Alert handling P1 acknowledgement/mitigation and P2 ownership Candidate P1 ack <15m, mitigation <4h; P2 owner <1 business day
Database audit Hash-chain continuity Any unexplained break is stop/security review
External WORM Sink acceptance plus storage retention/lock state Only when deployed; any required-control gap is stop

Migration rehearsal requirements

Follow the pilot migration runbook. At minimum:

  1. approve and checksum the source export and document inventory;
  2. provision/resolve an isolated target without customer traffic;
  3. run the exact target migration/import sequence;
  4. validate counts, relationships, documents, hosts/TLS, login, authorization, queues, and database audit;
  5. create an encrypted post-import tenant backup and recovery-key reference;
  6. run a non-destructive restore plan and an approved isolated real restore;
  7. time rollback and document reconciliation; and
  8. obtain customer/business validation.

Live rollback model

Before cutover, keep the source available and record its write state, final backup/export, DNS target/TTL, and rollback deadline.

Scenario Action
Failure before traffic cutover Keep users on source; quarantine target; preserve evidence
Failure after cutover, no target writes Return traffic to verified source
Failure after target writes Freeze both sides; data owner selects reconciliation or source/target recovery
Corruption/isolation/auth failure Disable affected traffic, preserve forensics, page Platform/Security, pause onboarding
Region outage Follow region failover planning; do not imply a standby exists

An image rollback does not reverse schema/data. A tenant logical backup does not restore documents, platform metadata, or source-system changes.

Immediate pause/rollback triggers

Decision and evidence package

Required approvers are Platform Owner, Migration/Database Lead, Operations/Incident Lead, Security/Audit Lead, and the pilot customer representative; include Counsel/Data Protection where commitments or residency are involved.

Store links—not secrets or raw customer data—to: