Skip to content

Execute production cutover, monitor parity, and retire legacy writes safely #74

Description

@alexeygrigorev

Parent epic: #10

Normative spec: 09 — Production cutover
Decision dependency: #29

Scope

After explicit owner authorization and successful #73, execute final content sync and course DB delta under documented write freeze/outbound-email disable, reconcile all gates, enable new production stack internally, switch canonical DNS/edge while retaining course-host compatibility, enable workers/email once after outbox reconciliation, submit production sitemap, monitor quantitative SEO/application/data/email/security signals, exercise rollback when triggered, and retain legacy systems read-only through approved window before staged retirement.

Non-goals

No scope redesign/SEO experiments, speculative redirects, destructive reverse migrations, immediate legacy DB deletion, duplicate workers/email, or cutover without explicit human approval.

Acceptance criteria

  • [HUMAN] owner authorizes the exact cutover window/runbook/exceptions and named roles.
  • Final snapshots/delta/count/checksum/score/certificate/link/active-commit reconciliation passes before DNS.
  • Internal production smoke proves TLS/health/auth/dynamic writes/noindex removal/production canonicals/sitemap before public switch.
  • DNS/edge switch preserves every classified path; permanent redirects activate only after destination smoke.
  • Exactly one worker/scheduler/email system starts after outbox reconciliation; no duplicate/missed logical messages.
  • Monitoring covers 404/5xx/redirect/canonical/crawl/Search Console/organic entrances, registrations/enrollments, auth, queue/SES, score integrity and triggers rollback quantitatively.
  • Rollback preserves post-cutover dynamic data; legacy artifacts/databases remain recoverable until approved retirement.
  • Legacy course writes and old site are retired only after observation/redirect gates, with recoverability documented.

Test scenarios

  1. Timed dress checklist using final-like snapshots and explicit go/no-go/abort roles.
  2. Production read-only smoke before switch; controlled dynamic registration/enrollment/email after enablement.
  3. Trigger representative rollback after new write and verify no data loss/duplicate email/canonical break.
  4. Monitor crawler/top URL/course API consumers and unknown legacy-host paths through observation window.

Playwright

Desktop/mobile production smoke across representative main/docs/FAQ/Podwiki/course/event/registration/learner/Studio routes before and after DNS; capture screenshots/headers/canonicals. Manual DNS/Search Console/provider checks stay [HUMAN].

Dependencies

Depends on #23, #26, #29, #71, and successful #73 plus explicit owner authorization. This issue must remain open until observation/retention obligations are met.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0Must-have or release-blockingdata-migrationArea: data-migrationhumanCode complete; manual verification requiredoperationsArea: operationsseoArea: seo

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions