Blue/Green & Canary (CKAD)
Two Deployments, one Service, and a label selector that decides who gets the customers.
An interactive Kubernetes lesson: 20 steps, about 30 minutes, on a live simulation in your browser.
Your shop runs version 1.0 as a Deployment, web-blue. Its pods carry two labels: app=web and version=blue. Customers come in through the Service web, whose selector asks for both labels.
Version 2.0 is a rewrite of the checkout. A rolling update would replace pods a few at a time, so for a while customers would land on 1.0 or 2.0 at random, and the first real test of 2.0 would be real customers.
What you will learn
Two versions, one Service
- Blue is live: Blue/green and canary are not Kubernetes features. They are two Deployments and one Service selector.
- Deploy green beside blue: Every label in a selector must match. Green can run at full size next to blue and stay invisible to customers.
- Test green before anyone sees it
The flip
- Flip the selector: A blue/green release is one selector edit. Every customer moves at the same moment and no pod changes.
- Break it: green falls over
- Roll back by flipping again: Blue/green rollback is the same selector edit pointed the other way. It only works while the old Deployment is still up.
- Second attempt, then retire blue
A smaller bet
- A selector on the shared label only: Blue/green: the selector names one version. Canary: the selector names only the label both versions share.
- One canary pod: A Service balances across pods, not across Deployments. The canary's share is its share of the Ready pods.
- The split is a replica ratio: Canary share = canary replicas ÷ total replicas. To change the split you change pod counts.
- Night falls, stable scales down
Promote or abort
- Promote: the canary passed: Promote a canary by rolling its image into the stable Deployment, then scale the canary away.
- Break it: a canary that is Ready and wrong
- Abort: scale the canary to zero: In both patterns the old version stays untouched until the verdict is in. That is what makes backing out cheap.
Limits, and choosing
- What replica ratios cannot do: Replica ratio: the split follows pod counts. Gateway weight: the split is a number you write down, whatever the pod counts are.
- Which one, when: Rolling update: cheap and gradual. Blue/green: instant switch, double cost. Canary: small blast radius, needs someone watching.
At exam speed
- Drill: the blue/green flip
- Drill: set a canary share
Recap & playground
- Cheat sheet
- Playground