Canary Rollout Planner
Plan a canary rollout with traffic percentages, bake time per step and the sample size each step needs to detect a regression, plus automatic rollback thresholds.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
A canary is only useful if it can detect the problem
Sending one percent of traffic to a new version for five minutes sounds cautious and frequently detects nothing. If the service handles ten requests per second, one percent for five minutes is thirty requests, and a regression that affects two percent of requests will probably not appear in that sample at all. The canary then passes, traffic ramps, and the regression arrives at full volume. The step size and bake time have to be derived from the traffic rate and the size of regression you want to catch, not from a set of round numbers.
Bake time must cover the slow failures
Errors appear immediately. Memory leaks, file descriptor exhaustion, connection pool depletion, cache degradation and the effects of a slow background job appear over tens of minutes. A rollout that completes in fifteen minutes cannot catch any of them, which is why a long final step at high traffic percentage, before the old version is removed, is worth more than several short early steps.
Rollback has to be automatic to be fast
Every rollout plan says it will roll back if metrics degrade. The ones that actually work define the metric, the threshold and the comparison window in advance and wire them to an automated action. A human watching a dashboard is slower than the outage, and during an incident is exactly when judgement is worst. The threshold should compare the canary against the baseline running at the same moment rather than against a historical value, since that controls for load and time of day.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
How long should each canary step last?
Long enough to accumulate a statistically meaningful sample at that traffic percentage, and long enough for slow failures to appear. The calculator derives the first from your traffic rate and the regression size you want to detect; for the second, at least one step should run for 30 minutes or more.
What percentages should the steps use?
Something like 1, 5, 25, 50 and 100 is common, but the right first step is whatever gives a usable sample in a reasonable time. On a low traffic service, 1 percent may need hours to produce enough requests, in which case start higher and accept the larger blast radius.
What metrics should gate the rollout?
Error rate and latency at minimum, compared against the baseline version running at the same time rather than against a historical value. Comparing to the concurrent baseline controls for load, time of day and any external factor affecting both.
How do I roll back a database migration?
You mostly cannot, which is why schema changes should be backwards compatible and deployed separately from the code that uses them. Add a column, deploy code that writes both old and new, backfill, deploy code that reads the new one, and only then remove the old. Each step is independently reversible.
Is a canary better than blue-green?
They answer different questions. Blue-green switches all traffic at once and rolls back by switching back, which is fast but has no gradual exposure. A canary limits blast radius during the rollout but takes longer and needs traffic splitting. Canary is generally better for user facing services with meaningful traffic.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter your traffic volume and error budget to get a canary schedule with statistically meaningful steps.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.