Blue-Green Deployment
Two complete production environments where traffic is switched from the old to the new in one step, and back just as fast.
Blue-green buys one property above all: rollback in seconds by flipping traffic back to the environment that is still running and still warm. That is genuinely valuable for changes where you cannot afford a long mean time to recovery.
What it does not buy is safety during the switch. All traffic moves at once, so a defect that only appears under production load hits every user simultaneously. Blue-green limits the duration of exposure, canary limits the blast radius. They answer different questions and are frequently combined.
The hard parts are never the load balancer. They are the shared state: a database both versions must read and write, which forces backward-compatible schema changes anyway; in-flight requests and long-lived connections on the old environment that must drain rather than be cut; caches that are cold on the green side and will produce a latency spike the moment traffic lands; and background jobs or message consumers that are not behind the load balancer at all and need their own cutover plan.
Cost is the honest objection — two full environments, though only briefly if you tear down after the soak window.