pattern

Feature Flag

also called Feature Toggle

A runtime switch that separates deploying code from releasing behaviour.

flagsreleasedecoupling

The core value is decoupling two events that are usually welded together. Deployment becomes a low-risk technical act; release becomes a business decision, reversible in seconds without a build. That reversibility is the reason flags reduce change failure rate: the remedy for a bad release stops being a redeploy under pressure.

Flags are not one thing, and conflating the kinds is where the mess starts. Release flags are short-lived and must be removed after rollout. Experiment flags live for the duration of a test. Operational flags — kill switches, load-shed levers — are permanent and belong to operations. Permission flags gate entitlements and are really product configuration.

The failure mode is accumulation. Every flag is a branch in the code, and n flags is 2^n theoretical paths, almost none of them tested. Untended flag debt produces genuinely bizarre incidents where a combination nobody imagined becomes reachable. Treat a release flag with an expiry date as non-negotiable, and fail the build on flags older than the limit.

Also: flags in the request path are a dependency. If the evaluation service is down, the default must be safe and local.