FREE STUDY NOTES · AZ-400

Blue-green, canary, ring and feature-flag deployments compared

How each release pattern limits risk, what it costs and how traffic or users move to the new version.

From Ultra Transcenders AZ-400 by Tony Rough (coming November 2026)

Every release pattern trades cost and complexity for a smaller blast radius. Microsoft calls the family of techniques progressive exposure or “controlling the blast radius”: a release is shown first to the audience with the highest tolerance for risk and widens only as it proves itself. Figure 9.1 contrasts how traffic moves in blue-green, canary and ring-based deployment.

Blue-green switches all user traffic from the current (blue) copy to the validated new (green) copy, keeping blue for rollback. Canary sends a small share, for example 10%, to the new version and widens it if healthy, while ring-based deployment promotes the new version from internal users to external cohorts to everyone, with a health gate and bake time between rings.
Figure 9.1: How traffic moves to a new version in blue-green, canary and ring-based deployment
Strategy How it works Exposure control Rollback Typical Azure mechanism
Rolling update New instances replace old ones in batches; new instances take traffic as soon as they are ready By instance, not by user; old and new versions serve traffic together Redeploy previous version Kubernetes Deployment default; Azure Pipelines rolling strategy for VMs
Blue-green Full new environment (green) is deployed beside the live one (blue), validated, then traffic switches All or nothing at the switch (can be stepped with weights) Switch traffic back to blue App Service slot swap; Container Apps revisions with labels; Kubernetes service selector
Canary New version goes to a small subset of clients or servers, monitored, then widened Percentage of traffic or pods Route traffic back; reject the canary Container Apps traffic splitting; KubernetesManifest@1 canary; App Service Traffic %
Ring-based (progressive exposure) Several canary-like stages, each a wider user cohort (ring 0 internal users, then external cohorts, then everyone) Ring membership, often one pipeline stage per ring Halt promotion; redeploy previous version to affected rings Multi-stage pipeline with checks between ring stages
Feature flags Code ships dark and is switched on at runtime per user, group or percentage Runtime configuration, down to an individual user Turn the flag off; no redeployment Azure App Configuration feature manager
A/B testing Two or more variants run concurrently with randomised cohorts; results are compared statistically against a goal Allocation per variant Allocate all users to the winning variant App Configuration variant (Experiment) flags; Container Apps traffic splitting
Dark launching New functionality runs in production without users being told, or without being visible, to collect telemetry Hidden; small cohort or shadow execution Disable the dormant feature Feature flags or canary infrastructure

A few distinctions that matter when picking a pattern:

Microsoft’s safe deployment guidance adds two operating principles: allow bake time between tiers (a 24-hour day is generally enough to expose latent bugs, and it should include a peak-usage period), and deploy during working hours, early in the day and week, so the people who can fix problems are available.

Common trap: Treating blue-green and canary as the same thing because both run two versions - blue-green validates the new environment and then switches traffic (typically all at once), whereas canary deliberately sends a small share of real traffic to the new version and widens it gradually based on monitoring.

Get the whole book

This note is one section of Ultra Transcenders AZ-400: Designing and Implementing Microsoft DevOps Solutions, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · AZ-400 terms in the glossary · All AZ-400 study notes

More AZ-400 study notes