4 ms·
It is indeed insane, but there is some value to leaving coarse feature flags in production. I've seen outages resolved by flipping a feature flag that was accid
by paledot 3y ago
It is indeed insane, but there is some value to leaving coarse feature flags in production. I've seen outages resolved by flipping a feature flag that was accidentally left in production months after deployment, where without it we would've had to resort to more drastic or hackish measures to restore service. (Eg. If one query is overloading the database, you can disable the feature that runs the query and investigate the real problem at your leisure while the database stabilizes.)
That only works in moderation, though - with 13k flags, there's no way the particular combination that you're about to release directly on production has been properly tested.
- borplk 3y agoThis is also known as a "kill switch" which is technically slightly different than feature flags that get used for release safety. You can bake kill switches into many features as a core part of the application for operational reasons. One similar thing I like is having global "maintenance" switches so you can gracefully put an application into maintenance mode.
- paledot 3y agoYeah, fair enough. At some point my ex-employer wised up and implemented kill switches on purpose instead of by accident.