Skip to main content
CodeOath
← All posts

CI/CD & DevOps65 min total · 17 parts

CI/CD Pipelines Explained: From Push to Production

Part 14 of 17 · ~1 min

Feature Flags: Decoupling Deploy from Release

worker gaining the ability to auto-categorize a receipt by vendor — restaurant, office supplies, travel — is the first feature the team deliberately ships dark:

if (flags.isEnabled("auto-categorize", { accountId: account.id })) {
  return categorizeAutomatically(receipt);
}
return leaveUncategorized(receipt);

The code goes out with a normal deploy, running in production, doing nothing for anyone, because the flag starts at zero percent. Turning it on for real is a config change to the flag service, not a new deploy — first for the team's own test account, then for five percent of real accounts, watched for a day to see whether the categorization is actually any good before anyone decides whether to widen it.

The moment that actually pays for the whole mechanism comes a few days later, when the auto-categorization turns out to mislabel a whole class of gas-station receipts as "travel" instead of "fuel." Nobody reaches for a rollback. Somebody flips the flag back toward zero, and the bad behavior is gone in the time it takes the flag service to propagate — nothing rebuilt, nothing redeployed, no pipeline even involved. Deploying the code and releasing the feature turn out to be two separate decisions, made by two different mechanisms, and only one of them requires touching the pipeline at all.