Small deploys
A deploy you can describe in one sentence is a deploy you can undo.
Big releases fail in boring ways. Two migrations, a feature flag, a copy change, and a dependency bump land together. When production misbehaves, you cannot tell which one did it, so you roll all of them back and lose the parts that were fine.
Ship the smallest change that is still true:
- A migration ships before the code that needs it, and it only adds. Dropping a column waits until nothing reads it.
- A flag defaults off. Turn it on for one account, then a few, then the rest.
- A dependency bump is its own commit. If the tests only fail there, you know why.
The release note should fit in a sentence. "Distribution reports exclude inactive members." If you need a paragraph of "also", it is more than one deploy.
Rollback is part of the change. If you cannot revert the app without a new migration, the migration was too eager. Forward-only fixes are fine when they are small. They are miserable when they are tangled.