Skip to content

Production MLOps Platform · Jun 2026

ml-canary-deploy: Model Registry and Canary Deployment

Degraded model detected and rolled back in under 60 seconds, no human involved

Source

The problem

A bad model reaches production and nobody notices until users do.

Approach

A custom registry layer over MLflow with full provenance and stage gates running from dev through staging and canary to production. Redis-backed configurable traffic splitting, Prometheus monitoring on accuracy, latency and error rate, automated promotion or rollback against thresholds, Slack alerting and a full audit log. Validated with a deliberately underfit model at 54% against an 85% baseline.

How it works

Key decisions

Automate the rollback, not just the alert
An alert at 2am is still a human in the loop, and the damage happens while they wake up. The threshold evaluation acts by itself and reports afterwards.
Prove it with a deliberately bad model
Validated by deploying a model underfit to 54% against an 85% baseline and watching the system revert in under 60 seconds. A rollback path that has never fired is not a rollback path.
Read the traffic split on every request
It was originally read once at startup, which meant a canary started later would have received zero traffic forever while looking perfectly healthy. Now it is read per request.

Interface

Deployment event timeline showing an automatic rollback
The timeline of a real rollback: two passed health checks, then two critical failures, then rolled_back and auto_rollback_triggered. Timestamps put the whole sequence inside 40 seconds, with no human involved.

Architecture

Canary deployment with automated rollbackIncoming traffic is split between the stable model and a canary. Prometheus monitors accuracy, latency and error rate for both. A threshold evaluation either promotes the canary to stable or rolls it back automatically within 60 seconds.TrafficSplitRedis-backedStable90% trafficCanary10% trafficPrometheusaccuracy · latencyerror ratepromoteroll back<60s, no human

What broke

Running it

docker compose up

Full setup, configuration and API reference are in the repository README.

Stack

Written up in