⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All CI/CD & GitOps Interview Questions Scenario 152 of 176 in CI/CD & GitOps
Senior DevOps / SRE CI/CD Kubernetes Ingress & Traffic Management Traffic Management

Q: Your company wants automated canary deployments and blue-green testing in Kubernetes, but leadership forbids deploying a heavyweight service mesh (Istio/Linkerd) due to CPU overhead. How do you design and execute a progressive canary rollout using native Ingress-Nginx annotations (canary-weight, canary-by-header, canary-by-cookie)?

Engineering a zero-downtime canary deployment pipeline using native Ingress-Nginx canary annotations, weight-based traffic splitting, and header/cookie matching with zero service mesh dependencies.

#CI/CD #Ingress-Nginx #Canary #Blue-Green #Kubernetes #Traffic Routing
🎙️ Candidate Opening & Architectural Context
"Service meshes introduce substantial sidecar CPU and latency overhead. We engineered a lightweight, zero-service-mesh progressive canary release pipeline utilizing native Ingress-Nginx canary annotations and automated CI/CD traffic controllers."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Deploy Dual Stable (Blue) and Canary (Green) Workloads

Maintain two parallel production workloads in the same namespace:

  • Primary Deployment: Deployed payment-stable (v1.0.0) with Service payment-stable-svc.
  • Canary Deployment: Deployed payment-canary (v1.1.0) with Service payment-canary-svc.
  • Primary Ingress: Configured standard Ingress pointing to payment-stable-svc for host api.example.com.
Pro Tip: Maintaining separate Deployments and Services for stable and canary versions allows independent scaling and zero-downtime teardown.
2️⃣

Enable Header-Based Canary Testing for Internal QA

Route internal testing requests to the canary without exposing public traffic:

  • Canary Ingress Manifest: Created secondary Ingress with identical host api.example.com pointing to payment-canary-svc.
  • Header Annotations: Added annotations: nginx.ingress.kubernetes.io/canary: 'true' and nginx.ingress.kubernetes.io/canary-by-header: 'X-Canary' with canary-by-header-value: 'always'.
  • Verification: Requests with header X-Canary: always route to Green; all other public traffic routes strictly to Blue.
Pro Tip: Header matching allows QA teams and automated smoke tests to validate production canary pods with zero public exposure.
Advertisement
3️⃣

Execute Progressive Weight-Based Traffic Shifting (10% -> 50% -> 100%)

Gradually shift public customer traffic while monitoring error rates:

  • Weight Annotation: Updated canary Ingress annotation: nginx.ingress.kubernetes.io/canary-weight: '10' (routes 10% of randomized requests to canary).
  • Progressive Ramp: CI/CD pipeline steps through 10% -> 25% -> 50% over 15 minutes while polling Prometheus for HTTP 5xx error spikes.
Pro Tip: Nginx evaluates canary-weight using client IP hashing, ensuring smooth statistical request distribution across backend services.
4️⃣

Promote Canary to Stable & Clean Up Secondary Resources

Complete the release lifecycle and reclaim compute capacity:

  • Promotion: Updated payment-stable image to v1.1.0.
  • Delete Canary Ingress: Deleted the secondary canary Ingress manifest, returning 100% of traffic to the stable service.
  • Teardown: Scaled payment-canary deployment to 0 replicas.
  • Overhead Benchmark: Delivered full progressive delivery with 0% sidecar CPU overhead.
Pro Tip: Ingress-Nginx canary annotations deliver 90% of service mesh canary capabilities with zero extra infrastructure overhead.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Ingress-Nginx canary annotations provide lightweight progressive delivery without service mesh sidecars, supporting header matching for QA validation and weighted percentage shifting for safe public releases."
⚡ 60-Second Elevator Pitch Talking Points
  • Deploy dual stable and canary Deployments with independent Kubernetes Services.
  • Use nginx.ingress.kubernetes.io/canary: 'true' with canary-by-header for internal QA.
  • Shift public traffic progressively using canary-weight (10% -> 50%) while monitoring Prometheus.
  • Promote stable deployment to the new image and delete canary ingress with zero sidecar overhead.
Advertisement
Want more CI/CD & GitOps scenarios?
Explore our complete collection of scenario-based CI/CD & GitOps interview runbooks.
Browse All CI/CD & GitOps Questions →