Q: Define a plan for blue/green deployment with rollback on Azure using Terraform and pipelines.
Production blueprint for implementing Blue/Green zero-downtime deployments with instant traffic rollback on Azure using Terraform, App Service deployment slots, and Azure DevOps.
Want to master this scenario in a live sandbox? KodeKloud's HashiCorp Certified Terraform Associate (003) Interactive Labs covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Declare Blue and Green Slots with Sticky Settings in Terraform
Provision Azure App Service with a dedicated `staging` slot alongside `production`. Crucially, configure database connection strings and environment flags as `sticky_settings` so that when slots swap, configuration stays bound to the slot.
# Terraform App Service with Deployment Slot
resource "aws_app_service" "api" { ... }
resource "azurerm_app_service_slot" "green" {
name = "staging"
app_service_name = azurerm_linux_web_app.app.name
resource_group_name = azurerm_resource_group.rg.name
location = azurerm_resource_group.rg.location
app_service_plan_id = azurerm_service_plan.plan.id
}
resource "azurerm_linux_web_app_slot" "sticky_config" {
# Mark slot-specific environment settings
}
CI/CD Pipeline Deploys to Staging (Green) & Runs Warmup Probes
The Azure DevOps pipeline packages the build artifact and deploys it exclusively to the Green (`staging`) slot. Execute automated smoke tests and verify warm-up health checks while Blue continues handling 100% of public traffic.
# Azure DevOps Pipeline Step
- task: AzureWebAppDeployment@4
inputs:
azureSubscription: 'Azure-OIDC'
appName: 'app-prod-banking'
deployToSlotOrASE: true
slotName: 'staging'
package: '$(Pipeline.Workspace)/**/*.zip'
Zero-Downtime Slot Swap (Virtual IP Cutover)
Trigger an Azure slot swap. Azure manages the cutover seamlessly at the reverse-proxy routing layer by redirecting DNS/VIP bindings: Green becomes Production and Blue becomes Staging with zero dropped TCP connections.
- task: AzureAppServiceManage@0
inputs:
azureSubscription: 'Azure-OIDC'
Action: 'Swap Slots'
WebAppName: 'app-prod-banking'
ResourceGroupName: 'rg-banking'
SourceSlot: 'staging'
SwapWithProduction: true
Instant Sub-Second Rollback Protocol
If post-swap telemetry reveals error spikes, trigger an immediate second slot swap. Because the previous stable Blue code is still alive in the staging slot, swapping back restores stability instantly without building or deploying.
- Use Terraform to declare primary and staging slots with sticky configuration parameters.
- Deploy new releases into the staging slot and execute automated health checks.
- Execute an Azure slot swap to redirect production traffic with zero downtime.
- Execute an instant reverse slot swap if error rates spike post-cutover.