Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success.

MITAuto-check passedDevOps & Cloud

Install Canary

skills CLI
$ npx skills add atelier-fashion/adlc-toolkit --skill canary -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install atelier-fashion/adlc-toolkit canary --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/atelier-fashion/adlc-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/canary .claude/skills/canary && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canary
GitHub stars
171
Token cost
~2.2k tokens
SKILL.md length
885 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success.

  • Works in 7 steps: Build and Push Image → Deploy Canary Revision (Zero Traffic) → Health Checks → …
  • The user says canary deploy
  • SKILL.md covers Ethos, Context, Input and Prerequisites, plus 4 more sections
  • Calls gcloud, curl and docker

What it does

Canary is an agent skill from atelier-fashion/adlc-toolkit. Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success. Use when the user says "canary deploy", "deploy with canary", "smoke test the deploy", or wants deployment confidence before going live.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment and QA and bug reports. It works with Google Cloud and Cloud Run. The repository describes itself as: Shared SDLC skills and templates for Claude Code. The licence is MIT.

When your agent uses it

  • The user says canary deploy
  • Deploy with canary
  • Smoke test the deploy
  • Wants deployment confidence before going live

Example prompts

  • “canary deploy”
  • “deploy with canary”
  • “smoke test the deploy”
  • “/canary”

Requirements

  • Docker

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Build and Push Image
  2. Deploy Canary Revision (Zero Traffic)
  3. Health Checks
  4. Smoke Tests
  5. Promote to Production
  6. Rollback (Failure Path)
  7. Update Pipeline State (if in /proceed context)

What it can do on your machine

Read from SKILL.md and the folder at commit 3a48c27. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud
    • curl
    • docker
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gcloud, curl, docker and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Canary loads about 2.2k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 885 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from atelier-fashion/adlc-toolkit at commit 3a48c27, republished under its MIT licence (© atelier-fashion). 885 words, ~2,237 tokens.

Download SKILL.mdSave it as .claude/skills/canary/SKILL.md (or your agent's skills folder).
name
canary
description
Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success. Use when the user says "canary deploy", "deploy with canary", "smoke test the deploy", or wants deployment confidence before going live.
argument-hint
Optional repo id (from .adlc/config.yml) or service name — auto-detected from current worktree if omitted

/canary — Canary Deployment with Smoke Tests

You are deploying code through a canary process: deploy a zero-traffic revision, verify it works, then promote to live traffic. This prevents broken deploys from reaching users.

Ethos

!test -s .adlc/ETHOS.md && cat .adlc/ETHOS.md || echo No ethos found — run /init to vendor .adlc/ETHOS.md

Context

  • Current directory: !pwd
  • Current branch: !git branch --show-current || echo Not a git repo
  • GCP project: !gcloud config get-value project 2>/dev/null || echo "No GCP project configured"
  • Active Cloud Run services: !gcloud run services list --format="table(SERVICE,REGION,URL)" 2>/dev/null || echo "gcloud not configured"

Input

Target: $ARGUMENTS

Prerequisites

  1. gcloud CLI must be authenticated and configured with the correct project
  2. The service must already exist on Cloud Run (this skill deploys revisions, not new services)
  3. A Docker image must be available (either build locally or use the latest from Artifact Registry)

Service Resolution

Service configuration lives in .adlc/config.yml in the primary repo under a services: block, keyed by repo id. This is the single source of truth — no service names, regions, or image paths should be hardcoded in this skill.

Expected config shape (primary repo .adlc/config.yml):

yaml
repos:
  api:
    path: ../api
  web:
    path: ../web

services:
  api:
    cloud_run_service: api
    region: us-central1
    image_path: us-central1-docker.pkg.dev/<gcp-project>/api/api
  web:
    cloud_run_service: web
    region: us-central1
    image_path: us-central1-docker.pkg.dev/<gcp-project>/web/web

Resolution order:

  1. If $ARGUMENTS is a repo id defined under repos: in the primary's config, look up services[<repo-id>] and use that. If the repo id has no services: entry, stop and ask the user to add one.
  2. If $ARGUMENTS is a Cloud Run service name already (e.g., the user passed api and it matches services.*.cloud_run_service), use that entry.
  3. If no argument: detect which repo the current cwd is inside by walking up to find a git root and matching it against repos[*].path (resolve each to an absolute path first). Then look up its service.
  4. If the project has no .adlc/config.yml (single-repo legacy setup) AND the current repo has a top-level Dockerfile and a single Cloud Run service name that matches the repo basename, fall back to auto-detection: service name = repo basename, region = us-central1, image path = $(gcloud config get-value project)/<service>. Surface this fallback in the logs so the user knows it's being inferred.
  5. If none of the above resolves, stop with a clear error: "Could not determine Cloud Run service. Add a services: block to .adlc/config.yml or pass the service name as an argument."

Operating worktree: if the resolved repo has a feature-branch worktree (e.g., .worktrees/REQ-xxx) that matches the current /proceed pipeline, build from inside that worktree. Otherwise build from the repo's main checkout. The caller can also pass the worktree path explicitly.

Note (post-REQ-380, REQ-381): /canary is no longer auto-invoked from /proceed (REQ-380) or /bugfix (REQ-381). Operators run it manually when a production canary is needed.

Instructions

Step 1: Build and Push Image
  1. Determine the image tag: use the current git SHA (git rev-parse --short HEAD)
  2. Build the Docker image:
    bash
    docker build -t <IMAGE_PATH>:canary-<SHA> ./<subdir if needed>
  3. Push to Artifact Registry:
    bash
    docker push <IMAGE_PATH>:canary-<SHA>

If the user says "use latest" or the image was already built by CI, skip the build and use the :latest tag from Artifact Registry.

Step 2: Deploy Canary Revision (Zero Traffic)

Deploy a new revision that receives NO traffic:

bash
gcloud run deploy <SERVICE_NAME> \
  --image=<IMAGE_PATH>:canary-<SHA> \
  --region=us-central1 \
  --no-traffic \
  --tag=canary \
  --format="json"

This creates a tagged revision accessible at https://canary---<SERVICE_NAME>-<hash>.a.run.app without affecting production traffic.

Capture the canary URL from the output.

Show full SKILL.md (396 more words)Show less
Step 3: Health Checks

Run basic health checks against the canary URL:

  1. Liveness: curl -s -o /dev/null -w "%{http_code}" <CANARY_URL>/health

    • Expected: 200
    • Retry up to 3 times with 5-second intervals (cold start grace period)
  2. Readiness: curl -s -o /dev/null -w "%{http_code}" <CANARY_URL>/api/health

    • Expected: 200 (or the service's documented readiness endpoint)

If health checks fail after 3 retries, go to Step 6 (Rollback).

Step 4: Smoke Tests

Run smoke tests against the canary URL. Load test definitions from the primary repo's .adlc/context/smoke-tests.md if it exists, otherwise use defaults. In cross-repo mode the primary's smoke-tests.md is the authoritative source for every service — sibling repos do not need their own copy.

Default smoke tests (API services):

GET  /health              -> 200
GET  /api/health          -> 200

Custom smoke tests (from .adlc/context/smoke-tests.md): Each entry should specify: method, path, expected status, optional body pattern.

For each test:

bash
RESPONSE=$(curl -s -w "\n%{http_code}" <CANARY_URL><PATH>)
STATUS=$(echo "$RESPONSE" | tail -1)
BODY=$(echo "$RESPONSE" | head -n -1)

Report results:

## Smoke Test Results

| Test | Method | Path | Expected | Actual | Status |
|------|--------|------|----------|--------|--------|
| Health | GET | /health | 200 | 200 | PASS |
| API Health | GET | /api/health | 200 | 200 | PASS |

Result: 2/2 passed

If any test fails, go to Step 6 (Rollback).

Step 5: Promote to Production

All checks passed — promote the canary revision to 100% traffic:

bash
gcloud run services update-traffic <SERVICE_NAME> \
  --region=us-central1 \
  --to-tags=canary=100

Verify promotion:

bash
gcloud run services describe <SERVICE_NAME> \
  --region=us-central1 \
  --format="table(status.traffic[].percent,status.traffic[].revisionName,status.traffic[].tag)"

Confirm canary revision is now serving 100% traffic.

Remove the canary tag (clean up):

bash
gcloud run services update-traffic <SERVICE_NAME> \
  --region=us-central1 \
  --remove-tags=canary

Report:

Canary promoted to production.
Service: <SERVICE_NAME>
Revision: <REVISION_NAME>
URL: <PRODUCTION_URL>
All smoke tests passed.
Step 6: Rollback (Failure Path)

If health checks or smoke tests fail:

  1. Delete the canary revision tag (so it's not addressable):

    bash
    gcloud run services update-traffic <SERVICE_NAME> \
      --region=us-central1 \
      --remove-tags=canary
  2. Report the failure:

    CANARY FAILED — rolled back.
    Service: <SERVICE_NAME>
    Failed revision: canary-<SHA>
    
    Failures:
    - [list failed health checks or smoke tests]
    
    Production traffic is unchanged — still serving the previous revision.
  3. Suggest next steps:

    • Check Cloud Run logs: gcloud run services logs read <SERVICE_NAME> --region=us-central1 --limit=50
    • Investigate the failure locally
    • Fix and re-run /canary
Step 7: Update Pipeline State (if in /proceed context)

If pipeline-state.json exists for the current REQ:

  1. Add a canary entry to phaseHistory with the result (passed/failed)
  2. Include: service name, revision, smoke test results, canary URL

Smoke Test Configuration

To customize smoke tests, create .adlc/context/smoke-tests.md with this format:

markdown
# Smoke Tests

## api
| Method | Path | Expected Status | Body Pattern |
|--------|------|-----------------|--------------|
| GET | /health | 200 | |
| GET | /api/health | 200 | |
| GET | /api/v1/config | 200 | "version" |

## web
| Method | Path | Expected Status | Body Pattern |
|--------|------|-----------------|--------------|
| GET | / | 200 | |
| GET | /api/health | 200 | |

The keys above (api, web) are repo ids — the same ids you used under repos: in .adlc/config.yml. /canary looks up the smoke tests for the service it's deploying by matching repo id.

What This Skill Does NOT Do

  • It does not create new Cloud Run services — the service must already exist
  • It does not handle iOS deployments — TestFlight is already a canary-like process
  • It does not modify CI/CD workflows — it's a manual deployment confidence tool
  • It does not handle database migrations — run those separately before deploying

© atelier-fashion, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in canary of atelier-fashion/adlc-toolkit.

Open the folder on GitHubat commit 3a48c27

Compare with similar skills

Canary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canary compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canary this skillatelier-fashion/adlc-toolkit171—~2.2kAutomated safety check: PassMIT
Broccoli Oss GCP Deploybesimple-oss/broccoli285—~4.1kAutomated safety check: PassMIT
Google Agents CLI Publishpifferologo/cloud-agents-cli1291 repos~2.4kAutomated safety check: PassApache-2.0
DeployingGoogleCloudPlatform/race-condition234—~3kAutomated safety check: PassCustom licence
Google Cloud Solution Guided Gke AI Migrationgoogle/skills21k—~8.3kAutomated safety check: PassApache-2.0
Apollo Deploy Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Broccoli Oss GCP Deploy

    besimple-oss/broccoli

    Deploy this repository to a new Google Cloud project using the repo's existing Cloud Run, Cloud Run Jobs, Cloud SQL, Secret Manager, and Artifact Registry scripts.

    285 GitHub stars~4.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Google Agents CLI Publish

    pifferologo/cloud-agents-cli

    This skill should be used when the user wants to "publish an agent", "publish my ADK agent", "register an agent with Gemini Enterprise", "publish to Gemini Enterprise", or needs guidance on the…

    129 GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Deploying

    GoogleCloudPlatform/race-condition

    Guides deployment of Race Condition to a GCP project. An agent skill from GoogleCloudPlatform/race-condition.

    234 GitHub stars~3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Guides the migration of existing AI workloads (Cloud Run, Gemini API, Gemini Enterprise Agent Platform) to self-hosted GKE inference using gcloud and kubectl.

    21k GitHub stars~8.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Apollo Deploy Integration

    jeremylongshore/tons-of-skills-marketplace

    Deploy Apollo.io integrations to production. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Research To Deploy

    jeremylongshore/tons-of-skills-marketplace

    Researches infrastructure best practices and generates deployment-ready configurations, Terraform modules, Dockerfiles, and CI/CD pipelines.

    2.8k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from atelier-fashion/adlc-toolkit

All 16 skills in this repo
  • Sprint

    atelier-fashion/adlc-toolkit

    Parallel pipeline orchestrator — launch multiple /proceed sessions concurrently across REQs, monitor progress, and report status.

    171 GitHub stars~9.8k tokensUpdated 12 days ago
    Auto-check passed
  • Template Drift

    atelier-fashion/adlc-toolkit

    Detect drift across ALL the sync surfaces /init vendors into a project — .adlc/templates/.md, .adlc/partials/.sh, .adlc/ETHOS.md, and the workflow runtime (.adlc/workflows/adlc-sprint.workflow.js +…

    171 GitHub stars~9k tokensUpdated 12 days ago
    Auto-check passed
  • Proceed

    atelier-fashion/adlc-toolkit

    End-to-end ADLC pipeline that takes a requirement from spec through to deployed.

    171 GitHub stars~14k tokensUpdated 12 days ago
    Auto-check: warnings
  • Init

    atelier-fashion/adlc-toolkit

    Bootstrap .adlc/ structure in a new repo or subdirectory. An agent skill from atelier-fashion/adlc-toolkit.

    171 GitHub stars~4.1k tokensUpdated 12 days ago
    Auto-check passed
  • Manifest

    atelier-fashion/adlc-toolkit

    Remote-derived view of all in-flight ADLC work — open PRs and pushed feat/REQ- branches across every session — with a coarse component/domain overlap report.

    171 GitHub stars~4.8k tokensUpdated 12 days ago
    Auto-check passed
  • Review

    atelier-fashion/adlc-toolkit

    Multi-agent code review covering correctness, quality, architecture, test coverage, and security

    171 GitHub stars~1.9k tokensUpdated 12 days ago
    Auto-check passed

Questions about Canary

What does Canary do?

Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success. Canary is an agent skill from atelier-fashion/adlc-toolkit. Canary deployment with smoke tests — deploy to a zero-traffic revision, run health checks, and promote on success.

When should I use Canary?

Canary fits situations like: the user says canary deploy; deploy with canary; smoke test the deploy; wants deployment confidence before going live.

How do I install Canary in Claude Code?

Run `npx skills add atelier-fashion/adlc-toolkit --skill canary -a claude-code`. Or copy the skill folder (canary in atelier-fashion/adlc-toolkit) into .claude/skills/canary in your project. Claude Code loads it when a task matches its description.

How do I install Canary in Codex?

Run `npx skills add atelier-fashion/adlc-toolkit --skill canary -a codex`. Or copy the skill folder (canary in atelier-fashion/adlc-toolkit) into .agents/skills/canary in your project. Codex loads it when a task matches its description.

Can I use Canary in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add atelier-fashion/adlc-toolkit --skill canary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canary, .gemini/skills/canary, .github/skills/canary and .opencode/skills/canary in your project.

What does Canary need to run?

Going by SKILL.md and its folder, Canary needs the command-line tools its instructions call (gcloud, curl, docker and git). Our summary lists: Docker.

Does Canary access the network?

SKILL.md contains no URLs. Its commands use curl, docker and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Canary safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canary use?

Canary is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canary use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Canary?

Skills that share tags, products or a category with Canary: Broccoli Oss GCP Deploy (besimple-oss/broccoli, 285 stars), Google Agents CLI Publish (pifferologo/cloud-agents-cli, 129 stars), Deploying (GoogleCloudPlatform/race-condition, 234 stars) and Google Cloud Solution Guided Gke AI Migration (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canary?

atelier-fashion (a GitHub organization) maintains it in atelier-fashion/adlc-toolkit, which has 171 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on September 28, 2026.

Source: atelier-fashion/adlc-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.