<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Travis Wheatley</title>
    <description>The latest articles on DEV Community by Travis Wheatley (@traviswheatley).</description>
    <link>https://dev.to/traviswheatley</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4113641%2Fbe1ba22c-68a6-4be9-bade-3d9ac0ed2dc5.png</url>
      <title>DEV Community: Travis Wheatley</title>
      <link>https://dev.to/traviswheatley</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/traviswheatley"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>Travis Wheatley</dc:creator>
      <pubDate>Wed, 09 Sep 2026 06:27:14 +0000</pubDate>
      <link>https://dev.to/traviswheatley/-2dh3</link>
      <guid>https://dev.to/traviswheatley/-2dh3</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/earlgreyhot1701d/gating-access-with-bifrost-nine-calls-three-refusals-one-trap-46h4" class="crayons-story__hidden-navigation-link"&gt;Scoping Permissions with RBAC and Data Access Control at the AI Gateway&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/earlgreyhot1701d" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3683045%2F745698c0-b6f4-42ea-96e9-44a671fa69e0.png" alt="earlgreyhot1701d profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/earlgreyhot1701d" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Earl Grey
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Earl Grey
                &lt;a href="/++"&gt;&lt;img alt="Subscriber" class="subscription-icon" src="https://assets.dev.to/assets/subscription-icon-805dfa7ac7dd660f07ed8d654877270825b07a92a03841aa99a1093bd00431b2.png"&gt;&lt;/a&gt;
                
              
              &lt;div id="story-author-preview-content-4610297" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/earlgreyhot1701d" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3683045%2F745698c0-b6f4-42ea-96e9-44a671fa69e0.png" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Earl Grey&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/earlgreyhot1701d/gating-access-with-bifrost-nine-calls-three-refusals-one-trap-46h4" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Sep 9&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/earlgreyhot1701d/gating-access-with-bifrost-nine-calls-three-refusals-one-trap-46h4" id="article-link-4610297"&gt;
          Scoping Permissions with RBAC and Data Access Control at the AI Gateway
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/buildinpublic"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;buildinpublic&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/civictech"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;civictech&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/claude"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;claude&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/aws"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;aws&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/earlgreyhot1701d/gating-access-with-bifrost-nine-calls-three-refusals-one-trap-46h4" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;12&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/earlgreyhot1701d/gating-access-with-bifrost-nine-calls-three-refusals-one-trap-46h4#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              5&lt;span class="hidden s:inline"&gt;&amp;nbsp;comments&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            16 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Feature Flag Tools Compared (2026): LaunchDarkly vs Flagsmith vs Unleash vs ConfigBee vs Statsig vs PostHog vs ConfigCat vs Harness FME</title>
      <dc:creator>Travis Wheatley</dc:creator>
      <pubDate>Mon, 07 Sep 2026 21:22:04 +0000</pubDate>
      <link>https://dev.to/traviswheatley/feature-flag-tools-compared-2026-launchdarkly-vs-flagsmith-vs-unleash-vs-configbee-vs-statsig-vs-1f30</link>
      <guid>https://dev.to/traviswheatley/feature-flag-tools-compared-2026-launchdarkly-vs-flagsmith-vs-unleash-vs-configbee-vs-statsig-vs-1f30</guid>
      <description>&lt;p&gt;I recently had to pick a feature flag tool for a project and made the mistake of Googling "feature flag tools comparison." Every result was either written by a vendor (ranking itself first, naturally) or frozen in 2023. The market has moved a lot since then:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Split no longer exists as a standalone product.&lt;/strong&gt; Harness acquired it in 2024, and it's now Harness FME, a module inside the Harness platform. The old split.io pricing page redirects to harness.io.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;OpenAI acquired Statsig in September 2025&lt;/strong&gt; (reported at $1.1B). Statsig still operates independently, but that's now a fact in your vendor-risk column.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;LaunchDarkly repositioned.&lt;/strong&gt; Its pricing page now sells "features and agents": AI config, observability, and session replay alongside flags. Flags alone stopped being the premium product.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So I did the work myself. I read every official pricing page and dug through each vendor's docs for the stuff comparison posts skip: how rollouts actually bucket users, how fast a flag flip reaches a client, and what the pricing meter really charges. Everything below is from official sources as of September 2026 (linked at the bottom). If something's wrong, call it out in the comments and I'll fix it.&lt;/p&gt;

&lt;h2&gt;
  
  
  TL;DR - the verdict up front
&lt;/h2&gt;

&lt;p&gt;Most comparison posts bury the conclusion. Here's mine, then the evidence that earns it:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Overall pick for a new project in 2026: &lt;a href="https://configbee.com" rel="noopener noreferrer"&gt;ConfigBee&lt;/a&gt;&lt;/strong&gt; - unlimited flags and dynamic configs on the free tier, realtime updates on every plan, a written 99.99% delivery SLA, no seat tax, $60/mo entry. The weights behind that call, and where it flips, are in the verdict section at the bottom.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Category winners:&lt;/strong&gt; Statsig (free tier, experimentation), Flagsmith (budget), Unleash (open source/self-host), LaunchDarkly (enterprise), PostHog or Harness FME (if you're already in their ecosystem), ConfigBee (availability commitment, runtime config).&lt;/li&gt;
&lt;li&gt;If you read nothing else, read the update-speed findings. Two of these tools deliver flag changes in realtime, in milliseconds. The rest make users wait - one of them for days.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Quick comparison: 8 feature flag tools side by side
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Free tier&lt;/th&gt;
&lt;th&gt;Paid starts at&lt;/th&gt;
&lt;th&gt;Pricing meter&lt;/th&gt;
&lt;th&gt;Self-host&lt;/th&gt;
&lt;th&gt;Realtime updates&lt;/th&gt;
&lt;th&gt;Reliability (SLA)&lt;/th&gt;
&lt;th&gt;CDN / edge delivery&lt;/th&gt;
&lt;th&gt;OpenFeature&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;LaunchDarkly&lt;/td&gt;
&lt;td&gt;1K client MAU, 5 service connections&lt;/td&gt;
&lt;td&gt;PAYG ($10/conn, $8.33 per 1K MAU)&lt;/td&gt;
&lt;td&gt;Usage&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes (streaming)&lt;/td&gt;
&lt;td&gt;SLA at Enterprise; public status (99.94% 90-day delivery)&lt;/td&gt;
&lt;td&gt;Flag Delivery Network&lt;/td&gt;
&lt;td&gt;Yes (official providers)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flagsmith&lt;/td&gt;
&lt;td&gt;50K requests/mo, 1 seat&lt;/td&gt;
&lt;td&gt;$45/mo&lt;/td&gt;
&lt;td&gt;API requests&lt;/td&gt;
&lt;td&gt;Yes (open source)&lt;/td&gt;
&lt;td&gt;Enterprise plan only&lt;/td&gt;
&lt;td&gt;SLA at Enterprise (contact sales)&lt;/td&gt;
&lt;td&gt;Edge API at Enterprise tier&lt;/td&gt;
&lt;td&gt;Yes (official providers)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unleash&lt;/td&gt;
&lt;td&gt;Open source self-host&lt;/td&gt;
&lt;td&gt;$75/seat/mo (cloud)&lt;/td&gt;
&lt;td&gt;Seats&lt;/td&gt;
&lt;td&gt;Yes (open source)&lt;/td&gt;
&lt;td&gt;Poll + cache&lt;/td&gt;
&lt;td&gt;99.9% (PAYG), 99.99% (Enterprise)&lt;/td&gt;
&lt;td&gt;Unleash Edge layer&lt;/td&gt;
&lt;td&gt;Yes (official providers)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ConfigBee&lt;/td&gt;
&lt;td&gt;500 monthly active visitors&lt;/td&gt;
&lt;td&gt;$60/mo&lt;/td&gt;
&lt;td&gt;Monthly active visitors&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Yes (real-time streaming)&lt;/td&gt;
&lt;td&gt;99.99% delivery / 99.9% non-essential, written + credits&lt;/td&gt;
&lt;td&gt;Multi-CDN (Cloudflare + CloudFront), 200+ PoPs&lt;/td&gt;
&lt;td&gt;Yes (official web provider)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Statsig&lt;/td&gt;
&lt;td&gt;2M events/mo, unlimited flag checks&lt;/td&gt;
&lt;td&gt;$150/mo flat&lt;/td&gt;
&lt;td&gt;Analytics events&lt;/td&gt;
&lt;td&gt;Warehouse-native&lt;/td&gt;
&lt;td&gt;Yes&lt;/td&gt;
&lt;td&gt;No delivery SLA published (99.95% console SLA at enterprise)&lt;/td&gt;
&lt;td&gt;Not detailed publicly&lt;/td&gt;
&lt;td&gt;Community/limited&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PostHog&lt;/td&gt;
&lt;td&gt;1M flag requests/mo&lt;/td&gt;
&lt;td&gt;Usage from $0.0001/request&lt;/td&gt;
&lt;td&gt;Flag requests&lt;/td&gt;
&lt;td&gt;Yes (open source)&lt;/td&gt;
&lt;td&gt;Local eval + refresh&lt;/td&gt;
&lt;td&gt;No published SLA; public status page&lt;/td&gt;
&lt;td&gt;Local evaluation; CDN not detailed&lt;/td&gt;
&lt;td&gt;Community/limited&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ConfigCat&lt;/td&gt;
&lt;td&gt;10 flags, 2 environments&lt;/td&gt;
&lt;td&gt;$110/mo&lt;/td&gt;
&lt;td&gt;Config JSON downloads&lt;/td&gt;
&lt;td&gt;Dedicated option&lt;/td&gt;
&lt;td&gt;Poll + CDN cache&lt;/td&gt;
&lt;td&gt;99% to 99.99% by tier, published&lt;/td&gt;
&lt;td&gt;Global CDN (config JSON)&lt;/td&gt;
&lt;td&gt;Yes (most providers in the ecosystem)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Harness FME&lt;/td&gt;
&lt;td&gt;Free plan at signup&lt;/td&gt;
&lt;td&gt;Contact sales&lt;/td&gt;
&lt;td&gt;MAU, enterprise contract&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;Gradual sync (see below)&lt;/td&gt;
&lt;td&gt;Enterprise contract only&lt;/td&gt;
&lt;td&gt;CDN-cached rollout plans&lt;/td&gt;
&lt;td&gt;Yes (via Split providers)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Now the details, tool by tool.&lt;/p&gt;

&lt;h2&gt;
  
  
  The two mechanics everyone asks about first
&lt;/h2&gt;

&lt;p&gt;Before the deep dives: every buyer's first two questions are "can I roll out to a percentage of users" and "can I target a specific set of users." Here's the quick audit (details and sources in each section):&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Percentage rollouts&lt;/th&gt;
&lt;th&gt;Target a set of users&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;LaunchDarkly&lt;/td&gt;
&lt;td&gt;Yes - in any rule or the default rule, down to 0.001% precision (hash partitions 1-100,000); progressive rollouts can automate the ramp&lt;/td&gt;
&lt;td&gt;Individual contexts, attribute rules, segments (large/synced segments are Enterprise)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flagsmith&lt;/td&gt;
&lt;td&gt;Yes - "% Split" segment rule, sticky per user&lt;/td&gt;
&lt;td&gt;Segments on user traits, per-flag segment overrides, individual identity overrides&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unleash&lt;/td&gt;
&lt;td&gt;Yes - gradual rollout strategy with sticky bucketing&lt;/td&gt;
&lt;td&gt;Constraints on any context field, reusable segments, user ID lists; strategies OR, constraints AND&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ConfigBee&lt;/td&gt;
&lt;td&gt;Yes - percentage of visitors and percentage of context (anonymous traffic and known users bucket separately)&lt;/td&gt;
&lt;td&gt;Contextual targeting at user/account/org/environment level, target lists, individual personalizations, composite combos&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Statsig&lt;/td&gt;
&lt;td&gt;Yes - pass percentage per rule, stable per user via per-gate salt&lt;/td&gt;
&lt;td&gt;User ID lists, email, app version, segments, custom attributes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PostHog&lt;/td&gt;
&lt;td&gt;Yes - rollout % per release condition set&lt;/td&gt;
&lt;td&gt;Person properties, cohorts, groups (orgs/teams), even non-user entities like pages or machines&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ConfigCat&lt;/td&gt;
&lt;td&gt;Yes - sticky percentage options (multi-value splits count against plan limits)&lt;/td&gt;
&lt;td&gt;Targeting rules on any user attribute, segments, dedicated fallback for unidentified users&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Harness FME&lt;/td&gt;
&lt;td&gt;Yes - deterministic 100-bucket distribution per flag&lt;/td&gt;
&lt;td&gt;Individual user IDs, segments (standard/large/rule-based), attribute rules; account-level targeting&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://launchdarkly.com" rel="noopener noreferrer"&gt;LaunchDarkly&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzns0wwh64q1xllx6hfj2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fzns0wwh64q1xllx6hfj2.png" alt="LaunchDarkly flags list with production and test environments" width="800" height="244"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The incumbent, and still the deepest platform: targeting rules with prerequisites, individual and segment targeting, scheduled rollouts, approvals, and 30 SDKs (13 client-side, 13 server-side, 4 edge).&lt;/p&gt;

&lt;p&gt;Percentage rollouts deserve a specific nod: you can attach one to any targeting rule or the default rule, allocate down to three decimal places (0.125% is valid - the hash space has 100,000 partitions), and progressive rollouts can automate the ramp on a schedule instead of you babysitting the slider. Individual user targeting, attribute-based rules, and segments cover set selection, with the large and synced segment lists reserved for Enterprise.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How evaluation works:&lt;/strong&gt; server-side and edge SDKs evaluate locally with embedded rules; client-side SDKs get evaluated results from LaunchDarkly's backend. Flag changes stream over a persistent connection, and every SDK lets you subscribe to change listeners, so a flag flip hits connected clients in near real time. This is the gold standard for "kill switch speed."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Track record:&lt;/strong&gt; when AWS us-east-1 fell over on October 20, 2025, LaunchDarkly's flag management and delivery were both impacted, and their &lt;a href="https://launchdarkly.com/blog/what-happened-what-we-learned-and-how-were-improving/" rel="noopener noreferrer"&gt;public postmortem&lt;/a&gt; is candid about the internal cascading failures that extended recovery. Read it before assuming streaming delivery means invincible - and credit to them for publishing it, which is what you want from a vendor.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; the &lt;a href="https://launchdarkly.com/pricing/" rel="noopener noreferrer"&gt;free Developer tier&lt;/a&gt; is genuinely usable (unlimited seats, unlimited flags, capped at 1K client-side MAU and 5 service connections monthly). Past that, Foundation is pay-as-you-go: $10 per service connection per month plus $8.33 per 1K client-side MAU, with separate meters for AI runs, logs, traces, and session replays.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; bill shape. You're estimating connections, MAU, and observability volume at once, and the Enterprise features (advanced targeting, workflows, custom roles) sit behind custom pricing. Small teams routinely pay for depth they never touch.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; you need governance, approvals, and streaming kill switches at scale. &lt;strong&gt;Skip it if:&lt;/strong&gt; you're a small team that just needs flags - the meters will outrun you.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://flagsmith.com" rel="noopener noreferrer"&gt;Flagsmith&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Feo0qyahsl6sz19afvd47.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Feo0qyahsl6sz19afvd47.png" alt="Flagsmith feature flag dashboard" width="799" height="453"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The open source pragmatist. Self-host the community edition for free, or use their cloud: free tier at 50K API requests/month (1 team member, unlimited flags and environments), Start-Up at &lt;a href="https://www.flagsmith.com/pricing" rel="noopener noreferrer"&gt;$45/mo&lt;/a&gt; (1M requests, 3 members), Scale-Up at $300/mo (5M+ requests, governance features). Overage is roughly $50 per million requests, decreasing with volume.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How rollouts work:&lt;/strong&gt; percentage rollouts are a segment rule. Flagsmith hashes the identity ID plus segment ID into a stable float between 0 and 1, so a user at 0.35 enters the segment when you cross 40% and stays there. Standard sticky bucketing, done transparently - the docs literally walk you through the math.&lt;/p&gt;

&lt;p&gt;For picking a set of users, segments match on any trait you send (plan, email domain, semver version), segment overrides apply per flag per environment, and identity overrides pin a value for one specific user - the classic "turn it on for the CEO's account first" move.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Real-time behavior:&lt;/strong&gt; here's the catch most listicles miss. Real-time updates exist (SSE stream per environment, SDKs subscribe and re-fetch), but the docs state it requires an Enterprise subscription. On lower tiers, your SDKs poll. If "flip a flag, every client updates now" matters to you, that's a paid-gated feature here. Their public status page shows the delivery path has had hiccups - see the &lt;a href="https://status.flagsmith.com/incidents/d4yndjchgq8s" rel="noopener noreferrer"&gt;January 2026 Edge API incident&lt;/a&gt; - minor impact, resolved, and posted openly, which is the transparency you want to see.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; request-based pricing. A chatty frontend that polls aggressively can eat the included volume. Count your clients' poll intervals before picking a tier.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; you want open source with a cloud option and the lowest credible entry price. &lt;strong&gt;Skip it if:&lt;/strong&gt; you need realtime updates without an Enterprise plan.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.getunleash.io" rel="noopener noreferrer"&gt;Unleash&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7ef8dltc4kweitnkavfj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F7ef8dltc4kweitnkavfj.png" alt="Unleash gradual rollout strategies with constraints" width="800" height="517"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The other open source heavyweight, and the most flag-puritan tool here. Self-hosted Unleash is free and very capable. Unleash Cloud is &lt;a href="https://www.getunleash.io/pricing" rel="noopener noreferrer"&gt;$75/seat/month&lt;/a&gt; (5-seat minimum on self-hosted Enterprise trial terms), and in exchange you get unlimited client-side MAU and 53M API requests a month.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SDK coverage:&lt;/strong&gt; 8 official backend SDKs (Go, Java, Node, PHP, Python, Ruby, Rust, .NET) that evaluate flags locally, and 9 frontend SDKs (Android, iOS, Flutter, JavaScript, React, React Native, Next.js, Svelte, Vue) that fetch evaluated flags from the server or Unleash Edge. Note the split: frontend evaluation happens server-side, so the user context travels to Unleash.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How rollouts work:&lt;/strong&gt; activation strategies. Each flag gets one or more strategies (gradual rollout with a MurmurHash-normalized percentage, user lists, IPs, hostnames), each strategy gets AND-ed constraints on context fields, and the strategies themselves are OR-ed. It's composable and explicit. Rollout stickiness keeps a user in the same bucket across sessions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where it shines:&lt;/strong&gt; lifecycle management. Stale-flag dashboards, flag tagging, "mark as stale" workflows, four-eyes approvals. Unleash treats flag debt as a first-class problem, which nobody else on this list does as well.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; seat pricing in a big org, and no realtime model. SDKs cache in memory and refresh on an interval. Their status page is public too - the &lt;a href="https://unleash.instatus.com/clk5wufah178390o8of4yev1xrd" rel="noopener noreferrer"&gt;July 2023 partial outage&lt;/a&gt; that hit some Pro customers is documented there, updates and all.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; you're self-hosting or drowning in stale flags. &lt;strong&gt;Skip it if:&lt;/strong&gt; per-seat pricing bites at your org size, or you need client updates the moment you flip a flag.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://configbee.com" rel="noopener noreferrer"&gt;ConfigBee&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpwzsacb521jjekneoah6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpwzsacb521jjekneoah6.png" alt="ConfigBee dashboard with flags and dynamic configs" width="800" height="373"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The newest tool here, and the one to watch: it's the only one built around runtime configuration as a first-class product instead of a JSON value hanging off a flag. Dynamic configs (text, number, JSON) get the same workflows as flags: contextual targeting, rollout strategies, the lot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pricing:&lt;/strong&gt; metered on monthly active visitors (MAV) - unique visitors per month, not pageviews. Free tier with 500 MAV and - unusually - unlimited flags and unlimited dynamic configs on every plan, including free. Paid is &lt;a href="https://configbee.com/pricing" rel="noopener noreferrer"&gt;$60/mo (5K MAV) and $200/mo (25K MAV)&lt;/a&gt;, published in USD and INR, which is a tell about who they're building for. Overage drops from $0.40 to $0.20 per 100 visitors as you scale.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Rollouts:&lt;/strong&gt; five strategies: instant, percentage of visitors, percentage of context, target lists, and composite combinations. The visitor/context split is a distinction most tools gloss over: anonymous traffic buckets as visitors, known users bucket by context, so a rollout can treat "people browsing logged-out" and "this customer's account" as separate populations. Contextual targeting works at user, account, organization, environment, or custom segment level, with target lists and per-record personalizations for named sets.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Real-time behavior:&lt;/strong&gt; realtime updates are the default. Changes stream to connected clients in milliseconds with an onUpdate callback, plus local caching and offline fallback in every SDK. This is the thing that's genuinely different from the poll-based middle of the market.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Availability:&lt;/strong&gt; this is where ConfigBee makes its loudest claims, and to its credit they're contractual rather than decorative - but read the contract the way a dev would. The &lt;a href="https://configbee.com/sla/" rel="noopener noreferrer"&gt;published SLA&lt;/a&gt; commits to 99.99% monthly uptime for Essential Services (base flag and config delivery) and 99.9% for Non-Essential Services, with a service-credit ladder running from 10% up to a full month's fees. Two nuances a skeptical reader should catch. First, "downtime" on the essential tier only counts when every delivery endpoint (primary plus all fallbacks) fails at once; a failover event is classed as degradation, not downtime. That definition flatters the number, though it also reflects the actual architecture. Second, the real-time streaming and contextual targeting service sits on the 99.9% non-essential tier - the 99.99% promise covers baseline delivery, not the realtime updates. The architecture itself is &lt;a href="https://configbee.com/reliability/" rel="noopener noreferrer"&gt;multi-cloud and multi-CDN&lt;/a&gt; (Cloudflare and AWS CloudFront are named in the SLA) with automatic endpoint fallback, edge delivery across 200+ PoPs, and a claimed sub-50ms average response. There's a real-world data point too: during the October 2025 AWS us-east-1 outage, their &lt;a href="https://blog.configbee.com/2025/10/20/configbee-status-update-aws-us-east-1-outage-october-20-2025/" rel="noopener noreferrer"&gt;status update&lt;/a&gt; reported essential delivery unaffected because SDKs pull through Cloudflare by default, while only the management plane degraded. LaunchDarkly's &lt;a href="https://launchdarkly.com/blog/what-happened-what-we-learned-and-how-were-improving/" rel="noopener noreferrer"&gt;postmortem of the same outage&lt;/a&gt; records flag delivery impacted with a much longer recovery - same day, very different blast radius. And note the fine print everyone should check on any vendor: the SLA excludes free-of-charge services, so the free tier isn't covered.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Usage limits:&lt;/strong&gt; instead of the usual vague "fair use" hand-waving, ConfigBee &lt;a href="https://docs.configbee.com/fair-usage-policy/" rel="noopener noreferrer"&gt;publishes its FUP math&lt;/a&gt;. Limits derive from your plan's monthly active visitors and deployment units: the free tier works out to 5M requests/month, 20GB of traffic, 25 concurrent streaming connections, and 1,000 config updates, scaling to 250M requests on Growth. Two reader-friendly policies stand out. There's no seat tax at any tier - staff seats scale by formula while Unleash charges $75 per seat. And there's a no-automatic-penalty guarantee: crossing a threshold triggers an engineering review of your integration, not a surprise invoice or a shutoff. If you're planning a launch-day spike, you can even request a pre-approved traffic waiver in advance. The catch, same as any fair-use policy: it prohibits agency-style shared accounts, and the published numbers are estimates that shift with custom contracts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; youth. The SDK family covers JavaScript, React, Angular, Flutter, React Native, and Python, plus an official OpenFeature web provider, but their own &lt;a href="https://docs.configbee.com/sdk-capability-matrix/" rel="noopener noreferrer"&gt;capability matrix&lt;/a&gt; shows the newer rollout types haven't landed in the Angular and Python SDKs yet. There's no built-in experimentation engine, so pair it with your analytics. MAV pricing scales with your traffic, not your team. And there's no self-host option. For a greenfield web or mobile app that lives and dies by runtime tuning, it's the most interesting tool on this list; for a 200-service backend estate, it's not the pick today.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; you're building web or mobile and runtime config is a daily need, not a quarterly one. &lt;strong&gt;Skip it if:&lt;/strong&gt; you need self-hosting, a mature backend SDK estate, or built-in experiments.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.statsig.com" rel="noopener noreferrer"&gt;Statsig&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpzbod83f99wfth565dnw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpzbod83f99wfth565dnw.png" alt="Statsig gate rules with pass percentages" width="800" height="634"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Statsig's model inverts everyone else's: flag and config checks are free and unlimited on every plan, and you pay for analytics events. Free tier: 2M events/month, unlimited flags, unlimited seats, no credit card. Pro is a flat &lt;a href="https://www.statsig.com/pricing" rel="noopener noreferrer"&gt;$150/mo&lt;/a&gt; with 5M events included ($0.05 per 1K after). Enterprise adds warehouse-native deployment, where Statsig runs inside your own data warehouse.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How gates work:&lt;/strong&gt; rules evaluate top to bottom; each rule has conditions (user ID lists, email, app version, country, custom attributes) plus a pass percentage for qualifying users. Bucketing is stable per unit ID via a per-gate salt, and you can "resalt" to reshuffle users. Their own docs recommend a 2% -&amp;gt; 10% -&amp;gt; 50% -&amp;gt; 100% rollout, and each step generates experiment readouts automatically.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Standout detail:&lt;/strong&gt; their docs explicitly tell you when NOT to use feature gates: "if you need structured or multi-value data, use a Dynamic Config; for complex hypotheses, use an Experiment." A vendor that documents its own tool's limits earns trust.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; flags are the on-ramp to the experimentation platform, not the product. And the OpenAI acquisition is a real consideration for multi-year commitments. Also note OpenFeature support is thin compared to the open source players; check the ecosystem directory if that's your integration path. Their public status history isn't spotless either: a &lt;a href="https://status.statsig.com/incidents/mfzybgjxdqkq" rel="noopener noreferrer"&gt;July 2026 incident&lt;/a&gt; had launched feature gates evaluating incorrectly for V2 Config Delivery API users for about five hours. Resolved and documented openly, but file it under things to know.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; experimentation is your center of gravity and flags come along for free. &lt;strong&gt;Skip it if:&lt;/strong&gt; you want a vendor whose roadmap answers to its own customers, not a parent company's.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://posthog.com" rel="noopener noreferrer"&gt;PostHog&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0h3pqtz57oc6kf65hpbk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0h3pqtz57oc6kf65hpbk.png" alt="PostHog feature flag variant keys and release conditions" width="800" height="474"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you already run PostHog analytics, adding flags is close to free: 1M flag requests/month on the free tier, then &lt;a href="https://posthog.com/pricing" rel="noopener noreferrer"&gt;usage-based&lt;/a&gt; from $0.0001 per request with volume discounts, plus billing limits so you never get surprise invoices. Open source and self-hostable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Targeting model:&lt;/strong&gt; because PostHog already knows your users, release conditions target person properties, cohorts, and groups, not just a percentage. Flags support JSON payloads (their remote config answer), local evaluation, and bootstrapping so the flag state survives page loads without flicker.&lt;/p&gt;

&lt;p&gt;One quirk worth knowing: the entity you target doesn't have to be a user at all. Their docs walk through targeting groups, organizations, pages, machines, and services as flag subjects, which opens up ops-style use cases most flag tools don't address.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Standout detail:&lt;/strong&gt; the loop closes inside one tool. You roll out to 5%, then watch session replays and error rates for exactly the users who got the flag. No other tool on this list makes "did the rollout work" that easy to answer. They're also shipping interesting flag-hygiene tooling that detects dead flags and opens draft PRs to remove them. And they publish full postmortems in their public handbook - including the &lt;a href="https://posthog.com/handbook/company/post-mortems/2025-10-21-feature-flags-recurring-outages" rel="noopener noreferrer"&gt;October 2025 run of feature-flag outages&lt;/a&gt; - which is the transparency every vendor on this list should copy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; governance. Approvals, granular RBAC, and lifecycle workflows are thinner than the dedicated platforms. And request-metered pricing on a high-traffic consumer app needs a calculator before you commit.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; PostHog already runs your analytics. &lt;strong&gt;Skip it if:&lt;/strong&gt; you need enterprise governance or you're starting from zero - there are deeper flag platforms.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://configcat.com" rel="noopener noreferrer"&gt;ConfigCat&lt;/a&gt;
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwanffb3ffsuae79y1qvf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwanffb3ffsuae79y1qvf.png" alt="ConfigCat dashboard" width="800" height="585"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The boring, predictable option, and I mean that as a compliment. Flat published pricing: a forever-free plan (10 flags, 2 environments, unlimited seats, unlimited MAU), then &lt;a href="https://www.configcat.com/pricing/" rel="noopener noreferrer"&gt;$110 / $325 / $900 per month tiers&lt;/a&gt;, and a $4,500/mo dedicated option. The meter is config JSON downloads (5M/month on free, scaling up the tiers), not users.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SDK coverage is the widest here:&lt;/strong&gt; JavaScript, Angular, React, Node, .NET, Java, Go, PHP, Python, Ruby, Elixir, Android, iOS, Flutter/Dart, Kotlin Multiplatform, C++, Rust, Unity, Unreal Engine.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Delivery model:&lt;/strong&gt; deliberately old-school. SDKs download a config JSON from ConfigCat's CDN on one of three polling modes: auto (every 60s by default), lazy (on cache expiry), or manual (you call forceRefresh). There's an offline mode and a shared cache option. No realtime updates, no streaming - and for a huge class of apps, a 60-second propagation delay is completely fine. Know which class you're in. When their CDN did take a DDoS hit back in 2021, they published the &lt;a href="https://configcat.com/blog/2021/10/08/ddos-recap/" rel="noopener noreferrer"&gt;full incident recap&lt;/a&gt;, timeline and all - consistent with the boring-reliability posture.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Targeting:&lt;/strong&gt; percentage options are sticky and consistent across SDKs, and combinable with targeting rules on any user attribute. Segments handle reusable user sets, and there's an explicit "to unidentified" fallback value for users missing the bucketing attribute - a small thing that saves you from a class of production surprises. One plan note: for multi-value settings, the number of percentage options per flag is plan-limited (free tier gets 4 per flag).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; the 10-flag free tier goes fast, the UX is utilitarian, and if you need instant propagation, the polling model is a hard constraint. Also the strongest OpenFeature citizen on this list, with the most provider entries in the ecosystem directory.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; you want flat prices, every SDK imaginable, and boring reliability. &lt;strong&gt;Skip it if:&lt;/strong&gt; realtime propagation or more than 10 free flags matter to you.&lt;/p&gt;

&lt;h2&gt;
  
  
  &lt;a href="https://www.harness.io" rel="noopener noreferrer"&gt;Harness FME&lt;/a&gt; (formerly Split)
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgscf30kgjfqfup2ez0sl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgscf30kgjfqfup2ez0sl.png" alt="Harness FME individual targets and treatment distribution" width="800" height="407"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;What Split became. The deterministic bucketing is nicely documented: user ID plus a per-flag seed get hashed into one of 100 buckets, so a 10% rollout covers buckets 0-9 and expanding to 30% just extends the range. Users never flip mid-rollout. There's also a "limit exposure" gate that buckets users out of targeting entirely, which is how you run clean experiments.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Targeting:&lt;/strong&gt; user-level, anonymous (cookie/device ID), or account-level. Their docs even flag the footgun: a 50/50 split by account can skew badly if one enterprise account holds thousands of users.&lt;/p&gt;

&lt;p&gt;For user sets, you get individual user IDs, attribute-based rules, and three segment flavors (standard, large, rule-based). One caveat buried in their docs: server-side SDKs don't support large segments and return the control treatment for flags that use them - check your SDK mix before building on those.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Real-time behavior:&lt;/strong&gt; client SDKs evaluate locally from a cached rollout plan (10-day default cache expiry on mobile/JS). And here's the honest part from their own docs: when you change a flag in the UI, mobile and browser SDKs "may not reflect the update immediately for all users," with devices syncing gradually over the following days unless you gate on the SDK_READY event. For a kill switch, that's a design consideration, not a footnote.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Watch out for:&lt;/strong&gt; there's no standalone product anymore. There's a free plan at signup, but anything real is a &lt;a href="https://www.harness.io/pricing" rel="noopener noreferrer"&gt;contact-sales MAU contract&lt;/a&gt; inside the Harness platform. If you're already a Harness shop, it's a natural add; if you're not, procurement is the price of entry. On transparency: Harness engineering has published at least one &lt;a href="https://medium.com/harness-engineering/0620-harness-production-incident-due-to-cloudflare-outage-e8ddbba0ce35" rel="noopener noreferrer"&gt;production-incident postmortem&lt;/a&gt; (a June 2022 Cloudflare outage) on their blog.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick it if:&lt;/strong&gt; your company already runs Harness. &lt;strong&gt;Skip it if:&lt;/strong&gt; you wanted standalone Split - that product no longer exists.&lt;/p&gt;

&lt;h2&gt;
  
  
  One layer up: OpenFeature
&lt;/h2&gt;

&lt;p&gt;Whatever you pick, integrate through OpenFeature. It's a CNCF incubating project: one vendor-neutral flagging API, with providers that adapt it to each backend. The ecosystem directory currently lists over 200 providers across 18 SDKs. ConfigCat, Flagsmith, LaunchDarkly, Split, and Unleash all maintain official providers; ConfigBee ships an &lt;a href="https://docs.configbee.com/openfeature-providers/web/" rel="noopener noreferrer"&gt;official web provider&lt;/a&gt;; several others have community coverage.&lt;/p&gt;

&lt;p&gt;The pitch writes itself after the last two years: Split's users woke up inside Harness, Statsig's users woke up inside OpenAI. An OpenFeature integration means your next migration is a provider swap, not a refactor.&lt;/p&gt;

&lt;p&gt;In practice it looks like this (web SDK, but every language follows the same shape):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;OpenFeature&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;@openfeature/web-sdk&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;ConfigbeeWebProvider&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;configbee-openfeature-provider-web&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;// Swap this provider for a Flagsmith, ConfigCat, or LaunchDarkly one&lt;/span&gt;
&lt;span class="c1"&gt;// and the rest of your app never changes.&lt;/span&gt;
&lt;span class="nx"&gt;OpenFeature&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setProvider&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nc"&gt;ConfigbeeWebProvider&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;accountId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;...&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;projectId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;...&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;environmentId&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;...&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;
&lt;span class="p"&gt;}));&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;client&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;OpenFeature&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;getClient&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;showNewUI&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;client&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;getBooleanValue&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;new-ui&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;One provider line is the whole vendor lock-in. The day your tool gets acquired, you change that line and go back to work.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd pick, by situation
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Solo dev / indie, watching dollars:&lt;/strong&gt; ConfigCat free (if 10 flags is enough), Statsig free (if you'll experiment), ConfigBee free (if runtime config is the actual need).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Startup shipping web + mobile:&lt;/strong&gt; ConfigBee or Flagsmith, depending on whether config or flags dominate your changes. Both stay under $100/mo at honest startup scale.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Must self-host:&lt;/strong&gt; Unleash or Flagsmith. PostHog if you want analytics in the same box.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Kill-switch speed is the requirement:&lt;/strong&gt; LaunchDarkly or ConfigBee (realtime updates), not a polling tool.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Delivery uptime is the requirement:&lt;/strong&gt; ConfigBee's written 99.99% SLA on flag/config delivery is the strongest published commitment here; LaunchDarkly and Unleash offer 99.9-99.99% uptime commitments at enterprise tiers. Compare contract terms, not landing pages - how each SLA defines "downtime" matters more than the headline number.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Already on PostHog or Harness:&lt;/strong&gt; use what you have. PostHog flags are nearly free to add; FME is a natural module.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Experimentation-first product team:&lt;/strong&gt; Statsig, eyes open on the ownership question.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enterprise governance with budget:&lt;/strong&gt; LaunchDarkly or Unleash Cloud. Do the MAU and seat math twice before signing.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The verdict: category winners and an overall pick
&lt;/h2&gt;

&lt;p&gt;Everything above this line is evidence. This section is opinion built from it. Categories first, overall call last.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best free tier: Statsig.&lt;/strong&gt; Unlimited flag and config checks, 2M events, unlimited seats, no card. Nothing else on this list is close on pure free-tier generosity. The asterisk you already know: OpenAI ownership, and the free ride is the top of an experimentation funnel.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best budget pick: Flagsmith.&lt;/strong&gt; $45/mo entry with unlimited flags and environments, and the open source edition underneath as an escape hatch if the meter ever annoys you. The cheapest credible way to run flags seriously.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best open source / self-host: Unleash.&lt;/strong&gt; Mature, flag-puritan, and the only tool here that treats flag debt as a first-class problem with lifecycle tracking and stale-flag dashboards. Flagsmith is the runner-up and the better pick if you want remote config values in the same box.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best enterprise platform: LaunchDarkly.&lt;/strong&gt; Approvals, workflows, custom roles, 30 SDKs, streaming kill switches, and a decade of enterprise scars. If procurement is involved and budget isn't the constraint, this is still the safe answer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for experimentation-first teams: Statsig.&lt;/strong&gt; Gates feed straight into a real stats engine with Pulse readouts at every rollout step. Harness FME inherits Split's strong experimentation DNA, but only inside an enterprise contract.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best if you're already in an ecosystem: PostHog / Harness FME.&lt;/strong&gt; PostHog users get flags nearly free against analytics they already trust. Harness shops get FME as a module. Ecosystem gravity is real; don't fight it without a reason.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best availability commitment: ConfigBee.&lt;/strong&gt; A written 99.99% SLA on flag and config delivery, with a credit ladder, at self-serve prices. Multi-cloud, multi-CDN, automatic endpoint fallback. The definition caveats from earlier apply, but nobody else on this list puts contract-backed availability on the table at $0-60/mo.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Best for runtime config: ConfigBee.&lt;/strong&gt; The only tool built around dynamic configuration as a first-class product rather than a flag's payload. Typed configs, contextual targeting, five rollout strategies, realtime updates on every tier. This category is the article's whole point, and right now it has one serious occupant.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Overall winner, for a new project starting today: ConfigBee - with the weighting on the table.&lt;/strong&gt; If you weight what a fresh web or mobile product needs in 2026 - unlimited flags and configs on the free tier, realtime updates without an enterprise plan, visitor and context rollouts, a written SLA, $60/mo entry, no seat tax - it wins on the evidence in this article. If you weight track record, backend SDK breadth, or self-hosting higher, the call flips: Unleash for infrastructure-heavy teams, Statsig if experimentation is the center of gravity, LaunchDarkly if governance is. That's the honest shape of this market: the overall winner depends on what you're optimizing for, and anyone who tells you otherwise is selling something. Including, possibly, me - so check the sources and argue in the comments.&lt;/p&gt;

&lt;h2&gt;
  
  
  The gap nobody's covering
&lt;/h2&gt;

&lt;p&gt;Every incumbent still treats config as an afterthought: a string value on a flag. But ask any team running a production app what changes more often - features, or the limits, thresholds, copy, and settings that shape them? Flags won the tooling war years ago. Runtime config, delivered in realtime and targeted like a flag, is where the interesting work is now, and most of this market hasn't noticed.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is the best feature flag tool in 2026?&lt;/strong&gt;&lt;br&gt;
There is no single best tool; it depends on what you optimize for. For a new web or mobile project, ConfigBee is my overall pick (unlimited flags on the free tier, realtime updates on every plan, written 99.99% delivery SLA, $60/mo entry). For self-hosting, Unleash. For experimentation-led teams, Statsig. For enterprise governance, LaunchDarkly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which feature flag tool has the best free tier?&lt;/strong&gt;&lt;br&gt;
Statsig: unlimited flag and config checks, 2M analytics events a month, unlimited seats, no credit card. ConfigBee's free tier is the runner-up for config-heavy apps (unlimited flags and dynamic configs, 500 monthly active visitors), and ConfigCat's works if 10 flags cover you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is Split still a feature flag tool?&lt;/strong&gt;&lt;br&gt;
Not as a standalone product. Harness acquired Split in June 2024 and folded it into Harness FME (Feature Management and Experimentation), sold as an enterprise module. The old split.io pricing page redirects to Harness.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's the difference between feature flags and runtime config?&lt;/strong&gt;&lt;br&gt;
Feature flags toggle code paths on and off. Runtime config changes values - limits, thresholds, copy, settings - without redeploying. Most flag tools bolt config on as a flag's payload; ConfigBee is the only tool here built around config as a first-class product.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which feature flag tools support OpenFeature?&lt;/strong&gt;&lt;br&gt;
ConfigCat, Flagsmith, LaunchDarkly, Split/Harness, and Unleash maintain official OpenFeature providers, and ConfigBee ships an official web provider. Statsig and PostHog rely on thinner community coverage. Integrating through OpenFeature keeps any future migration to a one-line provider swap.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How fast do flag changes reach users?&lt;/strong&gt;&lt;br&gt;
It varies more than vendors admit. LaunchDarkly and ConfigBee push changes to connected clients in milliseconds. Flagsmith offers realtime updates only on Enterprise. Unleash, Statsig, and ConfigCat poll or cache on intervals (ConfigCat's default is 60 seconds). Harness FME's own docs say cached mobile and browser sessions can take days to see an update unless you gate on SDK_READY.&lt;/p&gt;




&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;LaunchDarkly: &lt;a href="https://launchdarkly.com" rel="noopener noreferrer"&gt;https://launchdarkly.com&lt;/a&gt; | &lt;a href="https://launchdarkly.com/pricing/" rel="noopener noreferrer"&gt;https://launchdarkly.com/pricing/&lt;/a&gt; | &lt;a href="https://status.launchdarkly.com" rel="noopener noreferrer"&gt;https://status.launchdarkly.com&lt;/a&gt; | &lt;a href="https://launchdarkly.com/blog/what-happened-what-we-learned-and-how-were-improving/" rel="noopener noreferrer"&gt;https://launchdarkly.com/blog/what-happened-what-we-learned-and-how-were-improving/&lt;/a&gt; | &lt;a href="https://launchdarkly.com/docs/home/releases/percentage-rollouts" rel="noopener noreferrer"&gt;https://launchdarkly.com/docs/home/releases/percentage-rollouts&lt;/a&gt; | &lt;a href="https://docs.launchdarkly.com/sdk/features/flag-changes/" rel="noopener noreferrer"&gt;https://docs.launchdarkly.com/sdk/features/flag-changes/&lt;/a&gt; | &lt;a href="https://docs.launchdarkly.com/sdk/concepts/flag-evaluation-rules/" rel="noopener noreferrer"&gt;https://docs.launchdarkly.com/sdk/concepts/flag-evaluation-rules/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Flagsmith: &lt;a href="https://flagsmith.com" rel="noopener noreferrer"&gt;https://flagsmith.com&lt;/a&gt; | &lt;a href="https://www.flagsmith.com/pricing" rel="noopener noreferrer"&gt;https://www.flagsmith.com/pricing&lt;/a&gt; | &lt;a href="https://status.flagsmith.com/incidents/d4yndjchgq8s" rel="noopener noreferrer"&gt;https://status.flagsmith.com/incidents/d4yndjchgq8s&lt;/a&gt; | &lt;a href="https://docs.flagsmith.com/managing-flags/rollout/rollout-by-percentage" rel="noopener noreferrer"&gt;https://docs.flagsmith.com/managing-flags/rollout/rollout-by-percentage&lt;/a&gt; | &lt;a href="https://docs.flagsmith.com/managing-flags/rollout/rollout-by-attribute" rel="noopener noreferrer"&gt;https://docs.flagsmith.com/managing-flags/rollout/rollout-by-attribute&lt;/a&gt; | &lt;a href="https://docs.flagsmith.com/performance/real-time-flags" rel="noopener noreferrer"&gt;https://docs.flagsmith.com/performance/real-time-flags&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Unleash: &lt;a href="https://www.getunleash.io" rel="noopener noreferrer"&gt;https://www.getunleash.io&lt;/a&gt; | &lt;a href="https://www.getunleash.io/pricing" rel="noopener noreferrer"&gt;https://www.getunleash.io/pricing&lt;/a&gt; | &lt;a href="https://unleash.instatus.com/clk5wufah178390o8of4yev1xrd" rel="noopener noreferrer"&gt;https://unleash.instatus.com/clk5wufah178390o8of4yev1xrd&lt;/a&gt; | &lt;a href="https://docs.getunleash.io/sdks" rel="noopener noreferrer"&gt;https://docs.getunleash.io/sdks&lt;/a&gt; | &lt;a href="https://docs.getunleash.io/concepts/activation-strategies" rel="noopener noreferrer"&gt;https://docs.getunleash.io/concepts/activation-strategies&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Statsig: &lt;a href="https://www.statsig.com" rel="noopener noreferrer"&gt;https://www.statsig.com&lt;/a&gt; | &lt;a href="https://www.statsig.com/pricing" rel="noopener noreferrer"&gt;https://www.statsig.com/pricing&lt;/a&gt; | &lt;a href="https://status.statsig.com/incidents/mfzybgjxdqkq" rel="noopener noreferrer"&gt;https://status.statsig.com/incidents/mfzybgjxdqkq&lt;/a&gt; | &lt;a href="https://docs.statsig.com/feature-flags/conditions" rel="noopener noreferrer"&gt;https://docs.statsig.com/feature-flags/conditions&lt;/a&gt; | &lt;a href="https://docs.statsig.com/feature-flags/overview" rel="noopener noreferrer"&gt;https://docs.statsig.com/feature-flags/overview&lt;/a&gt; | &lt;a href="https://openai.com/index/vijaye-raji-to-become-cto-of-applications-with-acquisition-of-statsig/" rel="noopener noreferrer"&gt;https://openai.com/index/vijaye-raji-to-become-cto-of-applications-with-acquisition-of-statsig/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;PostHog: &lt;a href="https://posthog.com" rel="noopener noreferrer"&gt;https://posthog.com&lt;/a&gt; | &lt;a href="https://posthog.com/pricing" rel="noopener noreferrer"&gt;https://posthog.com/pricing&lt;/a&gt; | &lt;a href="https://posthog.com/handbook/company/post-mortems/2025-10-21-feature-flags-recurring-outages" rel="noopener noreferrer"&gt;https://posthog.com/handbook/company/post-mortems/2025-10-21-feature-flags-recurring-outages&lt;/a&gt; | &lt;a href="https://posthog.com/docs/feature-flags" rel="noopener noreferrer"&gt;https://posthog.com/docs/feature-flags&lt;/a&gt; | &lt;a href="https://posthog.com/docs/feature-flags/targeting-groups" rel="noopener noreferrer"&gt;https://posthog.com/docs/feature-flags/targeting-groups&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;ConfigCat: &lt;a href="https://configcat.com" rel="noopener noreferrer"&gt;https://configcat.com&lt;/a&gt; | &lt;a href="https://www.configcat.com/pricing/" rel="noopener noreferrer"&gt;https://www.configcat.com/pricing/&lt;/a&gt; | &lt;a href="https://configcat.com/blog/2021/10/08/ddos-recap/" rel="noopener noreferrer"&gt;https://configcat.com/blog/2021/10/08/ddos-recap/&lt;/a&gt; | &lt;a href="https://status.configcat.com/" rel="noopener noreferrer"&gt;https://status.configcat.com/&lt;/a&gt; | &lt;a href="https://configcat.com/docs/advanced/caching/" rel="noopener noreferrer"&gt;https://configcat.com/docs/advanced/caching/&lt;/a&gt; | &lt;a href="https://configcat.com/docs/targeting/percentage-options" rel="noopener noreferrer"&gt;https://configcat.com/docs/targeting/percentage-options&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Harness FME: &lt;a href="https://www.harness.io" rel="noopener noreferrer"&gt;https://www.harness.io&lt;/a&gt; | &lt;a href="https://www.harness.io/pricing" rel="noopener noreferrer"&gt;https://www.harness.io/pricing&lt;/a&gt; | &lt;a href="https://medium.com/harness-engineering/0620-harness-production-incident-due-to-cloudflare-outage-e8ddbba0ce35" rel="noopener noreferrer"&gt;https://medium.com/harness-engineering/0620-harness-production-incident-due-to-cloudflare-outage-e8ddbba0ce35&lt;/a&gt; | &lt;a href="https://status.harness.io/" rel="noopener noreferrer"&gt;https://status.harness.io/&lt;/a&gt; | &lt;a href="https://developer.harness.io/docs/feature-management-experimentation/feature-management/" rel="noopener noreferrer"&gt;https://developer.harness.io/docs/feature-management-experimentation/feature-management/&lt;/a&gt; | &lt;a href="https://developer.harness.io/docs/feature-management-experimentation/feature-management/targeting/target-segments" rel="noopener noreferrer"&gt;https://developer.harness.io/docs/feature-management-experimentation/feature-management/targeting/target-segments&lt;/a&gt; | &lt;a href="https://developer.harness.io/docs/feature-management-experimentation/sdks-and-infrastructure/client-side-sdks/" rel="noopener noreferrer"&gt;https://developer.harness.io/docs/feature-management-experimentation/sdks-and-infrastructure/client-side-sdks/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;ConfigBee: &lt;a href="https://configbee.com" rel="noopener noreferrer"&gt;https://configbee.com&lt;/a&gt; | &lt;a href="https://configbee.com/pricing" rel="noopener noreferrer"&gt;https://configbee.com/pricing&lt;/a&gt; | &lt;a href="https://blog.configbee.com/2025/10/20/configbee-status-update-aws-us-east-1-outage-october-20-2025/" rel="noopener noreferrer"&gt;https://blog.configbee.com/2025/10/20/configbee-status-update-aws-us-east-1-outage-october-20-2025/&lt;/a&gt; | &lt;a href="https://configbee.com/reliability/" rel="noopener noreferrer"&gt;https://configbee.com/reliability/&lt;/a&gt; | &lt;a href="https://configbee.com/sla/" rel="noopener noreferrer"&gt;https://configbee.com/sla/&lt;/a&gt; | &lt;a href="https://docs.configbee.com/fair-usage-policy/" rel="noopener noreferrer"&gt;https://docs.configbee.com/fair-usage-policy/&lt;/a&gt; | &lt;a href="https://docs.configbee.com/rollout-type-support/" rel="noopener noreferrer"&gt;https://docs.configbee.com/rollout-type-support/&lt;/a&gt; | &lt;a href="https://docs.configbee.com/sdk-capability-matrix/" rel="noopener noreferrer"&gt;https://docs.configbee.com/sdk-capability-matrix/&lt;/a&gt; | &lt;a href="https://docs.configbee.com/openfeature-providers/web/" rel="noopener noreferrer"&gt;https://docs.configbee.com/openfeature-providers/web/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;OpenFeature: &lt;a href="https://openfeature.dev/" rel="noopener noreferrer"&gt;https://openfeature.dev/&lt;/a&gt; | &lt;a href="https://openfeature.dev/ecosystem" rel="noopener noreferrer"&gt;https://openfeature.dev/ecosystem&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Prices and capabilities verified against official sources in September 2026. Vendors move fast; check the current pages before you commit.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Which of these are you running in production, and what did I get wrong about it? The best part of writing these is the comment section correcting me - have at it.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>featureflags</category>
      <category>devops</category>
      <category>webdev</category>
      <category>programming</category>
    </item>
    <item>
      <title>The night our rollback made things worse</title>
      <dc:creator>Travis Wheatley</dc:creator>
      <pubDate>Mon, 07 Sep 2026 13:19:06 +0000</pubDate>
      <link>https://dev.to/traviswheatley/the-night-our-rollback-made-things-worse-32oh</link>
      <guid>https://dev.to/traviswheatley/the-night-our-rollback-made-things-worse-32oh</guid>
      <description>&lt;p&gt;A few years ago I was the on-call engineer when we shipped what should have been a boring Thursday afternoon deploy. It turned into the incident that changed how I think about rollbacks, and I've never trusted the big red button since.&lt;/p&gt;

&lt;p&gt;Here's the story, then the lessons.&lt;/p&gt;

&lt;h2&gt;
  
  
  The deploy
&lt;/h2&gt;

&lt;p&gt;The change was ordinary: a new field on the orders table, an API endpoint that used it, and a migration that added the column as &lt;code&gt;NOT NULL&lt;/code&gt; with a default. We'd done fifty deploys like it. CI green, review approved, staging fine.&lt;/p&gt;

&lt;p&gt;The deploy went out at 6:40 PM. By 6:47, error rates on the checkout path were climbing. Not a spike, a slope - the kind of graph where you watch it for ninety seconds hoping it's a blip, and it isn't.&lt;/p&gt;

&lt;p&gt;The on-call playbook said what every playbook says: when in doubt, roll back. So at 6:55 we rolled back.&lt;/p&gt;

&lt;h2&gt;
  
  
  The rollback
&lt;/h2&gt;

&lt;p&gt;The application servers went back to the previous release in about four minutes. Error rates did not go back with them. They got worse.&lt;/p&gt;

&lt;p&gt;The reason took us twenty painful minutes to see, and it's obvious in hindsight: the migration had already run. The new column existed. Worse, the new code had been writing to it for fifteen minutes, and a backfill job we'd helpfully included had rewritten a few hundred thousand rows into a shape the old code didn't expect.&lt;/p&gt;

&lt;p&gt;Rolling back restored the code. It did nothing to the state. The old binary was now running against a database that had moved on, and every request that touched the affected rows failed in a new and exciting way.&lt;/p&gt;

&lt;p&gt;We'd pressed the button marked "make it like it was." The button was lying.&lt;/p&gt;

&lt;h2&gt;
  
  
  The recovery
&lt;/h2&gt;

&lt;p&gt;What actually saved us was rolling forward. We redeployed the broken release (the thing causing the original slope), then shipped a narrow fix for the actual bug, which turned out to be a missed null check in the new endpoint. Total customer impact: about 70 minutes. Time spent making it worse with the rollback: about 25 of those.&lt;/p&gt;

&lt;p&gt;In the review the next morning, someone asked the question that reframed the whole incident: "When did we last practice a rollback against a database that had already migrated?" The answer was never. We drilled application rollbacks constantly. We had never once rehearsed what happens to the data.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we changed
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;1. We stopped treating rollback as the safe default.&lt;/strong&gt; Rollback is a tool with a blast radius, not an undo key. It restores code, not state. Any deploy that touches state - schema, queues, caches, config formats - has to answer "what does the old version do against the new state?" before it ships, not at 6:55 PM.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Migrations became expand-contract, no exceptions.&lt;/strong&gt; Never change meaning and structure in the same deploy. First deploy expands: add the new column as nullable, or add the new table, and ship code that writes both. A later deploy migrates and backfills. A third contracts: drop the old shape once nothing reads it. Every intermediate state is safe for both old and new code, which means rollback stays boring at every step. That's the entire trick: keep every deploy reversible by making sure the state never outruns the code in a way the code can't survive.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. The &lt;code&gt;NOT NULL&lt;/code&gt; with a default got banned on hot tables.&lt;/strong&gt; On a big table, that migration rewrites rows or holds locks, depending on your engine and version. New columns start nullable or get a separate backfill. This one rule would have prevented our exact failure.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. We rehearsed the bad path.&lt;/strong&gt; Once a quarter, in staging, we now run the drill: deploy a change with a migration, then roll back and watch what breaks. The first time we did it, three things broke. Better there than in production. A rollback you've never tested is a hope, not a plan.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Deploy and release got separated.&lt;/strong&gt; Where it made sense, risky behavior moved behind configuration we could flip without a deploy, so "turn it off" stopped meaning "ship old code and pray the state is compatible." Even a crude version of this beats a heroic rollback.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part that stuck with me
&lt;/h2&gt;

&lt;p&gt;The failure that night wasn't the bug. Bugs ship; that's what on-call is for. The failure was that our safety mechanism had a hidden precondition - state compatibility - that nobody had written down, tested, or even said out loud. It worked in every drill because the drills never included a database.&lt;/p&gt;

&lt;p&gt;I still roll back deploys. But now the question comes first: what state has this release already touched, and can the previous version live with it? If the answer is "I don't know," the rollback isn't the safe option. It's just the familiar one.&lt;/p&gt;

&lt;p&gt;What's your worst rollback story? I collect these - every team has one, and they're never in the postmortem template.&lt;/p&gt;

</description>
      <category>devops</category>
      <category>sre</category>
      <category>cicd</category>
      <category>backend</category>
    </item>
  </channel>
</rss>
