Every December we stopped deploying. The freeze ran from the first week of the month until the middle of January, six weeks in which nothing shipped, and the reasoning behind it was entirely sound. The business was at its busiest, half the staff were on leave, and an outage during peak trading would have been genuinely expensive. I never argued against any of that. What I came to argue against was what happened in the third week of January, every single year.
The work did not stop during the freeze. It accumulated. Six weeks of changes from four teams queued up behind a closed gate, and when the gate opened they went out over a fortnight. Every one of them had been written and tested in isolation against a codebase that had since moved underneath it, and none of them had been tested against each other, because until release week they had never existed in the same place at the same time. We had bought the safest six weeks of the year by paying for them with the most dangerous fortnight of the year, and our own incident numbers said so clearly to anyone who bothered to plot them by month.
That is the part a freeze hides. It does not remove risk, it stores it, and stored risk compounds. A single small change is easy to reason about and easy to reverse. Forty changes released together are a system you have never actually run before, and when something breaks you are not rolling back a deployment, you are trying to work out which of forty things you need to unpick while the business watches. The freeze also quietly degrades the machinery you depend on, because a pipeline nobody has exercised for six weeks has usually rotted in some small way that only reveals itself under pressure.
What I ask for now is a freeze with a shape rather than a wall. Genuinely high-risk work stops, and stops properly. Low-risk, well-understood, easily reversible changes keep flowing at a reduced pace, partly to keep the batch small and partly to keep the release path warm and proven. The criteria are written down in advance so nobody is negotiating them at the worst moment.
A freeze is not an absence of risk. It is a decision about when you would prefer to face it.
– Serguey Shinder
Top comments (0)