Toolkit core rollback safety when apps expect newer core version
0 reputation · 06 Mar 2022, 17:00 UTC
Context
ShotGrid (Autodesk Flow Production Tracking) applies server-side upgrades on a shared schedule with no customer rollback control. Recovery planning therefore centers on client-side Toolkit components: the versioned core API in the pipeline configuration's core folder and the pinned app/engine descriptors in environment YAML.
Unresolved decision
When a core upgrade causes import errors or apps fail to load, the Toolkit CLI can revert the core to a prior version. However, if apps have already been updated to descriptors that declare compatibility with the newer core, no guaranteed core-to-app compatibility matrix is published. The operator must choose between a core-only rollback and a full configuration rollback, and custom apps written against the newer core may not load under the older core even when the rollback itself succeeds.
Goal
Determine whether a core-only rollback is safe after apps have been upgraded to descriptors that expect the newer core, or whether a full configuration rollback is required to restore a working state.
Is a core-only rollback ever safe once app descriptors have been updated to require the newer core? What signals indicate that a full configuration rollback is necessary instead? How can an operator verify compatibility before committing to either rollback scope in a production pipeline?