--- name: rollback-plan description: "Write a concrete rollback plan for a risky change (deploy, migration, feature-flag flip, config rollout) so the reverse is one command away — not an improvised debate at 2am. Use when asked to write a rollback plan, back-out plan, revert plan, or 'what if we need to undo this'. Produces a rollback plan with the signals that trigger it, exact reverse commands, verification steps, data-safety notes, and a communications template." --- # Rollback Plan Skill Turns "we'll roll back if it goes bad" into a plan somebody unfamiliar with the change can execute under pressure. The single job: make the reverse of the change knowable, verifiable, and boring. ## Working from a brief Deliver the full plan even from a thin brief — infer and label assumptions (never invent service names, dashboard URLs, commit SHAs, or migration IDs). If a required input is missing, ask once, then move on with `unknown — confirm before rollout` placeholders. ## Required Inputs Ask for (if not already provided), else label as unknown: - **The change** — what's shipping, service(s) affected, blast radius. - **How it ships** — deploy pipeline, feature-flag key, migration ID, config path. - **Rollout shape** — big-bang, staged (X% → Y% → 100%), canary, region-by-region. - **Data implications** — does it write new schema/data, change the meaning of existing columns, backfill, encrypt-in-place, delete? Reversible in-place or one-way? - **Downstream consumers** — services / queues / clients that read the changed contract. - **Trigger conditions** — the SLIs / dashboards / alerts that would tell us it's bad (be specific: metric, threshold, duration). - **Who owns the decision** — the human who can pull the trigger, and their escalation path if unreachable. ## Output Format ```markdown # Rollback Plan — **Owner:** · **Approver for rollback:** · **Rollout window:** ## 1. The change (one paragraph) ## 2. Trigger conditions — roll back if ANY of these hold | Signal | Threshold | Window | Where to look | |---|---|---|---| | | 400ms> | | | Also roll back on any P1/P2 incident opened against during the window. ## 3. The reverse — exact steps, in order > Rehearse this in a lower environment before the change ships. The first time you run these under load should not be the real rollback. 1. **Announce** — post in `#` from the template in §7. 2. **Stop the rollout** — . - Command: `` - Verify: `` 3. **Revert the code / config** — . - Command: ` && …>` or `>` or `` - Verify: 4. **Data reversal** — : - Reversible in place: run `