Skip to main content

Employee Cutover and Rollback

Summary

Gateway routing can move Employee-owned compatibility prefixes between the monolith and Employee Service, but current configuration keeps Employee cutover inactive and identifier parity is incomplete.

Audience

  • Gateway/Employee owners, DevOps engineers, QA engineers, architects, and product owners

Cutover/rollback flow

Confirmed boundaries

The gateway defines Employee-owned route prefixes, an extracted-service cluster, route-source reporting, and shadow routing. Employee compatibility endpoints preserve field names but use GUID identifiers and reject numeric Legacy identifiers.

Approval and evidence

Cutover needs UI/API contract parity, safe shadow evidence, tenant/auth checks, data ownership, migration readiness, outbox expectations, support coverage, and approved rollback/reconciliation criteria. Exact toggle names, infrastructure targets, and production commands are intentionally omitted.

Rollback limitations

Routing rollback does not reverse migrations or writes already accepted by either store. No Employee-specific rollback or reconciliation automation was found. Data disposition and recovery approvals Require confirmation.

Source References

  • microservices/src/gateway-api/Program.cs
  • microservices/src/employee-service/Api/EmployeeCompatibilityEndpoints.cs
  • microservices/src/employee-service/docs/employee-compatibility-placeholders.md
  • docs/production-configuration.md

See Also

Keywords

  • gateway cutover
  • routing rollback
  • shadow validation

Revision Information

  • Status: Draft
  • Last reviewed: 2026-07-15
  • Review cycle: Quarterly