Vol. 01 — 2026

October Code Freeze: Ship Safe Before Diwali Rush [2026]

Answer in 50 Words

Freeze feature deploys two weeks before the Diwali rush, pin every dependency, rehearse rollback, and load-test at 3x traffic. My Junagadh checklist held P95 at 48ms through last festive season with zero hotfixes. Dates, runbook, and the exception process below.

October code freeze operations diagram showing deploy lock dependency pins rollback runbook and 3x load test for festive traffic 2026

I run SaaS Next from Junagadh, Gujarat. Festive traffic forgives nothing. Last October I watched a perfectly good catalog fall over for reasons that had zero to do with code quality and everything to do with timing. Since then every client on my care plan gets the same October treatment: freeze, pin, rehearse, monitor. Here is the full routine.

War Story 1: The Deploy That Ate Checkout

Oct 24, 2025, 11:20. A client approved a "small" checkout-label change for their festive sale. Small meant a Laravel minor bump bundled in the same release. The bump changed a queue retry default. Under 3x festive load, failed UPI webhooks retried aggressively, exhausted the Valkey connection pool, and checkout latency climbed from 90ms to 4 seconds. We rolled back at 11:55, but 35 minutes of peak traffic saw a 60% checkout completion rate instead of 92%. Estimated damage: ₹1.9L in abandoned carts. The label change shipped a week later with zero drama. The lesson stuck: no non-essential release touches production inside the rush window. Ever.

War Story 2: The Rollback That Took 4 Minutes

Same season, different client. Their slot-booking deploy carried a migration that renamed a column the mobile app still read. Staging missed it because staging ran the new app build. Production still served the old one to 40% of users. Errors spiked at 09:05. Because we had rehearsed rollback the week before — snapshot verified, down-migration tested, Octane reload sequenced — production was healthy by 09:09. Four minutes. The client remembers the four minutes, not the bug. Rehearsal is the difference between an incident and a story.

The Freeze Calendar

Diwali 2026 lands early November. My dates:

Milestone Date Rule
Feature cutoff Oct 18 Last feature merge; only fixes after
Freeze begins Oct 20 No deploys except P0 fixes via exception
Rollback rehearsal Oct 22 Full restore drill on staging clone
Load test Oct 24 3x last-year peak, sustained 30 min
Freeze lifts 3 days after Diwali Post-mortem first, then resume

Exceptions need two approvals (mine + owner) and a written rollback line. In three seasons I have granted four exceptions. Two were genuine P0s. Two were "urgent" offers that waited fine until after the festival.

Pin Everything

Festive failures love moving targets. Lock file discipline:

# PHP — commit the lock, install exact
composer install --no-dev --optimize-autoloader --no-interaction
php artisan octane:reload

# Node — frozen installs only during freeze
npm ci
npm run build

My freeze rules: composer.lock and package-lock.json committed and untouchable without exception approval. No ^ or ~ range resolves anything new — npm ci fails loudly instead of silently upgrading. Docker base images pinned by digest, not tag. The Oct 24 incident above was a range-resolved minor bump; pinned installs make that class impossible.

Backups You Have Restored (Or You Have None)

Untested backups are wishes. My rehearsal script runs Oct 22 on a staging clone:

# snapshot, verify, restore-drill
php artisan backup:run --only-db --only-to-disk=s3
pg_restore --list latest.dump | head -5   # sanity: dump parses
# restore to staging clone, boot, run smoke suite
php artisan test --filter=Smoke

Smoke suite covers login, catalog search, UPI intent creation, and slot booking — the four paths money flows through. If restore + smoke passes inside the target window (mine: 20 minutes), the runbook is real. Last year the drill caught an expired S3 credential on one client. Finding that Oct 22 instead of mid-rush paid for the whole ritual.

Load Test at 3x

Thirty minutes sustained at 3x last-year peak, not a 2-minute spike. My checklist: warm the pgvector index first (cold HNSW lies about latency), run the broadcast sequence concurrently (festive traffic is chatty, not just page views), and watch Valkey pool saturation — the Oct 24 failure mode. Targets I hold: P95 under 100ms on catalog reads, checkout completion above 90%, zero 500s. Last season's numbers on the ₹6,200/month VPS: P95 48ms at 3x, completion 93%. The box was never the bottleneck. The queue defaults were. I also replay the previous year's actual slowest hour from access logs instead of synthetic paths only, because real festive traffic mixes search, chat callbacks, and webhook retries in proportions no guess reproduces.

On-Call Without Burnout

Festive on-call covers 06:00–23:00 in two shifts (mine + one trained staff member per client). Rules: alerts page on error-rate or P95 breach, not on CPU wiggles. Every alert links its runbook line. Handoff happens in writing at shift change with three numbers: orders, error rate, P95. I cap my own festive roster at three clients so every page gets a fresh brain. Clients get my personal number for the fortnight — and the freeze means it almost never rings. The written handoff also records deploy state (frozen commit hash, exception log) so the incoming shift never wonders what changed overnight.

When NOT to Freeze

Do not freeze a pre-launch product with zero traffic — velocity matters more than safety before product-market fit. Do not freeze security patches; the exception path exists for exactly this, and last year I shipped two patched dependencies mid-freeze with rehearsed rollbacks standing by. And do not confuse freeze with neglect: monitoring gets stricter during freeze, not looser. Frozen code with blind eyes is just a slower way to fail. My dashboard keeps orders, error rate, and P95 on one screen through the fortnight, and any excursion past threshold pages a human within two minutes.

Frequently Asked Questions

When should the Diwali code freeze start?

Two weeks before peak traffic — Oct 20 for Diwali 2026, with feature cutoff Oct 18. Rollback rehearsal Oct 22, load test Oct 24. Lift three days after the festival once the post-mortem is written. Dates shift with your peak; the sequence does not.

What deploys are allowed during freeze?

P0 fixes only, with two approvals and a written rollback line. Security patches always qualify. Offer changes, label tweaks, and dependency bumps wait. My three-season count: four exceptions granted, two genuinely urgent.

How do you load-test for festive traffic?

Thirty minutes sustained at 3x last-year peak with a warm index, concurrent chat traffic, and pool monitoring. Hold P95 under 100ms on reads and checkout completion above 90%. My Junagadh reference: P95 48ms at 3x on the standard ₹6,200/month VPS.

What does festive ops coverage cost?

Inside my care plans: freeze management, rehearsal, load test, and fortnight on-call from ₹15K for the season on top of the build. Standalone for existing systems: ₹25K including the restore drill and runbook. Against a ₹1.9L abandoned-cart morning, the math is short.

Bottom Line

Festive revenue rewards the boring: freeze Oct 20, pin every dependency, restore-drill Oct 22, load-test Oct 24, watch P95 and error rate like a hawk. My Junagadh seasons read zero hotfixes and P95 48ms at 3x. Start the calendar this week — the rush will not wait for your deploy pipeline.

Cover it with me: web development for hardened storefronts, automation notes for chat + slot plumbing, AI development for search that holds under load, selected work, and contact for a festive ops slot.

← All journal articles Get in touch →