{ "schemaVersion": 1, "runbooks": { "FE-RB-001": { "title": "Boot configuration failure", "gateId": "FE-GATE-021", "triggerKinds": ["BOOT_CONFIG_FAILURE"], "containment": "stop product route mount, show the safe support shell, and refetch at most once", "window": "owner triage planned-default 5m", "escalation": ["env-config owner", "release owner"], "recoveryEvidence": [ "clean-session boot", "product root mount", "config validation", "no repeated boot error" ], "negativeFixture": "a valid config followed by an injected mount failure must fail recovery" }, "FE-RB-002": { "title": "Chunk, manifest, or deployment mismatch", "gateId": "FE-GATE-022", "triggerKinds": [ "CHUNK_LOAD_FAILURE", "RELEASE_MANIFEST_FAILURE", "DEPLOY_MISMATCH" ], "containment": "warn for dirty state, fetch manifest no-store once, and allow one guarded reload", "window": "release owner triage planned-default 5m", "escalation": ["release-cache owner", "hosting/CDN owner"], "recoveryEvidence": [ "entry and lazy assets reachable", "release tuple coherent", "second reload blocked", "critical route smoke" ], "negativeFixture": "a second failure for the same release pair must not reload" }, "FE-RB-003": { "title": "Backend API degradation", "gateId": "FE-GATE-023", "triggerKinds": [ "TERMINAL_NETWORK_RATE", "REQUEST_TIMEOUT_RATE", "SERVER_FAILURE_RATE", "SCHEMA_MISMATCH" ], "containment": "do not expand retry caps, serve safe stale reads, and never retry an unkeyed mutation", "window": "rolling 5m trigger; first classification planned-default 10m", "escalation": [ "api-client owner", "backend operation owner", "release compatibility owner" ], "recoveryEvidence": [ "terminal failure rate at baseline", "no retry amplification", "critical read/write smoke", "schema fixtures" ], "negativeFixture": "an unkeyed POST receiving 503 must not retry" }, "FE-RB-004": { "title": "Telemetry sink failure", "gateId": "FE-GATE-024", "triggerKinds": ["TELEMETRY_FAILURE"], "containment": "keep product flow available, bound the queue, and never report recursively to the failing sink", "window": "platform triage planned-default 15m", "escalation": ["observability owner", "telemetry platform owner"], "recoveryEvidence": [ "product flow unaffected", "delivery self-check", "queue drained within bound", "forbidden attributes absent" ], "negativeFixture": "raw URL and query data must be removed from telemetry" }, "FE-RB-005": { "title": "Coherent release rollback", "gateId": "FE-GATE-025", "triggerKinds": ["RELEASE_BLOCKING_DEFECT"], "containment": "select a prior immutable tuple, verify asset/config/API compatibility, atomically switch, and smoke", "window": "provider recovery target TBD", "escalation": ["release-cache owner", "release approver/hosting owner"], "recoveryEvidence": [ "compatibility gate", "release coherence gate", "critical smoke", "release ID in incident timeline" ], "negativeFixture": "HTML build A with asset manifest B must be rejected" } } }