Commentary

What KISS means for service configuration

In brief

Feature flags and customer overrides show why a shorter configuration file can leave just as much behavior to investigate and support.

4 min read

Sources
A small opaque cover conceals part of an accordion of tabs while a transparent overlay reveals the rest.
Conceptual configuration view: moving overrides out of a short file does not remove their behavior; showing the effective configuration can make investigation easier.
On this page4 sections

A configuration file can get shorter while the service gets harder to operate. Consider a hypothetical cleanup that removes visible feature flags and moves the same behavior into customer-specific overrides in another service. The main file looks reassuringly simple. During an incident, however, the responder now needs another lookup and perhaps another team to discover what the application is doing.

This is where KISS, the “keep it simple” principle, becomes a practical engineering question. Which work became easier, and for whom? In reliability work, simplicity concerns the states and transitions people must understand, the evidence they can inspect and the recovery paths they must support. Moving a decision out of sight can improve an interface without reducing any of those obligations.

Ten flags can produce 1,024 combinations

A useful inventory begins with choices that change failure behavior, ownership, recovery or data compatibility. Ten independent binary flags permit up to 1,024 combinations. Constraints may make many of them unreachable, so the task is not automatically to test 1,024 cases. It is to identify which combinations the service actually supports and whether a responder can recognize them at runtime.

The moved customer override illustrates the difference. If it still produces the same distinct behavior, its support obligation survived the cleanup. An effective-configuration view can make that obligation easier to handle by showing inherited defaults together with overrides. A file containing only defaults cannot tell someone which value the running service ultimately uses.

Removing an unused override eliminates a behavior the team must support. Exposing an override in the effective-configuration view leaves the behavior in place but makes it easier to investigate. Both can simplify operations; the benefit comes from the states removed or the recovery and investigation work reduced, not simply from shortening the file.

Configuration choices multiply supported states
Configuration choices multiply supported states. Two independent binary flags produce four combinations; ten permit up to 1,024. Constraints may make some unreachable. Identify which supported combinations are tested and visible at runtime.
Two independent binary flags produce four combinations; ten permit up to 1,024. Constraints may make some unreachable. Identify which supported combinations are tested and visible at runtime.
Read diagram description

Two independent binary flags produce four combinations; ten permit up to 1,024. Constraints may make some unreachable. Identify which supported combinations are tested and visible at runtime. Rows show flag B off and on; columns show flag A off and on. The four cells are all combinations of the two flags.

An exception needs a way to end

Some differences are temporary because a customer or migration still depends on them. Their lifecycle becomes manageable when the record identifies that dependency, the person responsible for it, the intended expiry and the condition that permits removal. The migration path explains how the exception can disappear without abandoning its users.

That investigation also guards against an overenthusiastic cleanup. Two storage paths might duplicate effort, or one might provide a deliberate recovery boundary. Consolidating them is a different decision in each case. Necessary customer or migration behavior should remain when its benefit justifies its cost; make the effective state visible and test the supported combinations rather than delete capability for a simpler diagram.

Automation can reduce the work of managing the remaining complexity. Its value depends partly on what happens when it stops halfway. If a workflow exposes which operations completed and which did not, the responder can continue from that state. A single failure label covering several unresolved operations conceals the very detail recovery needs.

Retirement has a similar halfway problem. Nobody may have a flag enabled while old messages, stored records or scheduled jobs still depend on its former behavior. Before removing the recovery path, establish how those objects will be handled. Otherwise a later replay can bring back a state the team believes it has retired.

Rollback can leave newly written data behind

A proposed configuration change should explain what behavior it adds, how an operator will recognize it and which transitions are allowed. Rollback deserves particular attention when the new state produces data: returning the setting to its old value may leave data whose interpretation has changed. Consider combinations with existing modes that affect the same resource or lifecycle.

A canary process can exercise the supported behavior for a bounded population. When testing is sampled, the review should identify what the sample covers instead of letting a successful run imply exhaustive coverage. Consequential combinations that remain unverified can stay visible in the risk registry, where their cost and uncertainty can inform a later decision.

Retiring the customer override

Once an override’s consumers are understood, its retirement can proceed as a migration. Observed use identifies who still depends on it; moving a limited population gives the team a chance to examine normal operation and recovery before expansion. The previous path remains available while it is a valid rollback option, then can be removed when the agreed retirement condition is met.

After the migration, the customer override should either be gone or have a visible support path. In the first case, there is one less variant to maintain. In the second, a responder can discover the effective value without chasing another team. Those are concrete gains from simplification even when the final configuration still has plenty of lines.

Source context

This article does not include external reference links. Read it as the author’s perspective and evaluate the guidance against your environment.

Report an error or outdated detail

Related reading

Explore a related question