Maintenance calendar (Carrier tier)¶
Single source of truth for upcoming maintenance windows referenced from carrier-noc-runbook.md §4. The customer email, calendar invite, and this document must not disagree; when they do, this file wins and the others are republished from it.
Status: stub — populated at the first Carrier go-live. Until then the recurring windows are governed by the static rules below.
Recurring windows (default schedule)¶
| Cadence | Slot (BRT) | Scope | Customer notice |
|---|---|---|---|
| Weekly | Tue 03:00–05:00 | Stateless deploys, image rebuilds, worker restarts. No schema migration. | Calendar listing only; no per-occurrence email. |
| Monthly | First Sun 02:00–06:00 | Schema migrations, RDS minor-version patching, PITR snapshot at T−15 min. | ≥ 14 calendar days before window start. |
| Quarterly | Published 30 days in advance | DR drills (RDS PITR restore, region failover dry-run, S3 replication validation). | ≥ 30 calendar days; Carrier-tier Grafana banner on the day. |
Emergency changes follow carrier-noc-runbook.md §4 and are not listed here in advance by definition; they are appended to the "Past windows" table below within 24 h of the change.
Upcoming windows¶
| Window start (UTC) | Window end (UTC) | Type | Scope summary | Approver | Customer notice sent | PR / change link |
|---|---|---|---|---|---|---|
| none scheduled |
Past windows¶
| Window start (UTC) | Window end (UTC) | Type | Scope | Outcome | Post-deploy verification link |
|---|---|---|---|---|---|
| none yet |
Update procedure¶
- Open a PR that edits only this file with the proposed entry (one row per window).
- Reviewer = engineering lead + account owner for Monthly/Quarterly; engineering lead alone for Weekly.
- On merge, the merger sends the customer email and the calendar invite from the same row text. No drift permitted.
- Cancelling a window inside its notice horizon: same approver(s) re-open the row, mark it
CANCELLED, and send the cancellation notice ≥ 6 h before original start.