Stress-test a schema migration before lock windows, dual-write plans, and rollback steps harden into what every consumer path will quote.
Schema migrations fail when the runbook invents lock speed production never had, when dual-write paths dual-count the same row as migrated and as legacy, when read consumers still lack a named owner, and when eng cannot show who decides after a partial cut. A neat migration diagram is not evidence.
Freeze the plan
One sentence for why the migration exists, which tables and consumers it covers, who owns lock windows, dual-write, and rollback, and the abort trigger if error rates or lock duration past a named threshold. Attach the schema diff, sample lock metrics, consumer inventory, and the measured path from freeze to restored reads. If platform, product, and data disagree on which consumers are truly covered, stop and reconcile first.
Name the decision you will make if the stress test finds nothing new, and the delay criteria if any money-path consumer still lacks a named migration owner or a verified rollback drill.
Attack surfaces
- Lock fiction: windows that look short while production still blocks past the drill.
- Dual-write blur: completeness claims that invent catch-up the secondary never showed.
- Consumer theater: "all readers updated" language that still lacks a named inventory.
- Rollback lag: steps that trail the customer-visible error rate.
- Partial-cut silence: failures that land without a decision owner or measured lag.
Optional SRE seat if multi-region cutovers bind the form. Optional support seat if status updates bind the form. Optional finance seat if billing tables bind the form.
How to run it
Feed Pingpong the draft migration plan, drill notes, and open risk list. Early passes steelman the cut design. Later passes attack from eng, platform, product, support, and skeptic seats. End with a pass that turns surviving objections into clearer owners, a timed rollback drill, or a hold. Delete invented "we already migrated cleanly" claims and dual-counted success rates.
Ask eng and product seats to price the behavior the published migration will invite. If day-one runbooks promise five-minute locks while the last drill stranded checkout for twenty, buyers will treat the plan as false. Write the intended tables, the consumer checks, and the language you will refuse, then attack whether trust still holds under that discipline.
When the migration coincides with a multi-region cutover or a billing change, force eng and support seats to map every claim that still assumes the old schema. Partner embeds, reporting jobs, and admin panels count. A migration that looks clean in a PDF while a critical reader still pins to legacy columns will fail on the first traffic wave. Related: stress-test a migration plan, stress-test a migration freeze, stress-test a multi-region cutover, pretend you are the CTO, and the war-game decisions hub. Process: how to run a Pingpong.