← docsInfrastructure

/network-engineering

Define and execute network engineering changes with explicit design evidence, validation s.

Define and execute network engineering changes with explicit design evidence, validation steps, and rollback readiness.

Category

Infrastructure

Execution

7 steps, sequential + gated

Goal

Define and execute network engineering changes with explicit design evidence, validation steps, and rollback readiness.

Scope

Applies to

  • +Design this network change
  • +Update routing/firewall rules
  • +Validate connectivity after infra change

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Design this network change""Update routing/firewall rules""Validate connectivity after infra change""Create network engineering workflow"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Every change must define blast radius and dependency boundaries before execution.
  • 02Validation commands must be explicit and reproducible.
  • 03Rollback path must be available before any state mutation.
  • 04Security boundaries (ACL, security groups, firewall policy) must remain least-privilege.

Procedure

  1. Step 1Step 1 — Capture current-state topology and intended target-state.
  2. Step 2Step 2 — Produce change plan with affected paths, ports/protocols, and dependency map.
  3. Step 3Step 3 — Define pre-change checks (reachability, DNS, latency, packet loss, route tables).
  4. Step 4Step 4 — Apply network changes in a controlled sequence aligned with `changeWindow`.
  5. Step 5Step 5 — Execute post-change validation commands and compare against pre-change baseline.
  6. Step 6Step 6 — If validation fails, execute rollback and record exact failure point.
  7. Step 7Step 7 — Produce a handoff report with final state and residual risks.

Outputs

  • ▸Network change plan artifact.
  • ▸Validation log (pre/post checks and outcomes).
  • ▸Rollback report (executed or confirmed-ready).
  • ▸Handoff summary for operations and documentation workflows.

Review Gate

  • [ ]Blast radius, dependencies, and security boundaries are explicit.
  • [ ]Pre and post validation commands are documented and executed.
  • [ ]Rollback path is complete and actionable.
  • [ ]Final state matches intended network intent.