Error budget policy — freeze, waiver and window roll
The error budget policy of a 99.9%/30-day service as a finite state machine — healthy, watch, exhausted, time-boxed VP waiver and window roll — with the guard on every transition, for the SRE and product owner who have to sign it.
Make it your own.
title "Error budget policy — checkout API, 99.9% over 30 days"
# b = share of the 30-day error budget still unspent. The budget is 43.2
# minutes of bad traffic; b is recomputed hourly from the burn-rate query.
state Healthy label "Healthy"
state Watch label "Watch"
state Exhausted label "Exhausted"
state Exemption label "Exemption"
state Retired final label "Retired"
initial Healthy
transition Healthy -> Healthy on "recompute" [b > 25%]
transition Healthy -> Watch on "recompute" [b <= 25%] / notify
transition Watch -> Watch on "recompute" [0 < b <= 25%]
transition Watch -> Healthy on "recompute" [b > 25%]
transition Watch -> Exhausted on "recompute" [b = 0] / freeze deploys
transition Exhausted -> Exemption on "waiver" [VP, 72 h] / log change
transition Exemption -> Exhausted on "waiver_expiry"
transition Exhausted -> Healthy on "window_roll" / b = 100%
transition Exemption -> Healthy on "window_roll" / b = 100%
transition Watch -> Healthy on "window_roll" / b = 100%
transition Healthy -> Retired on "slo_retired"