Part 7 · 1 chapters · ~8 min
Configuration as Code, Validation and Review
Treating configuration changes as deploys: config in Git with schemas, CI validation and policy checks, review and approval rules for risky keys, canarying config by region or percentage, versioning and instant rollback, and audit trails.
12
Config changes are deploys
code
# config/ledger.prod.yaml, validated in CI against a JSON Schema and policy
transfer:
daily_limit_kobo: 20000000 # schema: integer, 100000..100000000
per_country:
NG: { daily_limit_kobo: 20000000 }
KE: { daily_limit_kobo: 15000000 }
fees:
bps: 15 # policy: changes to fees require 2 approvals from #payments-owners
# CI steps
1 schema validation (ajv / cue / conftest)
2 policy: who may change which keys (CODEOWNERS per path)
3 diff summary posted on the PR ("NG daily limit 20,000,000 → 2,000,000 kobo: -90%")
4 deploy to one region or 5% of traffic, watch error rate and business metrics, then the rest
5 every applied version is recorded; rollback = apply the previous versionThe human-readable diff in step 3 is the cheapest safety net there is: a misplaced zero in a limit or fee is obvious when the PR says "-90%" next to it.