blog articles

How Do You QA a Network Change?

Network change management QA stages from config validation to post-change verification

How Do You QA a Network Change?

Not review it. Not peer-check the config. Actually test it, the way software teams test a release before it ships.

In software this problem is largely solved. You have staging, CI pipelines, automated test suites, and a rollback that genuinely undoes what you did. In networking almost none of that holds.

Your staging environment is production. A lab reproduces topology, not traffic, not scale, not the specific hardware buffers, not the three legacy devices nobody wants to touch. You can validate syntax and you can validate intent, but validating behaviour under real load is where it falls apart.

And rollback is a comfortable word that hides a hard truth. You can restore a config. You cannot un-announce a prefix the internet already learned, un-drop the sessions that flapped, or un-deliver the ten minutes of degraded service your customers already experienced.

Everyone points to digital twins as the answer, and in principle they are right. In practice, building a twin that is close enough to be trustworthy is genuinely hard. It has to carry real topology, real state, real protocol behaviour, real timing, and stay in sync as the network changes underneath it. A twin that is 90 percent accurate is not a safety net. It is a false sense of one, and the 10 percent it misses is exactly where the incidents live.

So most operators fall back on process. Change windows, peer review, a documented rollback plan, someone senior watching. That is discipline, not QA. It reduces risk without ever telling you whether the change will actually do what you expect.

We are putting real time into this at the moment. We are building and testing a proper network change QA approach inside our own NOC first, on our own change workflow, before it goes anywhere near a customer. Once it is genuinely validated, it becomes part of HORA.

We are not claiming to have solved it. We are saying it is worth solving, and that the industry has been tolerating the gap for a long time.

So we are curious what others are doing. How do you QA a network change today? Lab, twin, canary deployment, staged rollout, or process and experienced people watching carefully? What actually works for you?