CORA: Config Risk Analyzer --- Predicting Risk of Configuration Changes at Scale
This program is tentative and subject to change.
Configuration changes — modifications to feature flags and service parameters — are important to operating services, but they can cause severe outages (SEVs) with notable service disruption. While code diff risk prediction is well studied, configuration diff risk has received little attention. The code-oriented Diff Risk Score (DRS) model provides limited discriminatory power for config diffs because config risk stems not from code complexity but from the importance, blast radius, and operational readiness of the affected services. We describe the development of CORA (COnfig R}isk Analyzer), a dedicated risk model for config diffs. A notable insight is that the config-path-to-service mapping bridges from what changed to which services are affected, enabling risk assessment in terms of service criticality rather than code properties.
CORA evolved through three iterations. A logistic regression model with config-specific features achieved an 11% improvement in recall at 5% gating over the DRS model on config diffs. Used for a freeze period, it reduced config gating while outage impact decreased 16.4% and config diff landing volume increased 47.7%. A unified LightGBM model trained on Meta-wide data achieved a 25.95% improvement in recall at 10% gating, with organization-level improvements ranging from 15% to 66%. An enhanced model with Bayesian hyperparameter optimization, SEV-severity-aware training, and enriched service features achieved a 22% improvement in recall at 15% gating with notable additional outage prevention. To our knowledge, CORA is the first system to apply predictive risk modeling specifically to configuration changes.
This program is tentative and subject to change.
Fri 9 OctDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
14:00 - 15:30 | Infrastructure as Code, CI/CD and Configuration RiskESEM - Software Engineering in Practice Track / ESEM - Emerging Results, Vision, and Reflection Papers Track / ESEM - Technical Track at Mars | ||
14:00 15mTalk | Evaluating CI/CD Security Best Practices in the GitHub Actions Documentation ESEM - Technical Track Lukas Boschanski University of North Carolina at Charlotte, Marco Vieira University of North Carolina at Charlotte | ||
14:15 15mTalk | Does Fixing Break Security? An Empirical Study of Security Degradation in Iterative LLM-Driven Infrastructure-as-Code Repair ESEM - Technical Track Benjamin Agyekum Colorado State University, Fabio Marcos De Abreu Santos Colorado State University, USA | ||
14:30 15mTalk | A Nightly Feedback-Driven Strategy for Quality Control in Safety-Critical Software Development ESEM - Software Engineering in Practice Track Simin Sun Chalmers University of Technology and University of Gothenburg, Peter Nemeth Zenseact, Staffan Johansson Zenseact, Theo Wiik Zenseact, David Friberg Zenseact, Farnaz Fotrousi Chalmers University of Technology and University of Gothenburg, Miroslaw Staron Chalmers University of Technology and University of Gothenburg | ||
14:45 15mTalk | CORA: Config Risk Analyzer --- Predicting Risk of Configuration Changes at Scale ESEM - Software Engineering in Practice Track Weiyan Sun Meta Platforms, Inc., Audris Mockus University of Tennessee, Nachiappan Nagappan Meta Platforms, Inc. | ||
15:00 10mTalk | Tools for Detecting Security Issues in Infrastructure-as-Code: A Focused Literature Review ESEM - Emerging Results, Vision, and Reflection Papers Track | ||
15:10 10mTalk | TerraRepair: A Tool-Grounded LLM Agent for Infrastructure-as-Code Repair ESEM - Emerging Results, Vision, and Reflection Papers Track Minase Mekete Mengistu University of L'Aquila, Juri Di Rocco University of L'Aquila, Phuong T. Nguyen University of L’Aquila, Davide Di Ruscio University of L'Aquila Pre-print | ||
15:20 10mTalk | An Agentic Approach Towards Replication Package Quality Evaluation ESEM - Emerging Results, Vision, and Reflection Papers Track | ||