A rollout advances only on Ready Pods, so readiness is its brake. Point the probe at a path the API lacks, and the first new Pod never turns Ready, no old Pod is removed, and after progressDeadlineSeconds the rollout fails:
kubectl patch deployment api --type=json -p='[{"op": "replace", "value": "/readyz",
"path": "/spec/template/spec/containers/0/readinessProbe/httpGet/path"}]'
kubectl rollout status deployment/api --timeout=120s
kubectl get pods -l tier=api
kubectl get deployment api -o jsonpath='{.status.conditions[?(@.type=="Progressing")].reason}'
echo && kubectl rollout undo deployment/apiOutput
deployment.apps/api patched Waiting for deployment "api" rollout to finish: 1 out of 3 new replicas have been updated... error: deployment "api" exceeded its progress deadline NAME READY STATUS RESTARTS AGE api-54b58bdffd-5sk4n 0/1 Running 0 61s api-6d799c4498-dvdgn 1/1 Running 0 81s api-6d799c4498-pllhc 1/1 Running 0 87s api-6d799c4498-v25v7 1/1 Running 0 71s ProgressDeadlineExceeded Warning: resource deployments/api was previously managed with 'kubectl apply'. Rolling back will not update the kubectl.kubernetes.io/last-applied-configuration annotation, ... deployment.apps/api rolled back
The old Pods served throughout. CI should fail on ProgressDeadlineExceeded (default deadline 600 seconds); nothing rolls back by itself. A readiness gate (spec.readinessGates) adds Pod conditions an outside controller must set, such as the AWS 24 Load Balancer Controller's health check.