If there's a CRD resource with wrong name or something similar, the watcher will fail. This allowed the service to be deployed and replace the working version.
Either the deployment is too aggressive when deploying, replacing all old instances, or it's too easy to get a 200 OK health check