Start here. This is the direct spoken answer to practice first.
Why this question matters
HTTP 500 responses immediately after a slot swap point toward the newly active artifact, production-bound configuration, cold initialization, dependency access, or incompatible data changes. Safe mitigation depends on knowing whether the old slot can still run against current state.
The timing points to the swap, and the evidence points more narrowly to the database contract. I would confirm the failing deployment version and exception, then compare the production migration history with the migration expected by that artifact. Because the health path did not touch the orders schema, a green swap did not prove this route was ready. I would stop broad configuration guessing once the missing column and skipped migration are confirmed.