Changing what the services stand on: ten years of ByteDance, read from its own repositories
How ByteDance changed the layer beneath thousands of services between 2021 and 2026 without changing the services: eighteen API-compatible replacements for the Go standard library, Apache Thrift, etcd, the Kubernetes scheduler and Kubernetes Federation, reconstructed from the CloudWeGo and KubeWharf repositories, the Go runtime's own source comments, the breakage threads the substitutions caused upstream and downstream, and the release notes in which the most aggressive of them was deleted.
An organisation past a certain size cannot ask its services to change, so when the layer beneath them becomes the constraint it replaces that layer and keeps the signature. This guide reconstructs every one of ByteDance's public substitutions, prices each from the artefact the price was paid in, and shows why the same strategy produced a decade-long success in Go and a frozen fork in Kubernetes. A reader finishes able to say, in a design review, which substitutions are safe to make, what the fallback and the version bound have to look like, and which patches mean you have quietly decided to stop upgrading.
The gravity reversed in one half of the stack and froze in the other: Go's own runtime source now names these packages as a compatibility constraint and the Go team restored a deleted symbol and backported it for them, while the same company's Kubernetes substitutions are published only against a Kubernetes patch release from September 2022, thirteen minor versions behind upstream.
What you get out of it
- Every one of the eighteen substitutions has the same five parts, and only the fifth, the reach-through past the published interface, generates any liability at all.
- The failures are never in the fast path. They are the seam closing upstream (Go 1.23, 1.24 and 1.26 each have a filed build-breakage issue), the toolchain's safety nets going (a checkptr crash under -race, and netpoll shipping race-tagged files to hide a deliberate data race), and the fork freezing.
- The most aggressive substitution was retired in public on a four-step path worth copying: cap the supported range, add the opt-out, flip the default, delete the code. Frugal did it in thirteen months and four releases.
- A fallback that is correct and silent is a capacity regression nobody can attribute: sonic's fast path switches itself off above go1.28 and delegates to encoding/json with no error, and byte compatibility with the original is a non-default config.
- The lesson: substitute through a contract someone else is obliged to keep, and treat a patch set that cannot become an upstream extension point as a decision to stop upgrading, because its version floor propagates to everything built on it.
Scope
Why this, now. Go 1.23 closed the linkname seam that a generation of high-performance Go libraries reached through, and the full consequence is only now visible in release notes: the retreat finished in September 2025 and the breakage recurred again on Go 1.26 in January 2026.
What it does not cover. It does not cover what any of this cost or felt like to operate inside ByteDance: there are no cost figures, no fleet or service counts and no company-published incident reviews in the public record, and this run's network policy blocked every engineering-blog, conference-talk and paper host, so the guide is a reconstruction of decisions and their prices from repositories alone.
Other field guides
Hardening the wrong plane: ten years of Cloudflare's architecture
A single-company dig: Cloudflare, 2016 to 2026, reconstructed from eight of its own incident reports, its engineering accounts of Pingora, Quicksilve…
30 sources · 12 organisations · 9 postmortemsReplacing the package with the image: ten years of Red Hat changing the unit of change
Four generations of one host operating system, reconstructed from the artefacts the decisions were taken in: Fedora CoreOS design records and tracker…
30 sources · 10 organisations · 4 postmortemsEverything they deleted was on the inside: ten years of HashiCorp, read from its own repositories
HashiCorp spent a decade deleting things from the inside of its products: a Raft log store, a dependency cluster, a process on every node, four produ…
24 sources · 5 organisations · 1 postmortem