Every source behind this page, graded. The strongest material is at the
tiers ordinary search never surfaces: the postmortems, the design records, and one closed,
unmerged proposal.
Postmortem
Slack2020-05
A Terrible, Horrible, No-Good, Very Bad Day at Slack
The definitive pool-view-drift incident: HAProxy state over eight hours stale,
autoscaling removing exactly the instances the stale view still trusted, and the one alert
that would have caught it silently broken.
Carry forwardAlert on the age of the balancer's view, not only on backend health.
slack.engineering
Postmortem
GitHub2026-02
Availability report: February 2026
A connection rebalancing event inside the internal LB layer skewed traffic across sites
and triggered throttling: 1.8% of Actions runs delayed by 15 minutes on average, from
housekeeping, not from failure.
Carry forwardLB reloads synchronize client reconnects; spread them deliberately.
github.blog
Postmortem
GitHub2025-08
Availability report: August 2025
Retries first masked flaky LB-to-search connectivity, then exhausted the balancers
themselves; up to 75% of search queries failed until the indexing pipeline was slowed.
Carry forwardRetry budgets must count the balancer's state, not just backend capacity.
github.blog
Postmortem
GitHub2024-05
Availability report: May 2024
A provider-side OS upgrade produced "unintended and uneven traffic distribution within
the cluster"; the remediation list included closing monitoring gaps for load thresholds.
Carry forwardWatch the distribution itself; even a managed layer can skew silently.
github.blog
Postmortem
Heroku2013-02
Routing Performance Update
The platform's official admission that routing behaviour had drifted from its
documentation and caused years of unexplained Rails latency; paired with a FAQ that
defends random routing and names its precondition.
Carry forwardRandom is fine for concurrent backends and poison for serial ones.
heroku.com
Source
gRPC2023–24
proposal PR #383: A68 deterministic subsetting, closed unmerged
The recorded argument: a full xDS policy for SRE-book-style deterministic subsetting,
drafted, implemented in Go and Java, and closed without merging, with the doc still
marked Draft.
Carry forwardDeterministic subsetting's fairness was not worth its churn and complexity to gRPC.
github.com/grpc/proposal
Source
gRPC2024–26
proposal PR #423: A68 random subsetting with rendezvous hashing
What won instead: per-process salted rendezvous hashing over the address list, shipped
as the experimental randomsubsetting balancer in grpc-go.
Carry forwardSalted randomness decorrelates clients; determinism correlates them on purpose. Pick which correlation you want.
github.com/grpc/proposal
Source
Envoychecked 2026-10
Issue #17013: deterministic aperture in Envoy
The feature request to port Twitter's d-aperture, with the benefit argued in-thread
(fewer connections, even spread, no coordination) and no implementation to date.
Carry forwardThe gap between published algorithm and available implementation is measured in years; plan around what your proxy ships.
github.com/envoyproxy
ADR
gRPC2023-04
gRFC A58: weighted_round_robin LB policy
The most explicit trust contract in the corpus: weight = qps / (utilization +
eps/qps × penalty), a 10 s blackout before a backend's reports count, 3 min expiry
after they stop, and an error term so failure cannot masquerade as capacity.
Carry forwardA self-reported signal is usable exactly to the extent you bound when it may be believed.
github.com/grpc/proposal
ADR
gRPC2023–24
A68 design doc (deterministic subsetting draft)
The draft design that carried Google's SRE-book subsetting algorithm into xDS
configuration, including the leftover-task refinement; valuable precisely because it was
not accepted.
Carry forwardRead rejected designs for the constraint list the accepted one had to beat.
github.com/grpc/proposal
Case study
Google2016
SRE book, ch. 20: Load Balancing in the Datacenter
The chapter that documents the error sinkhole ("frequently significantly faster to just
return an 'I'm unhealthy!' error than to actually process a request"), deterministic
subsetting, and weighted round robin on backend-reported load.
Carry forwardAny busy-ness score needs an error term, or failure reads as capacity.
sre.google
Blog
Netflix2018-09
Rethinking Netflix's Edge Load Balancing
Round robin plus blacklisting was not enough at 1M+ rps; the replacement combines
choice-of-2 with the balancer's view first and the server's self-report second, with
adaptive guardrails instead of static thresholds.
Carry forwardClient sees latency best; server sees its own utilization best. Use both, in that order.
netflixtechblog.com
Blog
Twitter2019
Deterministic Aperture
The three-act subsetting story with production numbers: full mesh unaffordable, random
subsets cut connections 99% but banded the load, ring-based determinism restored fairness.
Carry forwardSubsetting decisions show up in the worst replica's load, so measure that.
blog.twitter.com
Blog
Uber2022-05
Better Load Balancing: Real-Time Dynamic Subsetting
Subset sizes recomputed from aggregated real-time load reports across a mesh of
thousands of services in millions of containers; defines the p99/average CPU imbalance
metric this guide recommends.
Carry forwardA fixed subset size is wrong for someone; size it from observed load.
eng.uber.com
Blog
Uber2024-03
Load Balancing: Handling Heterogeneous Hardware
The year-long follow-up: weighting hosts by hardware generation, framed and funded as
efficiency work rather than reliability work.
Carry forward"Identical replicas" is a fiction with a hardware refresh cycle; weights must encode it.
uber.com
Blog
AWS (M. Brooker)2012 / 2024
Two random choices; Best-of-K
Twelve years apart, the same conclusion from simulation and large-scale deployment:
cached global state herds, best-of-k with k of 2 or 3 is nearly as good as perfect
information and far more robust to staleness.
Carry forwardStaleness tolerance, not optimality, is the property to buy.
brooker.co.za
Blog
Buoyant / Kubernetes2018-11
gRPC Load Balancing on Kubernetes without Tears
The connection-versus-request unit mismatch demonstrated on a live app: one pod took
all traffic because HTTP/2 multiplexes onto one long-lived connection.
Carry forwardName the unit your balancer balances before tuning its algorithm.
kubernetes.io
Blog
Linkerd2016-03
Beyond Round Robin: Load Balancing for Latency
The early public comparison showing latency-aware policies (least-loaded, peak EWMA)
beating the round robin that nginx and HAProxy made the industry default.
Carry forwardThe default algorithm in your proxy is an accident of history, not a recommendation.
linkerd.io
Blog
Heroku2013-02
Routing and Web Performance on Heroku: a FAQ
The defence of random routing on availability grounds, the 40 ms queue-time alarm line,
and the precise description of which applications the policy hurt.
Carry forwardPublish your balancer's contract; Heroku's outage was partly a documentation failure.
heroku.com
Paper
Mitzenmacher2001
The Power of Two Choices in Randomized Load Balancing
The supermarket-model result the whole field leans on: d=2 gives an exponential
improvement over random, d=3 only a constant factor more. The maths that makes sampling
two sufficient.
Carry forwardBuy the second choice; the third is not worth its coordination cost.
eecs.harvard.edu
Paper
Google2024-04
Load is not what you should balance: Introducing Prequal (NSDI '24)
YouTube's balancer: asynchronous reusable probes (~3 per query), hot/cold classification
at the 80th percentile of requests-in-flight, lowest latency among the cold. CPU is
deliberately not the signal.
Carry forwardBalance what predicts waiting (queue, latency), not what bills (CPU).
usenix.org
Paper
TU Berlin / UCLouvain2015-05
C3: Adaptive Replica Selection (NSDI '15)
Replica selection inside a data store, with ranking built to avoid herding onto fast
servers with growing queues; up to 3x p99.9 improvement over Cassandra's stock selection.
Carry forwardPenalise queue depth superlinearly or your fastest replica becomes your hottest.
usenix.org
Paper
Google2023-05
Reinventing Backend Subsetting at Google (CACM)
A decade after the SRE book published deterministic subsetting, Google wrote up its
replacement, designed around reducing connection churn during rollouts.
Carry forwardSubsetting quality is churn under change, not just spread at rest.
cacm.acm.org
Talk
Fastly2016-11
Load Balancing is Impossible (Tyler McMullen, QCon SF)
The talk that names the physics: Poisson arrivals and heavy-tailed service times mean
perfect balance is unattainable, and the practical frontier is randomized least-conns,
Join-Idle-Queue and careful load interpretation. Cited to the talk page and slide deck;
this build environment could not play the video to timestamp claims.
Carry forwardAim for bounded worst-case imbalance, not perfect balance.
infoq.com
Talk
Twitter / USENIX2019-03
Aperture: A Non-Cooperative, Client-Side Load Balancing Algorithm (SREcon19)
The conference version of the aperture story, explicit that thousands of independent
client-side balancers must reach fairness without coordinating. Cited to the talk page and
the SREcon APAC slide deck; video not viewable from this build environment.
Carry forwardWith client-side balancing, fairness is an emergent property you must design for, not configure.
usenix.org
Vendor
Envoy2026
Supported load balancers (architecture docs)
The least-request policy's two modes, the P2C default with the Mitzenmacher citation in
the docs themselves, and the admission that the weighted fallback "will never truly drain"
a host.
Carry forwardCheck which mode your weights push you into; they are different algorithms.
envoyproxy.io
Vendor
Envoy2026
Slow start mode
The cold-host guard and its own failure modes, documented: ineffective when the whole
fleet is new, risky at low traffic (starvation, non-gradual weight jumps).
Carry forwardSlow start protects against a few cold hosts, not a cold fleet; deploys need their own ramp.
envoyproxy.io
Vendor
Envoy2026
Panic threshold
Below 50% availability Envoy stops trusting health entirely, balancing to all hosts or
failing outright, with the trade-off between the two modes spelled out.
Carry forwardDecide before the incident whether a dying pool should spread load or shed it.
envoyproxy.io
Vendor
Twitter (Finagle)2026
Finagle client docs: load balancing (Clients.rst)
Unusually honest library documentation: the heap balancer's contention, P2C's
degradation to random under low load, Peak EWMA's long-polling blind spot, panic mode's
thresholds.
Carry forwardEvery load metric has a traffic pattern that blinds it; the docs of a 15-year-old balancer list them.
github.com/twitter/finagle
Vendor
AWS2019-11
ALB adds Least Outstanding Requests
The managed-platform data point: the biggest cloud load balancer offered only round
robin until late 2019, and added LOR citing varied request costs and target churn.
Carry forwardManaged defaults lag the state of the art by years; check what your LB actually runs.
aws.amazon.com