Evidence ledger 22 sources Checked 29 Sep 2026

Evidence ledger

One row per claim in Where resilience policy lives: Netflix, 2016 to 2026: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.

Field guide: The decade Netflix took resilience out of the client library (2026-09-29).

Constraint on this ledger, stated up front. The session that assembled it reached exactly three hosts: github.com, raw.githubusercontent.com and gist.github.com. Every other host was refused by the network egress policy, including netflixtechblog.com, arxiv.org, usenix.org, infoq.com and en.wikipedia.org. So there is no engineering blog, conference talk, paper or cost figure in this corpus. Every row below was fetched on 2026-09-29 from a repository Netflix or the Spring team publishes, and the guide is built only from what those repositories say. Where the argument needs something the repositories cannot supply, the guide says so rather than reaching for memory.

One row per claim, so a single artefact appears more than once. The guide's evidence wall shows 22 artefacts; the 40 rows below are the individual claims taken from them.

Quotes are copied, not paraphrased.

# Org Title Tier Published Checked URL Claim I take from it Supporting quote or figure
1 Netflix Hystrix README, project status adr 2018-11 (notice) 2026-09-29 https://github.com/Netflix/Hystrix Netflix retired its circuit breaker in favour of mechanisms that infer their own settings. "Hystrix is no longer in active development, and is currently in maintenance mode." … "our focus has shifted towards more adaptive implementations that react to an application's real time performance rather than pre-configured settings (for example, through adaptive concurrency limits)."
2 Netflix Hystrix README, community expectations adr 2018-11 2026-09-29 https://github.com/Netflix/Hystrix The retirement was explicit about what the community would and would not get. "Netflix will no longer actively review issues, merge pull-requests, and release new versions of Hystrix." … "we intend to continue using Hystrix for existing applications, and to leverage open and active projects like resilience4j for new internal projects."
3 Netflix Hystrix issue #1891, "Re-release Hystrix 1.5.11" source 2018-11-09 2026-09-29 https://github.com/Netflix/Hystrix/issues/1891 The public artefact had drifted ahead of the version Netflix actually ran. Netflix relied internally on 1.5.11 and reported "issues and instabilities to Hystrix 1.5.13 that make it problematic to use"; the final release 1.5.18 was cut to align Maven Central with "the last known stable version used internally at Netflix (1.5.11)".
4 Netflix Ribbon README, "Project Status: On Maintenance" adr c. 2016 2026-09-29 https://github.com/Netflix/ribbon The client-side load balancer was retired because a Java library could not serve a polyglot fleet. "Our team has instead started building an RPC solution on top of gRPC. We are doing this transition for two main reasons: multi-language support and better extensibility/composability through request interceptors."
5 Netflix Ribbon README, component inventory adr c. 2016 2026-09-29 https://github.com/Netflix/ribbon Parts of a published library were never what Netflix ran; several modules were marked unused. "ribbon-transport: not used" … "ribbon: not used" … "ribbon-httpclient: … Instead, we use an internal solution developed by our cloud security team"
6 Netflix Ribbon README, componentisation rationale adr c. 2016 2026-09-29 https://github.com/Netflix/ribbon The stated cause of the split was a move to single-responsibility RPC modules. "This is because Netflix started moving into a more componentized architecture for RPC with a focus on single-responsibility modules."
7 Netflix concurrency-limits README, background source n/d 2026-09-29 https://github.com/Netflix/concurrency-limits The argument against configured limits is that the configured value goes stale faster than operators can maintain it. "in large distributed systems that auto-scale this value quickly goes out of date and the service falls over by becoming non-responsive as it is unable to gracefully shed excess load."
8 Netflix concurrency-limits README, mechanism source n/d 2026-09-29 https://github.com/Netflix/concurrency-limits The replacement is a per-node control loop borrowed from TCP congestion control. "we borrow from common TCP congestion control algorithms by equating a system's concurrency limit to a TCP congestion window." Vegas estimates the queue as L * (1 - minRTT/sampleRtt).
9 Netflix concurrency-limits README, ground rules source n/d 2026-09-29 https://github.com/Netflix/concurrency-limits The design concedes that nobody can enumerate the constraints a service is actually bound by. "For large and complex distributed systems it's impossible to know all the hard resources."
10 Netflix concurrency-limits issue #171 source 2021-07-27 2026-09-29 https://github.com/Netflix/concurrency-limits/issues/171 The central blind spot of a latency-driven limiter has been an open question for five years. "How does this differentiate between a dependent service getting slower and standard too much concurrency impacting latency?" The thread carries no reply.
11 Netflix concurrency-limits issue #231 postmortem 2026-01-09 2026-09-29 https://github.com/Netflix/concurrency-limits/issues/231 The load-shedding path itself ships an unbounded default. BlockingAdaptiveExecutor defaults to Executors.newCachedThreadPool() with "no upper bound on thread creation (Integer.MAX_VALUE)"; a limiter failure under burst yields "java.lang.OutOfMemoryError: unable to create new native thread".
12 Netflix concurrency-limits issue #190 postmortem 2023-11-02 2026-09-29 https://github.com/Netflix/concurrency-limits/issues/190 Rejection paths leak the accounting the limiter depends on. Issue title: "Inflight requests leak when gRPC executor rejects tasks"; the reporter describes the symptom as "the qps just dies after sometime". Still open, no reply.
13 Netflix concurrency-limits, closed-unmerged pull requests source 2018-2026 2026-09-29 https://github.com/Netflix/concurrency-limits/pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged Time-to-decision on outside contributions is measured in years. #151 "add deadline limiter" opened 2019-11-15, closed unmerged 2026-06-17; #164 "Add counters for partitions" 2020-12-28 to 2025-09-28; #144 "Add dubbo limit support" 2019-08-21 to 2021-07-05.
14 Netflix concurrency-limits core source history source 2026-01-12 2026-09-29 https://github.com/Netflix/concurrency-limits/commits/main/concurrency-limits-core/src The successor is genuinely maintained in code, which is what makes the unanswered design question notable rather than expected. Most recent source commit: "Add time unit to Limit#onSample (#228)", 12 Jan 2026.
15 Netflix Hystrix core source history source 2021-11-30 2026-09-29 https://github.com/Netflix/Hystrix/commits/master/hystrix-core/src The functional death date of Hystrix is 2021, not the 2025 date the repository front page implies. Most recent commit touching hystrix-core/src: "fix typo HystrixContextSchedulerAction class name", 30 Nov 2021.
16 Netflix Ribbon load-balancer source history source 2021-03-03 2026-09-29 https://github.com/Netflix/ribbon/commits/master/ribbon-loadbalancer/src Same, for Ribbon, and the last change was a build upgrade rather than logic. Most recent commit touching ribbon-loadbalancer/src: "Upgrade to modern gradle and nebula", 3 Mar 2021.
17 Netflix Hystrix pull request #2115 source 2025-12-17 2026-09-29 https://github.com/Netflix/Hystrix/pull/2115 The 2025 commits on retired repositories are org-wide CI housekeeping, not maintenance. "Update Github Actions to use latest NetflixOSS recommendations", author rpalcolea, 17 Dec 2025, a CI configuration change. The same change landed as Ribbon #526, Servo #492 and Governator #425 on the same day.
18 Netflix Servo README adr n/d 2026-09-29 https://github.com/Netflix/servo How you retire a library you cannot make people uninstall: default it to a no-op. "# DEPRECATED … For any new projects it is recommended to use the [Spectator] library instead." and "As of version 0.13.0, the default monitor registry is a no-op implementation to minimize the overhead for legacy apps that still happen to have some usage of Servo."
19 Netflix Spectator README source n/d 2026-09-29 https://github.com/Netflix/spectator The instrumentation library survived the decade while the network-policy libraries did not. "Simple library for instrumenting code to record dimensional time series." Repository last updated 23 Sep 2026 per the Netflix organisation listing.
20 Netflix Simian Army README, "PROJECT STATUS: RETIRED" adr n/d 2026-09-29 https://github.com/Netflix/SimianArmy A tool suite was retired by dispersing its functions into the delivery platform. "The Simian Army project is no longer actively maintained." Chaos Monkey became "a standalone service", Swabbie replaced Janitor Monkey, and "Conformity Monkey functionality will be rolled into other [Spinnaker] backend services."
21 Netflix Vector README, project status adr n/d 2026-09-29 https://github.com/Netflix/vector Netflix retired its own observability front end in favour of an industry stack, and said so plainly. "we have contributed our latest developments in this space to the PCP project and are retiring Vector as a standalone web application" … "We have decided to lean into the Grafana stack. Grafana is widely used, well supported, and has an extensible framework".
22 Netflix Curator README adr n/d 2026-09-29 https://github.com/Netflix/curator The donation exit: the project leaves the company and the company keeps only its extensions. "Curator has moved to Apache. The Netflix Curator project will remain to hold Netflix extensions to Curator."
23 Netflix Conductor repository archive notice adr 2023-12-13 2026-09-29 https://github.com/Netflix/conductor The internal-fork exit: the public project is discontinued so engineering can realign on the private one. "Effective December 13, 2023, Netflix will discontinue maintenance of Conductor OSS on GitHub."
24 Netflix Titus README archival notice adr n/d 2026-09-29 https://github.com/Netflix/titus The aggregate repository was archived while its components continued separately. "This repo has been archived and is no longer in active development." Links remain to Titus API Definitions, Titus Control Plane and Titus Executor.
25 Netflix Archaius README source n/d 2026-09-29 https://github.com/Netflix/archaius The configuration library that bridged into Spring Cloud is an unmaintained snapshot on its 1.x line. "Development of Archaius now happens in the 2.x branch. The 1.x branch contains an unmaintained snapshot of the last legacy 1.x release."
26 Netflix Eureka issue #1510 postmortem 2023-08-07 2026-09-29 https://github.com/Netflix/eureka/issues/1510 A silent death of the registry refresh loop produced a four-day detection gap and routing to dead hosts. "Task java.util.concurrent.FutureTask rejected from java.util.concurrent.ThreadPoolExecutor[Running, pool size = 2, active threads = 2, queued tasks = 0]"; four days later a dependency redeploy produced "I/O exception (java.net.NoRouteToHostException) caught when processing request to http://10.164.92.119:8080: No route to host". Affected eureka-client 1.10.17 with Spring Cloud 3.1.2; resolved by a manual pod restart.
27 Netflix Eureka issue #1510, dependency calendar postmortem 2023-08-07 2026-09-29 https://github.com/Netflix/eureka/issues/1510 An operator cannot choose when to take a fix to an embedded client. The reporter observes that "Eureka-client updates only appear in major Spring Cloud releases".
28 Netflix Eureka issue #1362, "Eureka Server Down" postmortem 2020-11-06 2026-09-29 https://github.com/Netflix/eureka/issues/1362 When the registry is unreachable the client keeps serving its stale cache with no signal to the caller. "When Eureka Server Down,EurekaClient can't change locat cache. So when I call DiscoveryClient getInstace(),It still get application instance." Closed, labelled question, no maintainer reply visible.
29 Netflix Eureka README source n/d 2026-09-29 https://github.com/Netflix/eureka Eureka is the one 2016 component still described in the present tense and still load-bearing. "It plays a critical role in Netflix mid-tier infra." Support is "Community-driven mostly".
30 Spring spring-cloud-netflix README, branch 1.4.x source branch as of 2026-09-29 2026-09-29 https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/1.4.x/README.adoc What the industry actually adopted from Netflix in 2016: eight advertised capabilities, seven of them network policy. Features list: Eureka discovery (client and embedded server), Hystrix circuit breaker and dashboard, Feign, "Client Side Load Balancer: Ribbon", Archaius configuration bridge, "Router and Filter: automatic registration of Zuul filters".
31 Spring spring-cloud-netflix README, branch 3.0.x source branch as of 2026-09-29 2026-09-29 https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/3.0.x/README.adoc One release train removed five of the seven capabilities from the ecosystem's copy of the stack. Features list reduced to two lines, both Eureka: instance registration and discovery, and an embedded Eureka server.
32 Spring spring-cloud-netflix README, main branch source branch as of 2026-09-29 2026-09-29 https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/main/README.adoc The reduction held: in 2026 the project is a Eureka integration and nothing else. Features: the same two Eureka lines.
33 Spring spring-cloud-netflix reference docs, branch 2.2.x adr branch as of 2026-09-29 2026-09-29 https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/2.2.x/docs/src/main/asciidoc/spring-cloud-netflix.adoc Downstream maintainers had to build a replacement because the upstream library stopped. "Since Ribbon load-balancer is now in maintenance mode, we suggest switching to using the Spring Cloud LoadBalancer, also included in Eureka starters, instead."
34 resilience4j resilience4j README source n/d 2026-09-29 https://github.com/resilience4j/resilience4j The project Netflix named as the successor is a community library with no vendor behind it. "Resilience4j is a lightweight fault tolerance library designed for functional programming." Copyright lists individual maintainers; the README carries no sponsorship or maintenance statement.
35 Netflix Netflix organisation repository listing, source repos by last update source 2026-09-29 2026-09-29 https://github.com/orgs/Netflix/repositories?type=source&sort=updated What Netflix still ships in 2026, and what is absent from the first thirty entries. Present: atlas, spectator, EVCache, dgs-framework, dgs-codegen, hollow, genie, metaflow, zuul, mantis, metacat, maestro, Priam, iep, and a new Java toolchain (jig, ja, jfmt, jist, jdocserver), all updated in September 2026. Absent: Hystrix, ribbon, archaius, servo, governator, SimianArmy, conductor, falcor, titus.
36 Netflix jig README source 2026 (preview) 2026-09-29 https://github.com/Netflix/jig The current in-house investment is in the Java build and module layer, not in network libraries. "jig provides module version resolution, compilation and assembly for the Java Module System." The README states it is "currently in preview".
37 Netflix maestro README source n/d 2026-09-29 https://github.com/Netflix/maestro The systems Netflix open-sources now are services it operates, not libraries others link. "a general-purpose workflow orchestrator that provides a fully managed workflow-as-a-service (WAAS) to the data platform users at Netflix … It schedules hundreds of thousands of workflows, millions of jobs every day".
38 Netflix Zuul README source n/d 2026-09-29 https://github.com/Netflix/zuul The edge component survived as a deployed gateway while the in-process components did not. "Zuul is an L7 application gateway that provides capabilities for dynamic routing, monitoring, resiliency, security, and more." Repository last updated 25 Sep 2026 per the organisation listing.
39 Netflix dgs-framework releases source 2026 2026-09-29 https://github.com/Netflix/dgs-framework/releases The surviving application-level libraries encode data contracts, and they track the upstream ecosystem rather than diverging from it. Recent releases v12.0.0, v12.0.1, v12.1.0; the v11.0.0 notes point readers to "the Release Notes for Spring Boot 4 and Spring GraphQL".
40 Netflix Falcor commit history source 2025-08-28 2026-09-29 https://github.com/Netflix/falcor/commits/master/ The data-fetching library Netflix built before GraphQL is still present and still quiet. Most recent commit "Added Changelog for 2.4.1", 28 Aug 2025. Falcor does not appear among the thirty most recently updated Netflix source repositories.

Categories that are empty, and what that means

  • Engineering blogs, talks, papers, cost figures: zero. Not because none exist, but because the network policy in this session reached no host that serves them. A reader who wants Netflix's own narrative of these changes should start from the links the repositories themselves carry into netflixtechblog.com, which this guide lists but could not fetch and therefore does not cite.
  • Formal post-incident reviews: zero. Netflix publishes none in this corpus. The four rows graded postmortem are operator-filed incident reports in issue trackers, which is a weaker artefact: there is no timeline discipline, no impact measurement, and in three of the four cases no maintainer reply. The guide says so where it uses them.
  • Independent measurement: zero. No benchmark, latency figure or cost number in this corpus comes from anyone other than the project that wrote the code.