Evidence ledger
One row per claim in Where resilience policy lives: Netflix, 2016 to 2026: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.
Field guide: The decade Netflix took resilience out of the client library (2026-09-29).
Constraint on this ledger, stated up front. The session that assembled it reached exactly
three hosts: github.com, raw.githubusercontent.com and gist.github.com. Every other host
was refused by the network egress policy, including netflixtechblog.com, arxiv.org,
usenix.org, infoq.com and en.wikipedia.org. So there is no engineering blog, conference
talk, paper or cost figure in this corpus. Every row below was fetched on 2026-09-29 from a
repository Netflix or the Spring team publishes, and the guide is built only from what those
repositories say. Where the argument needs something the repositories cannot supply, the guide
says so rather than reaching for memory.
One row per claim, so a single artefact appears more than once. The guide's evidence wall shows 22 artefacts; the 40 rows below are the individual claims taken from them.
Quotes are copied, not paraphrased.
| # | Org | Title | Tier | Published | Checked | URL | Claim I take from it | Supporting quote or figure |
|---|---|---|---|---|---|---|---|---|
| 1 | Netflix | Hystrix README, project status | adr | 2018-11 (notice) | 2026-09-29 | https://github.com/Netflix/Hystrix | Netflix retired its circuit breaker in favour of mechanisms that infer their own settings. | "Hystrix is no longer in active development, and is currently in maintenance mode." … "our focus has shifted towards more adaptive implementations that react to an application's real time performance rather than pre-configured settings (for example, through adaptive concurrency limits)." |
| 2 | Netflix | Hystrix README, community expectations | adr | 2018-11 | 2026-09-29 | https://github.com/Netflix/Hystrix | The retirement was explicit about what the community would and would not get. | "Netflix will no longer actively review issues, merge pull-requests, and release new versions of Hystrix." … "we intend to continue using Hystrix for existing applications, and to leverage open and active projects like resilience4j for new internal projects." |
| 3 | Netflix | Hystrix issue #1891, "Re-release Hystrix 1.5.11" | source | 2018-11-09 | 2026-09-29 | https://github.com/Netflix/Hystrix/issues/1891 | The public artefact had drifted ahead of the version Netflix actually ran. | Netflix relied internally on 1.5.11 and reported "issues and instabilities to Hystrix 1.5.13 that make it problematic to use"; the final release 1.5.18 was cut to align Maven Central with "the last known stable version used internally at Netflix (1.5.11)". |
| 4 | Netflix | Ribbon README, "Project Status: On Maintenance" | adr | c. 2016 | 2026-09-29 | https://github.com/Netflix/ribbon | The client-side load balancer was retired because a Java library could not serve a polyglot fleet. | "Our team has instead started building an RPC solution on top of gRPC. We are doing this transition for two main reasons: multi-language support and better extensibility/composability through request interceptors." |
| 5 | Netflix | Ribbon README, component inventory | adr | c. 2016 | 2026-09-29 | https://github.com/Netflix/ribbon | Parts of a published library were never what Netflix ran; several modules were marked unused. | "ribbon-transport: not used" … "ribbon: not used" … "ribbon-httpclient: … Instead, we use an internal solution developed by our cloud security team" |
| 6 | Netflix | Ribbon README, componentisation rationale | adr | c. 2016 | 2026-09-29 | https://github.com/Netflix/ribbon | The stated cause of the split was a move to single-responsibility RPC modules. | "This is because Netflix started moving into a more componentized architecture for RPC with a focus on single-responsibility modules." |
| 7 | Netflix | concurrency-limits README, background | source | n/d | 2026-09-29 | https://github.com/Netflix/concurrency-limits | The argument against configured limits is that the configured value goes stale faster than operators can maintain it. | "in large distributed systems that auto-scale this value quickly goes out of date and the service falls over by becoming non-responsive as it is unable to gracefully shed excess load." |
| 8 | Netflix | concurrency-limits README, mechanism | source | n/d | 2026-09-29 | https://github.com/Netflix/concurrency-limits | The replacement is a per-node control loop borrowed from TCP congestion control. | "we borrow from common TCP congestion control algorithms by equating a system's concurrency limit to a TCP congestion window." Vegas estimates the queue as L * (1 - minRTT/sampleRtt). |
| 9 | Netflix | concurrency-limits README, ground rules | source | n/d | 2026-09-29 | https://github.com/Netflix/concurrency-limits | The design concedes that nobody can enumerate the constraints a service is actually bound by. | "For large and complex distributed systems it's impossible to know all the hard resources." |
| 10 | Netflix | concurrency-limits issue #171 | source | 2021-07-27 | 2026-09-29 | https://github.com/Netflix/concurrency-limits/issues/171 | The central blind spot of a latency-driven limiter has been an open question for five years. | "How does this differentiate between a dependent service getting slower and standard too much concurrency impacting latency?" The thread carries no reply. |
| 11 | Netflix | concurrency-limits issue #231 | postmortem | 2026-01-09 | 2026-09-29 | https://github.com/Netflix/concurrency-limits/issues/231 | The load-shedding path itself ships an unbounded default. | BlockingAdaptiveExecutor defaults to Executors.newCachedThreadPool() with "no upper bound on thread creation (Integer.MAX_VALUE)"; a limiter failure under burst yields "java.lang.OutOfMemoryError: unable to create new native thread". |
| 12 | Netflix | concurrency-limits issue #190 | postmortem | 2023-11-02 | 2026-09-29 | https://github.com/Netflix/concurrency-limits/issues/190 | Rejection paths leak the accounting the limiter depends on. | Issue title: "Inflight requests leak when gRPC executor rejects tasks"; the reporter describes the symptom as "the qps just dies after sometime". Still open, no reply. |
| 13 | Netflix | concurrency-limits, closed-unmerged pull requests | source | 2018-2026 | 2026-09-29 | https://github.com/Netflix/concurrency-limits/pulls?q=is%3Apr+is%3Aclosed+is%3Aunmerged | Time-to-decision on outside contributions is measured in years. | #151 "add deadline limiter" opened 2019-11-15, closed unmerged 2026-06-17; #164 "Add counters for partitions" 2020-12-28 to 2025-09-28; #144 "Add dubbo limit support" 2019-08-21 to 2021-07-05. |
| 14 | Netflix | concurrency-limits core source history | source | 2026-01-12 | 2026-09-29 | https://github.com/Netflix/concurrency-limits/commits/main/concurrency-limits-core/src | The successor is genuinely maintained in code, which is what makes the unanswered design question notable rather than expected. | Most recent source commit: "Add time unit to Limit#onSample (#228)", 12 Jan 2026. |
| 15 | Netflix | Hystrix core source history | source | 2021-11-30 | 2026-09-29 | https://github.com/Netflix/Hystrix/commits/master/hystrix-core/src | The functional death date of Hystrix is 2021, not the 2025 date the repository front page implies. | Most recent commit touching hystrix-core/src: "fix typo HystrixContextSchedulerAction class name", 30 Nov 2021. |
| 16 | Netflix | Ribbon load-balancer source history | source | 2021-03-03 | 2026-09-29 | https://github.com/Netflix/ribbon/commits/master/ribbon-loadbalancer/src | Same, for Ribbon, and the last change was a build upgrade rather than logic. | Most recent commit touching ribbon-loadbalancer/src: "Upgrade to modern gradle and nebula", 3 Mar 2021. |
| 17 | Netflix | Hystrix pull request #2115 | source | 2025-12-17 | 2026-09-29 | https://github.com/Netflix/Hystrix/pull/2115 | The 2025 commits on retired repositories are org-wide CI housekeeping, not maintenance. | "Update Github Actions to use latest NetflixOSS recommendations", author rpalcolea, 17 Dec 2025, a CI configuration change. The same change landed as Ribbon #526, Servo #492 and Governator #425 on the same day. |
| 18 | Netflix | Servo README | adr | n/d | 2026-09-29 | https://github.com/Netflix/servo | How you retire a library you cannot make people uninstall: default it to a no-op. | "# DEPRECATED … For any new projects it is recommended to use the [Spectator] library instead." and "As of version 0.13.0, the default monitor registry is a no-op implementation to minimize the overhead for legacy apps that still happen to have some usage of Servo." |
| 19 | Netflix | Spectator README | source | n/d | 2026-09-29 | https://github.com/Netflix/spectator | The instrumentation library survived the decade while the network-policy libraries did not. | "Simple library for instrumenting code to record dimensional time series." Repository last updated 23 Sep 2026 per the Netflix organisation listing. |
| 20 | Netflix | Simian Army README, "PROJECT STATUS: RETIRED" | adr | n/d | 2026-09-29 | https://github.com/Netflix/SimianArmy | A tool suite was retired by dispersing its functions into the delivery platform. | "The Simian Army project is no longer actively maintained." Chaos Monkey became "a standalone service", Swabbie replaced Janitor Monkey, and "Conformity Monkey functionality will be rolled into other [Spinnaker] backend services." |
| 21 | Netflix | Vector README, project status | adr | n/d | 2026-09-29 | https://github.com/Netflix/vector | Netflix retired its own observability front end in favour of an industry stack, and said so plainly. | "we have contributed our latest developments in this space to the PCP project and are retiring Vector as a standalone web application" … "We have decided to lean into the Grafana stack. Grafana is widely used, well supported, and has an extensible framework". |
| 22 | Netflix | Curator README | adr | n/d | 2026-09-29 | https://github.com/Netflix/curator | The donation exit: the project leaves the company and the company keeps only its extensions. | "Curator has moved to Apache. The Netflix Curator project will remain to hold Netflix extensions to Curator." |
| 23 | Netflix | Conductor repository archive notice | adr | 2023-12-13 | 2026-09-29 | https://github.com/Netflix/conductor | The internal-fork exit: the public project is discontinued so engineering can realign on the private one. | "Effective December 13, 2023, Netflix will discontinue maintenance of Conductor OSS on GitHub." |
| 24 | Netflix | Titus README archival notice | adr | n/d | 2026-09-29 | https://github.com/Netflix/titus | The aggregate repository was archived while its components continued separately. | "This repo has been archived and is no longer in active development." Links remain to Titus API Definitions, Titus Control Plane and Titus Executor. |
| 25 | Netflix | Archaius README | source | n/d | 2026-09-29 | https://github.com/Netflix/archaius | The configuration library that bridged into Spring Cloud is an unmaintained snapshot on its 1.x line. | "Development of Archaius now happens in the 2.x branch. The 1.x branch contains an unmaintained snapshot of the last legacy 1.x release." |
| 26 | Netflix | Eureka issue #1510 | postmortem | 2023-08-07 | 2026-09-29 | https://github.com/Netflix/eureka/issues/1510 | A silent death of the registry refresh loop produced a four-day detection gap and routing to dead hosts. | "Task java.util.concurrent.FutureTask rejected from java.util.concurrent.ThreadPoolExecutor[Running, pool size = 2, active threads = 2, queued tasks = 0]"; four days later a dependency redeploy produced "I/O exception (java.net.NoRouteToHostException) caught when processing request to http://10.164.92.119:8080: No route to host". Affected eureka-client 1.10.17 with Spring Cloud 3.1.2; resolved by a manual pod restart. |
| 27 | Netflix | Eureka issue #1510, dependency calendar | postmortem | 2023-08-07 | 2026-09-29 | https://github.com/Netflix/eureka/issues/1510 | An operator cannot choose when to take a fix to an embedded client. | The reporter observes that "Eureka-client updates only appear in major Spring Cloud releases". |
| 28 | Netflix | Eureka issue #1362, "Eureka Server Down" | postmortem | 2020-11-06 | 2026-09-29 | https://github.com/Netflix/eureka/issues/1362 | When the registry is unreachable the client keeps serving its stale cache with no signal to the caller. | "When Eureka Server Down,EurekaClient can't change locat cache. So when I call DiscoveryClient getInstace(),It still get application instance." Closed, labelled question, no maintainer reply visible. |
| 29 | Netflix | Eureka README | source | n/d | 2026-09-29 | https://github.com/Netflix/eureka | Eureka is the one 2016 component still described in the present tense and still load-bearing. | "It plays a critical role in Netflix mid-tier infra." Support is "Community-driven mostly". |
| 30 | Spring | spring-cloud-netflix README, branch 1.4.x | source | branch as of 2026-09-29 | 2026-09-29 | https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/1.4.x/README.adoc | What the industry actually adopted from Netflix in 2016: eight advertised capabilities, seven of them network policy. | Features list: Eureka discovery (client and embedded server), Hystrix circuit breaker and dashboard, Feign, "Client Side Load Balancer: Ribbon", Archaius configuration bridge, "Router and Filter: automatic registration of Zuul filters". |
| 31 | Spring | spring-cloud-netflix README, branch 3.0.x | source | branch as of 2026-09-29 | 2026-09-29 | https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/3.0.x/README.adoc | One release train removed five of the seven capabilities from the ecosystem's copy of the stack. | Features list reduced to two lines, both Eureka: instance registration and discovery, and an embedded Eureka server. |
| 32 | Spring | spring-cloud-netflix README, main branch | source | branch as of 2026-09-29 | 2026-09-29 | https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/main/README.adoc | The reduction held: in 2026 the project is a Eureka integration and nothing else. | Features: the same two Eureka lines. |
| 33 | Spring | spring-cloud-netflix reference docs, branch 2.2.x | adr | branch as of 2026-09-29 | 2026-09-29 | https://raw.githubusercontent.com/spring-cloud/spring-cloud-netflix/2.2.x/docs/src/main/asciidoc/spring-cloud-netflix.adoc | Downstream maintainers had to build a replacement because the upstream library stopped. | "Since Ribbon load-balancer is now in maintenance mode, we suggest switching to using the Spring Cloud LoadBalancer, also included in Eureka starters, instead." |
| 34 | resilience4j | resilience4j README | source | n/d | 2026-09-29 | https://github.com/resilience4j/resilience4j | The project Netflix named as the successor is a community library with no vendor behind it. | "Resilience4j is a lightweight fault tolerance library designed for functional programming." Copyright lists individual maintainers; the README carries no sponsorship or maintenance statement. |
| 35 | Netflix | Netflix organisation repository listing, source repos by last update | source | 2026-09-29 | 2026-09-29 | https://github.com/orgs/Netflix/repositories?type=source&sort=updated | What Netflix still ships in 2026, and what is absent from the first thirty entries. | Present: atlas, spectator, EVCache, dgs-framework, dgs-codegen, hollow, genie, metaflow, zuul, mantis, metacat, maestro, Priam, iep, and a new Java toolchain (jig, ja, jfmt, jist, jdocserver), all updated in September 2026. Absent: Hystrix, ribbon, archaius, servo, governator, SimianArmy, conductor, falcor, titus. |
| 36 | Netflix | jig README | source | 2026 (preview) | 2026-09-29 | https://github.com/Netflix/jig | The current in-house investment is in the Java build and module layer, not in network libraries. | "jig provides module version resolution, compilation and assembly for the Java Module System." The README states it is "currently in preview". |
| 37 | Netflix | maestro README | source | n/d | 2026-09-29 | https://github.com/Netflix/maestro | The systems Netflix open-sources now are services it operates, not libraries others link. | "a general-purpose workflow orchestrator that provides a fully managed workflow-as-a-service (WAAS) to the data platform users at Netflix … It schedules hundreds of thousands of workflows, millions of jobs every day". |
| 38 | Netflix | Zuul README | source | n/d | 2026-09-29 | https://github.com/Netflix/zuul | The edge component survived as a deployed gateway while the in-process components did not. | "Zuul is an L7 application gateway that provides capabilities for dynamic routing, monitoring, resiliency, security, and more." Repository last updated 25 Sep 2026 per the organisation listing. |
| 39 | Netflix | dgs-framework releases | source | 2026 | 2026-09-29 | https://github.com/Netflix/dgs-framework/releases | The surviving application-level libraries encode data contracts, and they track the upstream ecosystem rather than diverging from it. | Recent releases v12.0.0, v12.0.1, v12.1.0; the v11.0.0 notes point readers to "the Release Notes for Spring Boot 4 and Spring GraphQL". |
| 40 | Netflix | Falcor commit history | source | 2025-08-28 | 2026-09-29 | https://github.com/Netflix/falcor/commits/master/ | The data-fetching library Netflix built before GraphQL is still present and still quiet. | Most recent commit "Added Changelog for 2.4.1", 28 Aug 2025. Falcor does not appear among the thirty most recently updated Netflix source repositories. |
Categories that are empty, and what that means
- Engineering blogs, talks, papers, cost figures: zero. Not because none exist, but because
the network policy in this session reached no host that serves them. A reader who wants
Netflix's own narrative of these changes should start from the links the repositories
themselves carry into
netflixtechblog.com, which this guide lists but could not fetch and therefore does not cite. - Formal post-incident reviews: zero. Netflix publishes none in this corpus. The four rows
graded
postmortemare operator-filed incident reports in issue trackers, which is a weaker artefact: there is no timeline discipline, no impact measurement, and in three of the four cases no maintainer reply. The guide says so where it uses them. - Independent measurement: zero. No benchmark, latency figure or cost number in this corpus comes from anyone other than the project that wrote the code.