Failure Modes

Slow rather than down, partial, grey, and failing while reporting success.

6Questions
13Flashcards
9Terms
Terminology

9 terms in this topic

case-study

AWS S3 2017: The Blast Radius of a Typo

A mistyped command during routine debugging removed far more capacity than intended, and the affected subsystems had not been restarted in years.

concept

Byzantine Fault

A failure in which a component behaves arbitrarily or deceptively — returning wrong results rather than stopping — as distinct from simply crashing.

concept

Circular Observability Dependency

When the tooling used to diagnose a failure runs on the infrastructure that is failing - so the outage removes the ability to see the outage, convert…

concept

Control-Interval Matching

Setting a feedback loop's control interval to the delay of the thing it actuates - because a controller that adjusts faster than the system can respo…

concept

Fail-Fast vs Fail-Safe

Whether a component should stop immediately on detecting a problem, or continue in a degraded but safe mode — a choice that depends entirely on which…

concept

Gray Failure

A component that is degraded rather than down, passing health checks while serving a portion of requests slowly or incorrectly.

concept

Grey Failure

A component that is degraded rather than down — slow, intermittently erroring, or failing for a subset of operations — which defeats health checks bu…

pattern

Hedged Request

Sending the same request to a second replica after a short delay and using whichever responds first, to cut tail latency caused by unlucky slow servers.

concept

Metastable Failure

A failure state that sustains itself after the original trigger is gone, because the system's own recovery behaviour generates the load keeping it down.

Distributed Systems

Neighbouring topics

Distributed Systems

General material on partial failure, coordination and distributed reasoning.

11 quiz 27 cards 19 terms

CAP & PACELC

What you must give up during a partition, and the latency choice the rest of the time.

4 quiz 13 cards 3 terms

Consistency Models

Linearizable, sequential, causal, eventual, and the session guarantees between them.

5 quiz 10 cards 7 terms

Idempotency

Making an operation safe to repeat, because a client that times out cannot know.

5 quiz 14 cards 3 terms

Retries & Backoff

Exponential backoff, jitter, retry budgets, and how retries become the outage.

4 quiz 7 cards 2 terms

Timeouts & Deadlines

Per-hop timeouts that do not compose, and the deadline budget that replaces them.

5 quiz 9 cards 6 terms

Circuit Breakers

Failing fast on a broken dependency, and what you fail fast to.

6 quiz 9 cards 5 terms

Backpressure & Flow Control

Telling callers to slow down instead of buffering into congestion collapse.

4 quiz 10 cards 5 terms

Load Shedding

Rejecting some work deliberately so the rest can be served correctly.

6 quiz 10 cards 6 terms

Bulkheads & Isolation

Partitioning resources so one dependency cannot starve the others.

5 quiz 10 cards 6 terms

Leader Election

Agreeing who is in charge, and fencing the one who no longer is.

6 quiz 11 cards 5 terms

Consensus Protocols

Raft, Paxos and quorums — what they guarantee and what they cost.

2 quiz 7 cards 2 terms

Distributed Locking

Mutual exclusion across machines, and why it is harder than it looks.

4 quiz 9 cards 6 terms

Distributed Transactions

Two-phase commit, its blocking failure mode, and when it is still reasonable.

4 quiz 15 cards 5 terms

Sagas & Compensation

Replacing atomicity with semantic undo, and ordering the irreversible steps last.

6 quiz 11 cards 5 terms

Service Discovery

Finding a healthy address for something whose instances are ephemeral.

4 quiz 15 cards 4 terms

Messaging & Queues

Decoupling producer from consumer, and the semantics that come with it.

4 quiz 13 cards 3 terms

Event Streaming

Retained ordered logs, consumer offsets, partitions and replay.

6 quiz 16 cards 4 terms

Clocks & Ordering

Why wall clocks lie, and how logical clocks and versions restore order.

4 quiz 13 cards 2 terms