Chaos Engineering Platform · View 16 of 21 · Operations
Decisions
- Guardrail and lease state is regionally partitioned. Nothing in the abort path crosses a region, because the abort budget is 10 seconds and a cross-region round trip spends too much of it.
- The safety plane is deployed separately in both regions with its own service account, and its RTO is 60 seconds against the control plane's 30 minutes.
- The agent runs as a DaemonSet in a dedicated namespace, so its resource envelope is visible to the node's own autoscaling rather than hidden inside a workload.
Assumptions
- europe-west1 control, us-east4 warm replica, six regional GKE clusters across three regions.
- Control plane RTO 30 min, abort path RTO 60 s, reporting plane RTO 4 h.
- Loss of one region leaves no in-flight fault persisting anywhere in that region.
Risks
- A warm replica that is never exercised is a hope. The self-chaos suite on view 17 has to include failing over the lease issuer.