Health Check & Service Discovery  ·  View 02 of 21  ·  Context and scope

High-Level Architecture

Five stages, and a seam between the fourth and the fifth that the rest of the set is about.

Editable source SVG draw.io All views
Observe Active probers sharded, bounded fan-out Self-report ingest readiness + deps Passive outcome ingest reported by callers Decide Signal fusion 3 evidence classes Hysteresis + flap damper decaying score Min-healthy-fraction guard 50% floor Assemble Versioned view builder monotonic versions Topology priority tiers zone, region, cross Publish xDS stream tier incremental deltas DNS authority compatibility surface Resolution API tooling only Route Last-known-good cache durable, per client Envoy data plane ejection, shrink cap request outcomes serves on outage High-Level Architecture — Observe, Decide, Publish, Route Security / platform Interface / broker Application we own Data store event / async failure / alternate The seam is between Publish and Route: everything left of the cache may fail for an hour without changing where traffic goes. v 1.0 · owner Reliability Architecture

Decisions

  • Observe, Decide, Assemble and Publish are all advisory. Route is authoritative, and it is the only stage in the request path.
  • The sidecar reports the outcomes it saw back into Observe: the only health signal that cannot be self-reported or faked.
  • Three publication surfaces with identical semantics, so a client's capability never changes what health means.

Why this shape

  • A control plane that can be switched off for an hour can be deployed, patched and tested like anything else.
  • Making the cache the authority moves every safety mechanism into the client, which is the cost this design accepts.

Risks

  • The cache is the one durable copy on the request path the platform cannot restore — a client that loses it starts cold.
  • An hour of static serving is an hour of routing on stale truth. Verified by drill, not assumed.