Health Check & Service Discovery  ·  View 07 of 21  ·  Structure

Layered Architecture

Seven layers. Six of them are allowed to be unavailable for an hour.

Editable source SVG draw.io All views
1 · Sources of truth EKS endpoint state ECS + ASG state Service catalogue External declarations 2 · Registry Services + contracts Instances + leases Topology + policy 3 · Signal collection Active probers Self-report ingest Passive outcomes 4 · Evaluation Signal fusion Hysteresis + quarantine Fraction guard Weights + slow start 5 · View assembly Versioned views Filters + tiers Delta encoder 6 · Propagation xDS stream tier DNS authority Resolution API 7 · Client data plane Last-known-good cache Outlier ejection Shrink cap Route selection reconcile probe assignment outcomes eligibility versioned delta push outcomes Layered Architecture — Only Layer 7 Is In The Request Path External / third party Data store Security / platform Interface / broker Application we own synchronous event / async Layers 1 to 6 are advisory. Layer 7 keeps routing from cache for 60 minutes with none of them available. v 1.0 · owner Reliability Architecture

The rule the layering encodes

  • Only layer 7 is in the request path. Layers 1 to 6 improve the view that layer 7 already holds.
  • The outcome signal travels upward from layer 7 to layer 3 — the only arrow in the set that goes against the stack.
  • Nothing in layer 7 asks a question of layers 1 to 6 synchronously.

Assumptions

  • 60,000 concurrent xDS subscriptions, served by a tier that must survive its own deploys.
  • Client cost ceiling: 1% of each application instance's CPU.

Consequence

  • Every guard that bounds a wrong decision has to exist twice — once in evaluation, once in the client.