Health Check & Service Discovery  ·  View 18 of 21  ·  Operations

Instance Lifecycle

Eight states, and no edge that returns an instance straight to Serving.

Editable source SVG draw.io All views
Registered identity assigned Probed contract applied Ramping weight rising 60 s Serving full weight Suspect score decaying Withdrawn or quarantined Draining budget checked Deregistered or lease expired Instance lifecycle first readiness pass admitted, weight 0.1 ramp complete failure rate rises threshold crossed recovered, re-entry slower grace period ends replacement registers Instance Lifecycle — A Loop That Closes Application we own Security / platform Interface / broker Decision point Risk / gap External / third party Withdrawn returns to Draining or to Ramping — never straight to Serving. Re-entry is always the slow direction. v 1.0 · owner Reliability Architecture

What closes the loop

  • Withdrawn returns via Ramping, never directly to Serving: re-entry is always the slow direction (ADR-07).
  • Draining is a state with a budget check in front of it, which is what makes a deploy refusable.
  • Deregistered is reached either by graceful exit or by lease expiry, and the two are recorded as different outcomes.

Assumptions

  • 2,500 instance state changes a minute at steady state across 60,000 instances.

Consequence

  • Because every transition is recorded with its cause, the flap report is a query rather than a new subsystem.