Incident Management Platform  ·  View 24 of 34  ·  5 · Runtime

A DST Boundary — Found Nine Days Early, Not at 02:30

A rotation's handoff time does not exist on the spring-forward night. Two resolvers disagree about what that means, and that disagreement is the warning.

Editable source SVG draw.io All views
T − 14 d T − 9 d T − 72 h 02:00 local After Resolver Handoff at 02:30 local Instant does not exist Buckets materialised Verifier Second resolver disagrees Both agree after fix Rotation owner Gap warning received Override 01:00–04:00 Asleep Snapshot Old buckets held Verified buckets live Served unchanged Paging Page lands on override Audit names who A DST Boundary — Found Nine Days Early, Not at 02:30 Nothing about the clock change is computed on the night. The resolver's rule for a missing local time is to hand over at the next valid instant, and the verifier checks it did. v 1.0 · owner Reliability Architecture · date 2026-09

Decisions

  • Rotations are defined in local wall-clock time in a named IANA zone, because that is how people agree to be on call. Everything materialised and everything stored is UTC.
  • The rule for a local time that does not exist is to hand over at the next valid instant; for a local time that happens twice, at the first occurrence. Both are written down and both resolvers implement them independently.
  • Buckets for the boundary are materialised and verified 72 hours before it. Nothing about the clock change is computed on the night.

Proof

  • Every release runs schedule resolution for all 25 rotations across every DST transition in their zones until 2030, against both implementations. A zone rule change upstream is rolled out as a release and re-verified the same way.

What the owner sees

  • A warning naming the rotation, the night, the local interval and what each resolver produced, with a one-click override for the gap. Not a stack trace.