Service Mesh Platform  ·  View 19 of 31  ·  5 · Runtime

Cross-Cluster Failover

The local ledger pods fail, the caller spills to cluster c12 through an east-west gateway, and ledger still sees checkout as the caller.

Editable source SVG draw.io All views
checkout · c07 checkout proxy · c07 ledger pods · c07 East-west gateway · c12 ledger proxy · c12 ledger app · c12 1. GET ledger/balance 2. try local zone 3. 5 consecutive 503s 4. eject · local healthy below 70% 5. TLS · SNI names ledger subset 6. bytes forwarded, TLS untouched 7. peer is c07/checkout · allowed 8. request 9. 200 10. 200 · spillover counted Cross-Cluster Failover — The Caller's Identity Arrives Intact The gateway reads SNI and nothing else. It holds no workload identity, so it cannot be the caller. v 1.0 · owner Platform Networking Architecture · date 2026-09

Decisions

  • The east-west gateway routes on SNI and passes TLS through untouched. It holds no workload identity, so the destination authorises the original caller and nobody else.
  • Spillover starts when fewer than 70% of local endpoints are healthy. The threshold is declared per destination, not left to a default, because it is a cost decision as much as a latency one.
  • Remote endpoints come only from services the owning cluster has exported. A cluster's whole service list is never merged into another's discovery.

Targets

  • Loss of one cluster needs no configuration change anywhere else. Survivors degrade to their own capacity and outlier detection removes the lost cluster's endpoints.

Cost signal

  • Every spilled request is counted by source and destination locality. Cross-cluster bytes appear in the monthly cost report next to the team that caused them.