4 ms·
> "our redundancy all runs through the same conduit and ninjas chopped it in half during a new buildout." You can just consider that as a failure of the whole
by devit 11y ago
> "our redundancy all runs through the same conduit and ninjas chopped it in half during a new buildout."
You can just consider that as a failure of the whole datacenter.
The ninjas could just as well chop all the external network connections, which would result in actual datacenter failure (from a client/service PoV), so it shouldn't increase the rate that much.
- seiji 11y agoYou don't always have a choice: http://farm3.static.flickr.com/2316/2216487046_b7ca640f56_o.jpg http://farm3.static.flickr.com/2316/2216487046_b7ca640f56_o.... Plus, we live in cloud la la land these days. You have no idea how any of your machines/VMs are connected together. We can assume nothing.
- rdtsc 11y agoThat's not the same thing. A network partition is not equivalent to the the whole datacenter being off nice and clean. That would be nice actually, because it is an and easily testable failure mode. Network partition due to misconfiguration will happen and they have verious interesting corner cases -- multiple plartitions or say partitions between servers but not between clients (clients see the servers, server don't see each other). You can of course say "it will never happen" and just let chance decide what happens do the data in case when a partition happen.
- devit 11y agoNo, the system needs to be properly designed to be consistent, so the data will always be fine (as long as you don't permanently lose all the servers and backups). Partitions and datacenter failures only determine whether the system is up or not, and thus its availability properties.