6 ms·
What is the use cases for having the TTL shorter than 5 minutes?
by JimWestergren 6y ago
What is the use cases for having the TTL shorter than 5 minutes?
- deleted 6y ago[deleted]
- nathanaldensr 6y agoThe article posits why: Why are DNS records set with such low TTLs? - Legacy load balancers left with default settings - The urban legend that DNS-based load balancing depends on TTLs (it doesn’t - since Netscape Navigator, clients pick a random IP from a RR set, and transparently try another one if they can’t connect) - Administrators wanting their changes to be applied immediately, because it may require less planning work. - As a DNS or load balancer administator, your duty is to efficiently deploy the configuration people ask, not to make websites and services fast. - Low TTLs give peace of mind. - People initially use low TTLs for testing, and forget to crank them up later.
- JimWestergren 6y agoBut those are no valid use cases which was my question. So there are no valid use cases at all?
- hiq 6y ago> Administrators wanting their changes to be applied immediately, because it may require less planning work. Why is this not valid?
- JimWestergren 6y agoBut 5 minutes should be fine? It surprised me that so many has 1 second or 20 second TTL.
- samvher 6y agoIf I need to get a web service up and I can save 4 minutes by setting a low TTL when I configure my DNS record why wouldn't I?
- gertrunde 6y agoBecause you're pushing the cost on to someone else. If your DNS hosting provider charged you per query (some do, especially when adding features like health checks & load balancing), then it might make a big difference.
- fomine3 6y agoValid migration plan should be able to handle it without very short TTL.
- prophesi 6y agoA low DNS TTL for testing purposes is a valid use case.
- majewsky 6y agoThis is about production systems of large enterprises. ... Please tell me you're not testing in production.
- JimWestergren 6y agoFound an earlier HN discussion about this question from November 2019: https://news.ycombinator.com/item?id=21437160 https://news.ycombinator.com/item?id=21437160
- gwittel 6y agoThe major cases revolve around failure recovery, and traffic distribution. A 5 minute outage is not acceptable in many industries or at scale. If a load balancer or DC fails we need to ensure traffic moves away fast. Similarly if you want to take a system out for maintenance or perform migrations.
- marcosdumay 6y ago> A 5 minute outage is not acceptable in many industries or at scale. Well, if that's the case, you better have your redundant systems on your normal DNS entries, because there is no chance you will distribute new entries over the internet in 5 minutes, whatever value you specify at the TTL.
- toast0 6y agoThere are tons of things that don't follow TTLs, but a large majority of normal people traffic does. Easily 90% of new connections will move following the TTL. Of course, some traffic got a DNS result once in 2003 and is going to use that forever. If it's important traffic, you can trace it and follow up with them. If not, you do the best you can and let the rest go.
- cortesoft 6y agoThe DNS based load balancing isn’t a myth if you want to do any kind of load balancing that isn’t round robin. If you want to, say, send 10% of traffic to data center A and 90% to data center B, and you don’t want to use up 10 IPs to do that.
- codyb 6y agoI always was under the impression people lowered the TTL when updating records... which doesn't even really make sense since the change won't propagate until the previous TTL is overrun anyways. Then you were supposed to update it to a longer TTL when your change had propagated. So, I guess, after understanding things better... there is no use case really since if it's a new record your change will always propagate, and if it's an old record, lowering the TTL on update doesn't really matter since the old TTL will still be in effect.
- irishsultan 6y agoYou could lower TTL if you know a change is coming.
- ilikepi 6y agoExactly. The TTL is lowered in advance of the maintenance window, sufficiently far out to allow any entries with the old TTL to expire from most resolvers. Once the maintenance has been completed and validated, and sufficient time has elapsed to decide there are no issues requiring roll back, the TTL is raised back up to its stable value.
- aequitas 6y agoIt could help to lower your TTL way before you plan to update. If your current TTL was 24h, you just update it to 5m 24 hours before you plan the actual change of the record itself. The new record can them be set to 24h directly (unless you want a quick turnaround for rollback). It's still no guarantee all changes will propagate within 5 minutes. But it gives some ease of mind to know the bulk of change won't take a day. Also a lot of people forget the negative caching of NXDOMAIN records which is set by the TTL of the SOA record. Which means that it will take a while for your new record to be resolved if you started querying before you set the record.
- mschuster91 6y ago> It's still no guarantee all changes will propagate within 5 minutes. But it gives some ease of mind to know the bulk of change won't take a day. Especially it gives you peace of mind that should stuff go badly wrong you can easily revert the change.
- benmmurphy 6y agoAWS application load balancers have records with a TTL of 60s. Presumably they are doing it because they want the flexibility to change the IP addresses or the number of IP addresses dynamically. Seems like a reasonable use case.
- krzyk 6y agoMaybe for those cases where one can get random IP from their ISP and has a e.g. hopto.org configured? One would probably be OK if it was 5 or 10 mins, but it depends on what's behind that dns entry and how often ISP can change the IP.
- abricot 6y agoDo any ISPs generally change dynamic IPs more often than modem/routers reboot?
- majewsky 6y agoSome ISPs do it on a daily schedule. I know that the German Telekom rotates customer IPs every night at 01:45 AM, because a friend of mine is with them and that's the time when he drops from the video conference for a minute (if we stick around that long).
- rebelde 6y agoWindows Update. To reboot a server, you need to take it out of production. With a TTL of 5 minutes, it can take an hour for (nearly) all users to stop using that server.
- yjftsjthsd-h 6y agoSorry - why would a 5m TTL take an hour to stop using? Shouldn't it be 5 minutes?
- Twirrim 6y agoIf things behaved nicely, yes. There's all sorts of weird DNS caching behaviour out there. It's not unusual to find folks with DNS servers / clients that are caching records for 1 hour+, and then of course there's people running super old versions of Java that used to cache DNS forever by default (before JDK 6). There's a very clear set of user that seem to cache for 10-15 minutes, regardless of any DNS TTL.
- marcosdumay 6y agoYou can't fix systems that ignore your TTL by specifying lower TTL values.
- Twirrim 6y agoSure. My general approach is to use lower TTL values (~ 5 minutes) and just accept that if people do dumb things, they just have to put up with things randomly breaking unexpected.
- EricE 6y agoGood grief- you do not need to reboot the server; just flush the cache https://www.dnsstuff.com/clear-flush-dns-server-cache-windows https://www.dnsstuff.com/clear-flush-dns-server-cache-window...
- 6y ago
- linsomniac 6y agoWe have a service that uses AWS Route53 health checks, and set the records to 60s TTL because if there is a problem at the primary service fails healthcheck, we want it to get the updated DNS records, which point to another data center, fairly quickly. In our case, primary is AWS with a protection service in front of it, and secondary is our own servers at a data center. So something like VRRP wouldn't work.
- cortesoft 6y agoDNS based network load balancing. If you have two data centers, and you want to be able to dynamically and deterministically shift load between them, you want a short TTL so you can control the percentage of traffic going to each data center.
- numbsafari 6y agoIf you want to deterministically shift load, you use routing, not DNS, to manage your load. That’s what is missing from this discussion.
- cortesoft 6y agoHow would you use routing to balance load at that granularity?
- EricE 6y agoRather easily. There are routing protocols designed for such things. Far more reliable than trying to hijack DNS for load balancing. Indeed the root DNS servers are not a single server but pools of geographically distributed servers via anycast.
- cortesoft 6y agoAnycast doesn't support percentage based load balancing unless you control all the hops between client and server, which is almost never the case if you are serving the public. Every request that comes from the same network is going to be routed the same way. Anycast works great for regional load balancing in general, but it doesn't work for subdividing individual networks.
- numbsafari 6y agoRather than get into a lot of details, here's some excellent starting points: [1] Google Cloud networking in depth: Cloud Load Balancing desconstructed - https://cloud.google.com/blog/products/networking/google-cloud-networking-in-depth-cloud-load-balancing-deconstructed https://cloud.google.com/blog/products/networking/google-clo... [2] What is AWS Global Accelerator: https://docs.aws.amazon.com/global-accelerator/latest/dg/what-is-global-accelerator.html https://docs.aws.amazon.com/global-accelerator/latest/dg/wha... [3] Tumblr: Hashing Your Way To Handling 23,000 Blog Requests Per Second: http://highscalability.com/blog/2014/8/4/tumblr-hashing-your-way-to-handling-23000-blog-requests-per.html http://highscalability.com/blog/2014/8/4/tumblr-hashing-your... [4] Load Balancing without Load Balancers: https://blog.cloudflare.com/cloudflares-architecture-eliminating-single-p/ https://blog.cloudflare.com/cloudflares-architecture-elimina...