8 ms·
I mean, not to defend them too strongly, but literally half of this post mortem is addressing the failure of the Service Dashboard. You can take it on bad faith
by amalter 5y ago
I mean, not to defend them too strongly, but literally half of this post mortem is addressing the failure of the Service Dashboard. You can take it on bad faith, but they own up to the dashboard being completely useless during the incident.
- dijit 5y agoOnce is a mistake. Twice is a coincidence. Three times is a pattern. But this… This is every time.
- doctor_eval 5y agoFour times is a policy.
- s_dev 5y ago>You can take it on bad faith It's smart politics -- I don't blame them but I don't trust the dashboard either. There's established patterns now of the AWS dashboard being useless. If I want to check if Amazon is down I'm checking Twitter and HN. Not bad faith -- no faith.
- sorry_outta_gas 5y agoThat's only useful when it's an entire region, there are minor issues in smaller services that cause problems for a lot of people they don't reflect in their status board; and not everyone checks twitter or HN all the time while at work it's a bullshit board used fudge numbers when negoaiting SLAs like I don't care that much, hell my company does the same thing; but let's not get defensive over it
- toss1 5y ago>>It's smart politics -- I don't blame them Um, so you think straight-up lying is good politics? Any 7-year old knows that telling a lie when you broke something makes you look better superficially, especially if you get away with it. That does not mean that we should think it is a good idea to tell lies when you break things. It sure as hell isn't smart politics in my book. It is straight-up disqualifying to do business with them. If they are not honest about the status or amount of service they are providing, how is that different than lying about your prices? Would you go to a petrol station that posted $x.00/gallon, but only delivered 3 quarts for each gallon shown on the pump? We're being shortchanged and lied to. Fascinating that you think it is good politics on their part.
- efitz 5y agoYou don’t know what you’re talking about. AWS spends a lot of time thinking about this problem in service to their customers. How do you reduce the status of millions of machines, the software they run, and the interconnected-ness of those systems to a single graphical indicator? It would be dumb and useless to turn something red every single time anything had a problem. Literally there are hundreds of things broken every minute of every day. On-call engineers are working around the clock on these problems. Most of the problems either don’t affect anyone due to redundancy or affect only a tiny number of customers- a failed memory module or top-of-rack switch or a random bit flip in one host for one service. Would it help anyone to tell everyone about all these problems? People would quickly learn to ignore it as it had no bearing on their experience. What you’re really arguing is that you don’t like the thresholds they’ve chosen. That’s fine, everyone has an opinion. The purpose of health dashboards like these are mostly so that customers can quickly get an answer to “is it them or me” when there’s a problem. As others on this thread have pointed out, AWS has done a pretty good job of making the SHD align with the subjective experience of most customers. They also have personal health dashboards unique to each customer, but I assume thresholding is still involved.
- Karunamon 5y ago>How do you reduce the status of millions of machines, the software they run, and the interconnected-ness of those systems to a single graphical indicator? A good low-hanging fruit would be, when the outage is significant enough to have reached the media, you turn the dot red. Dishonesty is what we're talking about here. Not the gradient when you change colors. This is hardly the first major outage where the AWS status board was a bald-faced lie. This deserves calling out and shaming the responsible parties, nothing less, certainly not defense of blatantly deceptive practices that most companies not named Amazon don't dip into.
- efitz 5y agoHuman-in-the-loop != lying. Broken dashboard != lying. The specific charge of “lying” is what I dispute.
- systemvoltage 5y agoPeople of HN has been extremely unprofessional with regards to AWS's downtime. Some kind of a massive zeitgeist against Amazon, like a giant hive mind that spews hate. Why are we doing this folks? What's making you so angry and contemptful? Literally try searching the history of downtimes and it was always professional and respectful. Yesterday, my comment was fricking flagged for asking people to be nice to which people responded "Professionals recognize other professionals lying". Completely baseless and hate spewing comments like this is ruining HN.
- NicoJuicy 5y agoI think the biggest issue is about the status dashboard that always stays green. I haven't seen much else, no? It seems that degraded seems down in most cases. Since authorization of managers is required.
- jiggawatts 5y agoAWS as a business has an enormous (multi-billion-dollar) moral hazard: they have a fantastically strong disincentive to update their status dashboard to accurately reflect the true nature of an ongoing outage. They use weasel words like "some customers may be seeing elevated errors", which we all know translates to "almost all customers are seeing 99.99% failure rates." They have a strong incentive to lie, and they're doing it. This makes people dependent upon the truth for refunds understandably angry.
- ProAm 5y ago> Why are we doing this folks? What's making you so angry and contemptful? Because Amazon kills industries. Takes job. They do this because they promise they hire the best people that can do this better than you and for cheaper. And it's rarely true. And then they lie about it when things hit the fan. If you're going to be the best you need to act like the best, and execute like the best. Not build a walled garden that people cant see into, and hard to leave.
- edoceo 5y agoAll too often folk conflate frustration with anger or hate. The comments are frustrated users. Not hateful.
- luhn 5y agoOff the top of my head, this is the third time they've had a major outage where they've been unable to properly update the status page. First we had the S3 outage, where the yellow and red icons were hosted in S3 and unable to be accessed. Second we had the Kinesis outage, which snowballed into a Cognito outage, so they were unable to login into the status page CMS. Now this. They "own up to it" in their postmortems, but after multiple failures they're still unwilling to implement the obvious solution and what is widely regarded as best practice: host the status page on a different platform.
- koheripbal 5y agoThis challenge is not specific to Amazon. Being able to automatically detect system health is a non-trivial effort.
- bob778 5y agoThat’s not what’s being asked though - in all 3 events, they couldn’t manually update it. It’s clearly not a priority to fix it for even manual alerts.
- blackearl 5y agoWhy automatic? Surely someone could have the responsibility to do it manually.
- geenew 5y agoOr override the autogenerated values
- jjoonathan 5y agoThey had all day to do it manually.
- saagarjha 5y agoAs others mention, you can do it manually. But it’s also not that hard to do automatically: literally just spin up a “client” of your service and make sure it works.
- tw04 5y agoMultiple AWS employees have acknowledged it takes VP approval to change the status color of the dashboard. That is absurd and it tells you everything you need to know. The status page isn't about accurate information, it's about plausible deniability and keeping AWS out of the news cycle.
- dylan604 5y ago>it's about plausible deniability and keeping AWS out of the news cycle. How'd that work out for them? https://duckduckgo.com/?q=AWS+outage+news+coverage&t=h_&ia=web https://duckduckgo.com/?q=AWS+outage+news+coverage&t=h_&ia=w...
- tw04 5y agoWhen is the last time they had a single service outage in a single region? How about in a single AZ in a single region? Struggling to find a lot of headline stories? I'm willing to bet it's happened in the last 2 years and yet I don't see many news articles about it... so I'd say if the only thing that hits the front page is a complete region outage for 6+ hours, it's working out pretty well for them.
- grumple 5y agoLast year's Thanksgiving outage and this one are the two biggest. They've been pretty reliable. That's still 99.7% uptime.
- cookie_monsta 5y agoI am so naive. I honestly thought those things were automated.
- discodave 5y agoThe AWS summary says: "As the impact to services during this event all stemmed from a single root cause, we opted to provide updates via a global banner on the Service Health Dashboard, which we have since learned makes it difficult for some customers to find information about this issue" This seems like bad faith to me based on my experience when I worked for AWS. As they repeated many times at Re:Invent last week, they've been doing this for 15+ years. I distinctly remember seeing banners like "Don't update the dashboard without approval from <importantSVP>" on various service team runbooks. They tried not to say it out loud, but there was very much a top-down mandate for service teams to make the dashboard "look green" by: 1. Actually improving availability (this one is fair). 2. Using the "Green-I" icon rather than the blue, orange, or red icons whenever possible. 3. They built out the "Personal Health Dashboard" so they can post about many issues in there, without having to acknowledge it publicly.
- res0nat0r 5y agoEh I mean at least when DeSantis was lower on the food chain then he is now, the normal directive was that ec2 status wasn't updated unless a certain X percent of hosts were affected. Which is reasonable because a single rack going down isn't relevant enough to constitute a massive problem with ec2 as a whole.
- ProAm 5y ago> You can take it on bad faith, but they own up to the dashboard being completely useless during the incident. Let's not act like this is the first time this has happened. It's bad faith that they do not change when their promise is they hire the best to handle infrastructure so you don't have to. It's clearly not the case. Between this and billing I we can easily lay blame and acknowledge lies.
- nwallin 5y agoSo -- ctrl-f "Dash" only produces four results and it's hidden away in the bottom of the page. It's false to claim that even 20% of the post mortem is addressing the failure of the dashboard. The problem is that the dashboard requires VP approval to be updated. Which is broken. The dashboard should be automatic. The dashboard should update before even a single member of the AWS team knows there's something wrong.
- hunter2_ 5y agoIs it typical for orgs (the whole spectrum: IT departments everywhere, telecom, SaaS, maybe even status of non-technical services) to have automatic downtime messaging that doesn't need a human set of eyes to approve it first?