4 ms·
The concept at least seems insanely useful with EC2 spot instances - I’ve always wondered what’s the easiest way to transfer stream connections to another host
by leohonexus 4y ago
The concept at least seems insanely useful with EC2 spot instances - I’ve always wondered what’s the easiest way to transfer stream connections to another host pending imminent shutdown without the client experiencing any downtime.
It might even be possible to run a service fully on a moderate fleet of ephemeral instances and save over half of the EC2 costs.
- kreetx 4y agoWhat about using a load balancer in front of any two instances?
- toast0 4y agoa) how do you handle pending shutdown of a load balancer b) sure ok, if it's an http load balancer, you can finish up the existing requests and any new requests will go to new servers; but if it's a tcp load balancer, those don't generally let you swap the server in the middle
- wanderer_ 4y agoHeh, I guess screw them and shut it down anyway - at least that seems to be the policy in my IT department :)
- kevin_nisbet 4y agoa) There are several load balancers that allow sharing the state tables. So if you control the network, you share/transfer state tables ahead of removing the LB node from routing. Can even be the same IP with ECMP. I don't know how you would do this on something like an AWS network. b) In general your right, but this is already a fairly niche use case. But I do wonder if reprogramming the conntrack entry in linux would work, or for lvs which already has a userspace daemon for state synchronization, how it would behave if reprogramming an existing state. It's at least not implausible to do that rewrite somewhere real time... if you control the edge system. Also, again in a you control the network scenario, OpenFlow switches might allow you to reprogram the state tables while they're live.
- touisteur 4y agonetlink has all you need https://github.com/tgraf/libnl/blob/master/src/nf-ct-add.c https://github.com/tgraf/libnl/blob/master/src/nf-ct-add.c The Linux kernel stack is crazy.
- leohonexus 4y agoFor conntrack, one possibility might be to bypass conntrack on incoming connections using `iptables -j NOTRACK`, effectively making the firewall stateless.
- Thaxll 4y agoThis does not work AZ / zones most likely, also how do you transfert the state from the upstream routers?
- oh_sigh 4y agoOut of curiosity, is there something protcol-agnostic that is better than lameduck mode?