Cascading failure, circuit breaker và bulkhead
Overload là positive feedback loop: latency tăng → in-flight/retry tăng → capacity hữu ích giảm → latency tăng thêm.
Circuit breaker
Closed cho call; open fail fast; half-open cho số probe giới hạn. Phân loại failure đúng: 4xx business/client không nên mở circuit như timeout/5xx. Breaker không chữa dependency; fallback phải semantically correct và observable.
Bulkhead
Giới hạn concurrency/queue/pool theo dependency hoặc workload để một downstream chậm không chiếm hết threads/connections. Queue bounded; reject sớm thường tốt hơn nhận rồi timeout sau khi tiêu resource.
Load shedding và backpressure
Admission control theo priority, concurrency, rate hoặc deadline. Caller phải hiểu overload response và backoff. Scale callers khi DB đã saturated có thể làm incident nặng hơn.
Operational design
Metrics: concurrency, queue time, rejection, timeout, breaker state, half-open success, retry attempts và downstream saturation. Cho operator force open/close thận trọng; state transition phải concurrency-safe.
Cascading failure là positive feedback loop
Một replica mất làm load dồn sang phần còn lại; latency, in-flight work, memory, threads, GC và missed deadlines tăng. Retry tiếp tục bơm thêm work trong khi useful capacity giảm. Scale thêm caller hoặc giữ queue vô hạn khi database/dependency đã saturated có thể làm successful throughput thấp hơn.
Circuit breaker trong vận hành
Half-open chỉ cho một số probe có giới hạn; transition phải concurrency-safe. Expiry không nên bị failing threads liên tục đẩy ra xa. Operator có thể cần force open/close theo runbook, nhưng mọi override phải observable và có thời hạn.