Part 09 · Distributed Systems

Cascading failure, circuit breaker và bulkhead

Overload là positive feedback loop: latency tăng → in-flight/retry tăng → capacity hữu ích giảm → latency tăng thêm.

Circuit breaker

Closed cho call; open fail fast; half-open cho số probe giới hạn. Phân loại failure đúng: 4xx business/client không nên mở circuit như timeout/5xx. Breaker không chữa dependency; fallback phải semantically correct và observable.

Bulkhead

Giới hạn concurrency/queue/pool theo dependency hoặc workload để một downstream chậm không chiếm hết threads/connections. Queue bounded; reject sớm thường tốt hơn nhận rồi timeout sau khi tiêu resource.

Load shedding và backpressure

Admission control theo priority, concurrency, rate hoặc deadline. Caller phải hiểu overload response và backoff. Scale callers khi DB đã saturated có thể làm incident nặng hơn.

Operational design

Metrics: concurrency, queue time, rejection, timeout, breaker state, half-open success, retry attempts và downstream saturation. Cho operator force open/close thận trọng; state transition phải concurrency-safe.

Cascading failure là positive feedback loop

Một replica mất làm load dồn sang phần còn lại; latency, in-flight work, memory, threads, GC và missed deadlines tăng. Retry tiếp tục bơm thêm work trong khi useful capacity giảm. Scale thêm caller hoặc giữ queue vô hạn khi database/dependency đã saturated có thể làm successful throughput thấp hơn.

Circuit breaker trong vận hành

Half-open chỉ cho một số probe có giới hạn; transition phải concurrency-safe. Expiry không nên bị failing threads liên tục đẩy ra xa. Operator có thể cần force open/close theo runbook, nhưng mọi override phải observable và có thời hạn.

Senior follow-up: giải thích vì sao retry làm giảm throughput khi overload, queue vô hạn biến overload thành latency/memory failure, cancellation giảm zombie work, scale callers có thể làm database tệ hơn và half-open probes phải được giới hạn.
Addressing Cascading Failures · AWS Circuit Breaker · Resilience4j