Supplement · Tomcat
30 câu hỏi từ architecture đến incident
Mỗi câu trả lời theo mental model → trade-off/failure → evidence; follow-up dùng để kiểm tra khả năng áp dụng.
30 câu hỏi
Architecture và protocol
1. Catalina và Coyote khác gì?
Catalina quản container/lifecycle/routing; Coyote quản socket và protocol parsing/serialization. Follow-up: metric nào thuộc connector, metric nào thuộc application?
2. Server, Service, Connector, Engine, Host, Context liên hệ thế nào?
Server chứa Services; Service ghép Connectors với Engine; Engine route Host rồi Context. Follow-up: hai HTTPS connector dùng chung Engine có hệ quả gì?
3. Request path đầy đủ?
Coyote accept/parse → Mapper → Valve pipeline → Filter chain → Servlet/application → response. Follow-up: RemoteIpValve nên chạy trước access log nào?
4. Valve khác Filter?
Valve thuộc Tomcat container pipeline và có Engine/Host/Context scope; Filter thuộc webapp/Servlet spec. Follow-up: cross-app audit nên đặt đâu?
5. NIO và NIO2 có nghĩa application nonblocking?
Không; connector I/O model không biến blocking Servlet/downstream thành nonblocking. Follow-up: chứng minh bằng thread dump/load test thế nào?
6. HTTP/2 giải quyết thread saturation?
Multiplex giảm connections/handshakes nhưng streams vẫn tạo request work và downstream concurrency. Follow-up: limit nào cần đặt per connection/stream?
7. Keep-alive trade-off?
Giảm handshake/latency nhưng giữ connection state và có thể chiếm capacity. Follow-up: proxy/backend timeout lệch gây gì?
8. Parser limits là performance hay security?
Cả hai: bound memory/CPU và giảm ambiguous parsing/DoS. Follow-up: tại sao proxy và Tomcat phải đồng nhất?
9. Response commit nghĩa gì?
Headers/status đã gửi nên error handler không thể an toàn thay response như trước commit. Follow-up: streaming failure log/status ra sao?
10. AsyncContext giải phóng gì và giữ gì?
Giải phóng request thread nhưng vẫn giữ request lifecycle, connection/context và work. Follow-up: timeout race với complete xử lý thế nào?
Capacity, classloading và deployment
11. maxThreads tăng có tốt?
Chỉ khi CPU/downstream có capacity; nếu không tăng queue, memory và tail latency. Follow-up: workload/evidence tối thiểu?
12. maxConnections và acceptCount khác gì?
Một cái bound active accepted connections, một cái backlog khi capacity reached; kernel queues vẫn là layer khác. Follow-up: client thấy timeout hay refuse khi nào?
13. Tìm queue đầu tiên tăng như thế nào?
Correlate connector/executor/app bulkhead/DB pool metrics cùng timeline và load constant. Follow-up: CPU thấp có loại trừ saturation?
14. Virtual-thread executor có bỏ max concurrency?
Không; chỉ giảm platform-thread scarcity, còn CPU/DB/remote quotas phải bound. Follow-up: semaphore nên đặt theo gì?
15. Class identity trong Java?
Binary name cộng defining ClassLoader; cùng tên khác loader không cùng type. Follow-up: giải thích ClassCastException “X cannot be cast to X”.
16. Webapp classloader delegation có gì đặc biệt?
Thường local-first theo Servlet rules, với protected Java/Jakarta/XML APIs. Follow-up: đặt library ở Common đổi điều gì?
17. Redeploy leak roots phổ biến?
Thread/executor, ThreadLocal, driver, timer, registry, static cache giữ old loader. Follow-up: evidence nào chứng minh loader collectible?
18. WAR và embedded JAR trade-off?
WAR chia sẻ external container; JAR sở hữu version/config/process lifecycle. Servlet semantics vẫn còn. Follow-up: ai chịu trách nhiệm patch Tomcat?
19. autoDeploy production risk?
File observation/race/partial artifact và lifecycle ngoài rollout control. Follow-up: immutable rollout thay thế thế nào?
20. Parallel deployment có zero downtime mặc định?
Không; session/schema/routing compatibility và cleanup quyết định. Follow-up: session cũ đi version nào?
State, edge security và operations
21. Sticky session có phải HA?
Không; giảm replication nhưng node loss có thể mất state. Follow-up: chaos test nào cần chạy?
22. DeltaManager và BackupManager trade-off?
Replicate rộng đơn giản nhưng tốn tài nguyên; backup giảm copies nhưng topology/failover phức tạp. Follow-up: large attribute ảnh hưởng p99?
23. Trust X-Forwarded-For khi nào?
Chỉ từ proxy trusted đã strip/overwrite client input. Follow-up: direct spoof test thiết kế ra sao?
24. RemoteIpValve và framework strategy dùng cùng lúc?
Có nguy cơ double-processing; chọn một ownership rõ và test effective scheme/IP. Follow-up: redirect poisoning biểu hiện gì?
25. TLS ở proxy hay Tomcat?
Theo threat/compliance/key ownership; edge termination, re-encrypt hoặc mTLS có trade-off. Follow-up: test rotation không downtime thế nào?
26. AJP có cần không?
Chỉ enable khi architecture cần; private bind/firewall/secret/current patch. Follow-up: HTTP proxy thay được khi nào?
27. Manager/JMX hardening?
Network isolation, strong authz, TLS, audit và tách deploy/monitor credentials. Follow-up: endpoint nào đang exposed được inventory thế nào?
28. p99 cao nhưng Tomcat busy threads thấp?
Có thể queue ngoài connector, async/downstream, locks, DNS/TLS hoặc client/proxy. Follow-up: falsify DB-pool hypothesis?
29. Graceful shutdown đúng thứ tự?
Remove readiness → stop intake → drain sync/async → stop background work → close pools → exit trước grace. Follow-up: committed work policy là gì?
30. Điều tra memory tăng sau nhiều redeploy?
Count loaders/classes, thread dump, heap dominators, NMT/RSS; reproduce controlled redeploy và fix owner. Follow-up: restart có được coi root-cause fix?