Earlier quoted context omitted.
Smoke tests or gradual rollout won’t help with the change by fastly on May 12 when they deployed the buggy change. It’s likely that this was gradually rolled out and looked ok with all customer configs existing on May 12. Obviously there should be other safeguards in place but gradual rollout in itself wouldn’t have helped since it would look green at a 100% rollout weeks ago.
I meant smoke testing and gradual rollout of the config, not the code, although obviously that's important too.
Summary of June 8 outage
71–80 of 110 posts
Re: Summary of June 8 outage
#72Earlier quoted context omitted.
Test “it”? The change in question wasn’t by fastly but a customer of theirs making a config change. It’s possible that this customer did validate their change somehow. Fastly obviously didn’t test their code (with the bug) enough, but testing of course can never prove the absence of bugs. Testing for a global deployment like a massive CDN happens to a large extent in prod because you don’t have another globe. You can…
Fastly even say it was a valid change. > We experienced a global outage due to an undiscovered software bug that surfaced on June 8 when it was triggered by a valid customer configuration change. in the first sentence
The customer change was a valid configuration. That was yesterday.
Re: Summary of June 8 outage
#73* Bug was introduced on date X but only caused problems on date Y ("if the bug was introduced on date X then we would have seen it on date X, so you’re wrong")
* Doing X led to the outage but X wasn’t the fault, X was a valid thing to do, the code should have been able to handle X, the fact the code couldn't handle it was the actual problem which needs to be fixed ("look, you said X caused the problem, so the solution is just not to do X right?")
This article conveys both these points clearly and effortlessly. I might borrow some terminology from this in the future.
Re: Summary of June 8 outage
#74I love that somewhere out there is a developer who doesn't even work at Fastly but just innocently pushed a change to their Fastly config and basically broke the entire internet. I'm actually jealous. If it was me, I'd put that on my resume.
Re: Summary of June 8 outage
#75Re: Summary of June 8 outage
#76Wasn't there a failover or some redundency from Fastly in place during this outage?
No doubt, but there's always a way to smoke the whole thing, even with all the fail safe and redundancy in the world.
Re: Summary of June 8 outage
#77Earlier quoted context omitted.
A web filled with DDOS attacks and scraping is a web that needs cloudflare and fastly. I’m not sure how to avoid this sorry state of things.
Invisible Internet Project (I2P) is decentralized and defends from such attacks quite well.
Re: Summary of June 8 outage
#78I'm still a little annoyed at their status page [0]. It says:
> We're currently investigating potential impact to performance with our CDN services.
yet in the blog post we're talking about here it says:
> Early June 8, a customer pushed a valid configuration change that included the specific circumstances that triggered the bug, which caused 85% of our network to return errors.
85% of your network returning errors is _not_ a potential performance impact.
Re: Summary of June 8 outage
#79Earlier quoted context omitted.
Lots of tech companies have engineering offices with SRE responsabilities in Europe timezones. Could be anyone really.
My guess is this level of change would come from senior devs in the main office.
Also, just because the rollout to fastly happened at a morning EU time, doesn't mean that the change was made. If there's a deployment pipeline, it could have been made 2-3 hours earlier, or even the day before
Re: Summary of June 8 outage
#80Earlier quoted context omitted.
My guess is this level of change would come from senior devs in the main office.
Are you implying that no senior devs or main offices are located in europe? Also, just because the rollout to fastly happened at a morning EU time, doesn't mean that the change was made. If there's a deployment pipeline, it could have been made 2-3 hours earlier, or even the day before