Live data from Hacker News

Incident Report: Railway Blocked by Google Cloud [resolved]

status.railway.com

221–230 of 381 posts

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#221

May 2024 UniSuper incident: https://cloud.google.com/blog/products/infrastructure/detail... https://www.unisuper.com.au/about-us/media-centre/2024/a-joi... A joint statement from UniSuper CEO Peter Chun and Google Cloud CEO Thomas Kurian 8 May 2024 UniSuper and Google Cloud understand the disruption to services experienced by members has been extremely frustrating and disappointing. We extend our sincere apologies to…

I wrote about the UniSuper issue at the time: https://danielcompton.net/google-cloud-unisuper. It was a pretty nasty bug where their VMWare environment was created with a one-year expiry date, but was one "resource" from the perspective of Google Cloud.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#222
post #204

Earlier quoted context omitted.

GCP has a lot of customers. But you wouldn't know the companies that do, unless you worked there and wanted to leak it, or it publicly comes out. Eg it's been publicly acknowledged that Apple uses GCP for iCloud, https://www.cnbc.com/amp/2018/02/26/apple-confirms-it-uses-g... , and Home Depot is another that's used as a case study, https://cloud.google.com/customers/the-home-depot but most customers don't want to mak…

Apple also uses AWS, and I won't be surprised if they also use Azure. Big companies are multicloud, and not because it's a good idea (it rarely is), but because they inherited multiple environments on different CSPs, and maintaining those where they are is often cheaper than migrating them to a different CSP.

I wonder if big companies can get a special contract with something like you can't delete my service automatically (unless it's an emergency)

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#223
post #191
post #183

Earlier quoted context omitted.

Why does Railway deserve any blame here at all? It was an MCP with elevated infra access, that the user willingly connected through Cursor, which allowed an LLM Agent to manage infra on Railway. The user would first have gone through oAuth confirming the access level scope (I would have rejected the moment it indicates to me that it can delete critical infra and backups...). So obviously it has access to all commands…

Putting AI aside, people make mistakes. One of the most common mistakes people make is deleting the wrong thing. After they realize the mistake, people want to restore the thing they deleted from backups. Thus deleting the thing and deleting the backups of the thing should always be separate operations.

Absolutely.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#224

Is google allergic to humans or something? Cannot they just send an email or call the company before taking a wrecking ball to the entire company's infra? Are they stupid?

Keep the pitchforks at bay for now. No one knows what actually happened yet and we are only seeing one side of this outage.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#225

The 3-2-1 backup rule is pretty outdated in the world of cloud. You could have 3 complete copies of your data in different S3 buckets, but if they're all under the same account you've lost your blast radius protection

You replicate data to different clouds.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#226

How the heck do these things happen, especially with companies with huge monthly spend? At my last job we had some suspicious workloads running on AWS and our TAM reached out to us before taking any action. Who wants to bet this was some AI automation gone wrong and because GCP seems to be allergic to actually contacting a human to get a response, this just sits in some support queue that outsourced workers look at a…

Nothing surprises me with anything related to support on GCP. While we absolutely do not need them, I have been through no less than 12 different Account Executives over the last 6y and they're all ENTIRELY and COMPLETELY useless. They all introduce themselves, beg me to setup a meeting w/them and some sort of engineering resource(s), and they come to a meeting with a canned slide deck that is so absurdly unrelated t…

This is actually kind of validating. I work for a company that spends almost 1mm a year on GCP. We've never had an actual support contract with them because the numbers work out to, at a minimum, being 10% of our spend. We've yet to encounter a situation where we actually needed GCP support, so we've held off. In the moments where we'd like to get some support (mostly around datastore behavior) we've managed to work around it or figure it out ourselves. So it's good to know we haven't missed out on much. Beyond the offensive aspect of GCP offering no support if we aren't willing to cough up a non-trivial percentage of our spend, I'm pretty happy with it.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#227
post #160

The 3-2-1 backup rule is pretty outdated in the world of cloud. You could have 3 complete copies of your data in different S3 buckets, but if they're all under the same account you've lost your blast radius protection

If only there were a quick and easy way to replicate s3 buckets to an independent provider… … on the Unix command line … … to a cloud older than AWS… … if only …

Inflated egress costs might make this prohibitively expensive, $80 per TB at GCP and AWS

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#228
post #79

Earlier quoted context omitted.

Just google multi-cloud. Yes. It's a thing.

99% of multi-cloud is fake though. True multi-cloud is incredibly rare.

I appreciate it. That's my belief as well. Very easy to write a post like, "Just use multiple clouds!" or to claim to have done it with a small project. But it's hard for me to imagine the benefits outweighing the extremely massive complexity costs at a certain scale.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#229

This is bad. Even their own website is down at railway.com. Looks like total dependency on google cloud. Surprising for a company of their scale with all this VC money.

> Surprising for a company of their scale with all this VC money.

Not sure too many VCs would be cool with deep redundancy when there's more features to build to bring in more customers instead.

Re: Incident Report: Railway Blocked by Google Cloud [resolved]

#230
post #155

Earlier quoted context omitted.

I've been in AWS for almost twenty years at this point. It's been a long time since I've seen a global outage of the data plane on anything. The control plane, especially the US-east-1 services? Yes - but if you're off of east-1, your outages are measured in missile strikes, not botched deployments.

Didn't the latest outage affect people not on us-east-1 because internal aws services depend on us-east-1?

Work for a major bank who isn't solely in US East 1.

No it didn't impact us.

Post reply on HN