Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Engineering Large Systems When You're Not Googl...
Search
Charity Majors
April 30, 2018
Technology
5.7k
20
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Engineering Large Systems When You're Not Google Or Facebook (test in prod)
lightning talk at Clever, 4/30/18
Charity Majors
April 30, 2018
More Decks by Charity Majors
See All by Charity Majors
The situational ethics of stickers (with speaker notes)
charity
0
39
The situational ethics of stickers (lightning talk, no talk track)
charity
0
36
The Twin Mandate of Observability
charity
4
2.3k
In Praise of "Normal" Engineers (LDX3)
charity
4
2.9k
In Praise of "Normal" Engineers (with full speaker notes)
charity
1
300
AIOps: Prove It! (An Open Letter to Vendors Selling AI for SREs)
charity
1
92
SRECon 2024 Keynote: Is It Already Time To Version Observability? (Signs Point To Yes)
charity
3
560
CTO Craft Con Keynote: Observability is due for a version change: are you ready for it?
charity
4
1.5k
Case Studies: Modern Development Practices In Highly Regulated Environments
charity
6
4.4k
Other Decks in Technology
See All in Technology
認知負荷を吸収し、プロダクトをまたぐPR Preview基盤の設計事例
taiki45
2
560
[Kiro Meetup #7] Kiro Crew Dive Deep
konippi
0
440
The kernel report
ennael
PRO
1
170
1万名の社員が使う認証基盤で どう信頼性を担保するか?
kairim0
0
110
Apache Iceberg が拓く AI 時代のオープンレイクハウス
tomtanaka
0
200
営業オントロジーの作り方と、エージェントからの辿り方 ── ナレッジワークの現場から
kworkdev
PRO
1
220
Meet AgentCore Identity Consent Portal
hironobuiga
2
140
顧客の成果創出とプロダクトの成長を 両立するためのFDE
sansantech
PRO
0
560
Execution in the Kingdom of Agents: Reflections on Abstraction and Complexity
bcantrill
0
590
キャリアLT今日までそして明日から
kentapapa
1
140
AIエージェント時代のPlatform as a Product —— テックリードがPdMとして回す発見・導入・計測 / Platform as a Product in the AI Agent Era
toshi0607
1
550
OpenClawでAzure DevOpsのWiki更新を自動化する - クラウドAIだけでは届かない場所へ
yutakaosada
0
140
Featured
See All Featured
SEOcharity - Dark patterns in SEO and UX: How to avoid them and build a more ethical web
sarafernandez
0
290
The Hidden Cost of Media on the Web [PixelPalooza 2025]
tammyeverts
2
510
Exploring the relationship between traditional SERPs and Gen AI search
raygrieselhuber
PRO
3
4.3k
Chasing Engaging Ingredients in Design
codingconduct
0
340
Designing Experiences People Love
moore
143
24k
Thoughts on Productivity
jonyablonski
76
5.4k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
230
23k
Performance Is Good for Brains [We Love Speed 2024]
tammyeverts
12
1.9k
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.9k
The Curious Case for Waylosing
cassininazir
1
550
The SEO identity crisis: Don't let AI make you average
varn
0
570
Transcript
Engineering Large Systems When You’re Not Google Or Facebook Some
Advice By Charity Majors
None
I blame this guy: Testing in production has gotten a
bad rap.
None
how they think we are how we really are
but *why*?
monitoring => observability known unknowns => unknown unknowns LAMP stack
=> distributed systems
“Complexity is increasing” - Science
Many catastrophic states exist at any given time. Your system
is never entirely ‘up’
We are all distributed systems engineers now the unknowns outstrip
the knowns why does this matter more and more?
Distributed systems are particularly hostile to being cloned or imitated
(or monitored). (clients, concurrency, chaotic traffic patterns, edge cases …)
Distributed systems have an infinitely long list of almost-impossible failure
scenarios that make staging environments particularly worthless. this is a black hole for engineering time
unit tests integration tests functional tests basic failover test before
prod: … the basics. the simple stuff. known-unknowns
behavioral tests experiments load tests (!!) edge cases canaries rolling
deploys multi-region test in prod: unknown-unknowns
test in staging? meh
unit tests integration tests functional tests “What happens when …”
(you know the answer) “What happens when …” (you don’t) behavioral tests experiments load tests (!!) edge cases canaries rolling deploys multi-region test before prod: test in prod:
Only production is production. You can ONLY verify the deploy
for any env by deploying to that env
1. Every deploy is a *unique* exercise of your process+
code+system 2. Deploy scripts are production code. If you’re using fabric or capistrano, this means you have fab/cap in production.
Staging is not production.
Why do people sink so much time into staging, when
they can’t even tell if their own production environment is healthy or not?
That energy is better used elsewhere: Production. You can catch
80% of the bugs with 20% of the effort. And you should. @caitie’s PWL talk: https://youtu.be/-3tw2MYYT0Q
feature flags (launch darkly) high cardinality tooling (honeycomb) canary canary
canaries, shadow systems (goturbine, linkerd) capture/replay for databases (apiary, percona) also build or use: plz dont build your own ffs
Failure is not rare Practice shipping and fixing lots of
small problems And practice on your users!!
Failure: it’s “when”, not “if” (lots and lots and lots
of “when’s”)
Does everyone … know what normal looks like? know how
to deploy? know how to roll back? know how to canary? know how to debug in production? Practice!!~
None
None
None
• Charity Majors @mipsytipsy