Autodiscover Independent coverage of news

When Backup Strategy Is the Wrong Choice

By James Whitfield · · 1253 words
When Backup Strategy Is the Wrong Choice

A design that cannot be rolled back is a design that cannot be changed safely. The same reasoning holds for monitoring alerts. For monitoring alerts, the constraint matters more than the feature list. Latency budgets are easier to defend when every hop has a stated ceiling. Teams working on monitoring alerts usually discover this the hard way. Caching helps only until the invalidation rules become the bottleneck.

Consider observability specifically. The interesting number is not the average, it is the 99th percentile. Observability: Adding a cache in front of a slow query is a fix; fixing the query is a cure. Every abstraction you add is a place where behaviour can differ from intent. That applies to observability as well.

Consider backup strategy specifically. You can often replace a coordination problem with an idempotency key. Backup Strategy: Anything that grows without a bound will eventually hit one. Documentation that is not tested tends to describe the previous version. That applies to backup strategy as well.

Cloud Infrastructure: If the rollback plan needs a meeting, it is not a rollback plan. Cloud Infrastructure: Small pages that stay small are easier to keep fast than large ones made fast. Cloud Infrastructure: Write the invariant down; otherwise it lives only in someone's memory.

Screening is designed for people who may have an infection without knowing it; many STIs cause no noticeable symptoms. If someone has symptoms or has been told they may have been exposed, that is different from routine screening and should be discussed with a clinician. A screening appointment may need to include an assessment beyond the tests usually offered to someone without symptoms.

For content delivery, the constraint matters more than the feature list. A queue smooths spikes but also hides how far behind you are. Teams working on content delivery usually discover this the hard way. Retries without jitter turn a small outage into a large one. Separating the reads from the writes buys room to change either side. This is most visible in content delivery.

Queue Design: The first thing to settle is the failure mode, not the happy path. Queue Design: Measurements taken once are anecdotes; you need a baseline that repeats. Queue Design: Costs usually concentrate in a small number of operations, so find those first.

A respectful response may include questions asked to understand, a clear acceptance of the limit, or a request to discuss a separate preference. A partner does not have to share your boundary to respect it. By contrast, repeated bargaining after you have said no, guilt, threats, ridicule, or continuing after you ask to stop are not respectful ways to handle a boundary. You are not responsible for making another person approve of your limit.

Cloud Infrastructure: You can often replace a coordination problem with an idempotency key. Cloud Infrastructure: Anything that grows without a bound will eventually hit one. Cloud Infrastructure: Documentation that is not tested tends to describe the previous version.

Talking about boundaries can make intimacy clearer and safer, but it may feel awkward at first. A boundary is a limit or condition that describes what you are comfortable with; it is not a demand that another person must feel the same way. A step-by-step conversation can help both partners understand what is welcome, what is not, and how to respond when feelings or circumstances change.

Release Process: If a metric has no owner, it will drift until it causes an incident. The cheapest optimisation is usually removing work nobody asked for. That applies to release process as well. In practice, release process behaves differently: Aggregating at write time trades flexibility for predictable read cost.

If the rollback plan needs a meeting, it is not a rollback plan. The same reasoning holds for cost controls. For cost controls, the constraint matters more than the feature list. Small pages that stay small are easier to keep fast than large ones made fast. Teams working on cost controls usually discover this the hard way. Write the invariant down; otherwise it lives only in someone's memory.

Load Balancing: If a metric has no owner, it will drift until it causes an incident. Load Balancing: The cheapest optimisation is usually removing work nobody asked for. Load Balancing: Aggregating at write time trades flexibility for predictable read cost.

Crawl Budget: If the rollback plan needs a meeting, it is not a rollback plan. Crawl Budget: Small pages that stay small are easier to keep fast than large ones made fast. Crawl Budget: Write the invariant down; otherwise it lives only in someone's memory.

If the rollback plan needs a meeting, it is not a rollback plan. The same reasoning holds for storage tiers. For storage tiers, the constraint matters more than the feature list. Small pages that stay small are easier to keep fast than large ones made fast. Teams working on storage tiers usually discover this the hard way. Write the invariant down; otherwise it lives only in someone's memory.

Teams working on load balancing usually discover this the hard way. You can often replace a coordination problem with an idempotency key. Anything that grows without a bound will eventually hit one. This is most visible in load balancing. Consider load balancing specifically. Documentation that is not tested tends to describe the previous version.

In practice, data pipelines behaves differently: A queue smooths spikes but also hides how far behind you are. Retries without jitter turn a small outage into a large one. The same reasoning holds for data pipelines. For data pipelines, the constraint matters more than the feature list. Separating the reads from the writes buys room to change either side.

A yes is meaningful when a person can choose freely. Pressure can take many forms: repeated requests after a refusal, threats, guilt, intimidation, or using a position of authority to influence someone. A person who agrees because they fear consequences or feel unable to refuse may not be making a free choice.

Serving static bytes is the cheapest thing you can do at the edge. That applies to storage tiers as well. In practice, storage tiers behaves differently: A schema is an interface; changing it is a migration, not an edit. Track the denominator as carefully as the numerator. The same reasoning holds for storage tiers.

Storage Tiers: If a metric has no owner, it will drift until it causes an incident. Storage Tiers: The cheapest optimisation is usually removing work nobody asked for. Storage Tiers: Aggregating at write time trades flexibility for predictable read cost.

Observability: The interesting number is not the average, it is the 99th percentile. Observability: Adding a cache in front of a slow query is a fix; fixing the query is a cure. Observability: Every abstraction you add is a place where behaviour can differ from intent.

Access Control: Periodic jobs should be safe to run twice, because they will be. Access Control: You rarely need a new component to fix a boundary problem. Access Control: The signal you want is often already logged, just not aggregated.

Backup Strategy: If a metric has no owner, it will drift until it causes an incident. Backup Strategy: The cheapest optimisation is usually removing work nobody asked for. Backup Strategy: Aggregating at write time trades flexibility for predictable read cost.

Crawl Budget: If a metric has no owner, it will drift until it causes an incident. Crawl Budget: The cheapest optimisation is usually removing work nobody asked for. Crawl Budget: Aggregating at write time trades flexibility for predictable read cost.

Related reading