Building resilient services by assuming failures will happen and preparing for them. It walks through practical patterns like retries, circuit breakers, bulkheads, idempotency, and outbox, plus how to test and observe them. The goal is to design systems that degrade gracefully instead of breaking completely.
The talk focuses on designing services that can survive and recover from failures instead of pretending they won’t happen. It shows why the “happy path” mindset is dangerous in production, where rare bugs surface quickly at scale. Engineers are guided through a set of proven resilience techniques: retries with backoff and jitter, circuit breakers, timeouts, throttling, and bulkheading to contain failures. For asynchronous systems, it covers queues, DLQs, idempotency, and the outbox pattern to handle retries without duplication. In distributed systems, it discusses leader election, offline-first strategies, and clear separation of liveness vs. readiness probes. Architectural safeguards like dry runs, sagas, compensating transactions, graceful degradation, and killswitches are highlighted as essential for containing damage when things go wrong. Testing resiliency with chaos engineering tools and monitoring through metrics, logs, and traces are stressed as key practices. Finally, the cultural side: post-mortems, pre-mortems, and production readiness—ensures teams take failures seriously and learn from them. The message is simple: failures are inevitable, but with the right patterns, they don’t have to take your system down.
If builders built houses the way programmers built programs,Gerald Weinberg
the first woodpecker to come along would destroy civilization
...happens every 15 minutes at 1k RPS
facebook.com makes 350 HTTP requests
try-catchSocketException
Retry-After HTTP header
64 bytes from 216.58.212.14: icmp_seq=9720 ttl=114
time=749147.422 ms
source
How a Cache Stampede Caused One of Facebook’s Biggest Outages
But also:
Idempotency-Key HTTP Header
datatracker.ietf.org/doc/draft-ietf-httpapi-idempotency-key-header
Think: asynchronous replication, local SQLite
aka. simulation
terraform plan
"we sent 700 thousand text messages to one person"
Knight Capital took a [...] loss of $440 million in 45 minutes
Knight Capital Group: 2012 stock trading disruption
$1m per 6 seconds. Bill Gates makes < $8k per 6 seconds
Tiered services
Proxy mysqlProxy =
client.createProxy("mysql", "localhost:13306", "localhost:3306");
mysqlProxy
.toxics()
.latency("latency", DOWNSTREAM, 100)
.setJitter(15);
Death by a thousand dashboards
...and by millions of $ in APM bill