How Netflix Ensures Highly-Reliable Online Stateful Systems

QCon San Francisco 2023

Session Database

How Netflix Ensures Highly-Reliable Online Stateful Systems

Tuesday Oct 3 / 02:45PM PDT, Ballroom BC

Abstract

Under most stateless services are stateful databases, caches, and systems which form the bedrock applications are built on. These stateful systems have to be extremely reliable as even the slightest latency or availability blip can easily cascade up to the application layer due to data in-cast and query fan-out. With careful consideration, we can design reliable inter-process-communication (IPC), software deployment, and data models to handle millions of requests per second over petabyte scale datastores at single-digit millisecond latency.

In this talk we will start with the architecture of Netflix's stateful caches and databases, including how we capacity plan, bulkhead, and deploy software to our global, full-active, data topology. Keeping petabytes of state across four AWS regions and twelve fault isolation zones consistent and cost-efficient is challenging, but it allows us to meet our millisecond service-level-objectives for both reads and write operations at the level of availability Netflix applications demand.

Then, we will cover how we make stateful systems fully idempotent for both reads and writes, and use this to build novel resilience techniques into our stateful IPC layers using our KeyValue and TimeSeries (event) use cases as concrete examples. Developers at Netflix may see simple read and write APIs, but under the hood we implement advanced load balancing, routing, hedging and other resilience techniques to make those APIs function properly every time. Finally, we will conclude with how we design these systems to, when they do fail, fail as gracefully as possible to limit the blast radius of those failures and contain the business impact to Netflix. For example, most Netflix developers would rather sacrifice properties like immediate strong consistency via caching or partial shedding in emergency situations rather than be unavailable.

Interview

I focus on designing, implementing, operating, and scaling online data abstractions and storage engines. This work spans from high-level design and implementation of new atomic compare and swap protocols for our KeyValue service, to automating capacity planning optimal hardware to run our various storage engines, down to patching storage engines themselves to improve performance or scalability. On the side, I produce large quantities of memos.

To share stateful architectural and operational patterns as well as novel resilience techniques that get beyond five nines of availability.

A software developer, reliability engineer, or database operator who needs high availability from their caches and databases. Having a solid grasp of distributed systems and databases will enrich the talk, but is not required.

With new knowledge and concrete advice on how to design, build and scale their stateful systems to be even more reliable than before - ranging from small changes with big benefits, to more complex system-wide changes.

Topics

Database Distributed Systems Reliability Data Architecture
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon San Francisco 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 3 October

10:35 Ballroom BC Session Architecture Disaster Recovery Across a Million Pieces Michelle Brush Engineering Director, SRE @Google, Previously Director of HealtheIntent Architecture @Cerner Corporation & Lead Engineer @Garmin, Author of "2 out of the 97 Things Every SRE Should Know" 11:45 Ballroom BC Session Reliability Designing Fault-Tolerant Software with Control System Transparency Jon Moore Staff Software Engineer @Stripe with over 35 years of software engineering experience across both academia and industry 13:35 Ballroom BC Session Resiliency How Do We Talk to Each Other? How Surfacing Communication Patterns in Organizations Can Help You Understand and Improve Your Resilience Nora Jones Founder and CEO @jeli_io, Founder of Learning From Incidents (LFI) Online Community and Conference 14:45 Ballroom BC Session Database How Netflix Ensures Highly-Reliable Online Stateful Systems Joseph Lynch Principal Software Engineer @Netflix Building Highly-Reliable and High-Leverage Infrastructure Across Stateless and Stateful Services 15:55 Ballroom BC Session Resiliency Orchestrating Resilience: Building Modern Asynchronous Systems Sai Pragna Etikyala Technical Lead @Twilio 17:05 Seacliff D Unconference Unconference: Designing for Resilience