ContentsThe library

When One Machine Is Not Enough

How a Group Decides Without a Boss

Last timeThe Choice a Partition Forces

Several machines can agree on a single value even though some are down and messages are lost, by insisting that nothing counts until a majority has seen it.

Suppose five machines have to agree which of two values is the one that counts,

and you are not allowed to assume any of them is reliable or that any message

arrives promptly. This sounds like a puzzle and it is actually the foundation

under every system that has a single authoritative answer to anything.

What is being agreed

The group is not deciding one thing once. It maintains an ordered list of

decisions and settles them one position at a time.

FIG 1A decision moving through the group
The settled point is reached before every machine has the entry, which is why a group of five keeps working with two machines down. It is also why the latency is set by the middle machine rather than the slowest one.

One decision per position, settled forever, is a deliberately modest promise. It

is modest enough to be achievable under bad conditions, and strong enough that

almost everything else can be built on top of it: a lock is an entry claiming the

lock, a configuration change is an entry describing the new configuration, and a

leader election is an entry naming the leader.

The lesson stops here

6 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01The Three Reasons, and What Each One Costs
  2. 02How Far Behind a Copy Is Allowed to Beopening only
  3. 03Silence Means Nothing In Particularopening only
  4. 04What You Give Up When the Network Splitsopening only
  5. 05How a Group Decides Without a Bossyou are here
  6. 06Which Thing Happened Firstopening only
  7. 07Cutting the Data Into Piecesopening only
  8. 08Designing for the Failure You Will Actually Getopening only

Read alongside