ContentsThe library

Serving a Model to Many People

Saying No While You Still Can

Last timeThe Slowest One in a Hundred

A service that accepts everything offered to it serves nobody once the offer exceeds its capacity. Refusing work early is the only way to keep the accepted work fast.

Every service has a rate of work above which it cannot go. The interesting fact

is what happens just past it, because the intuitive picture is wrong. One

expects a service pushed beyond capacity to hold steady at its maximum and make

everybody wait a little. What actually happens is that the useful work it

completes per second falls, often sharply, while every machine reports itself

fully occupied.

The mechanism is simple. Arrivals above capacity join a queue that nothing is

draining, so the wait grows, answers begin arriving after the asker has given

up, and from that moment the service spends all of its capacity producing

results that nobody will read.

FIG 1What a full server can do with an arriving request
Both branches on the right preserve the promise made to accepted requests. The usually missing branch is the one comparing value, which converts an arbitrary refusal into a deliberate one.

Why the limit belongs on work in progress

The obvious protection is a limit on requests per second. It is also the wrong

unit, for a reason that appears the first time the traffic changes shape. A

thousand short questions and a thousand long documents are not the same load,

and no single number covers both. The limit must therefore be set for the worst

case, wasting capacity most of the time, or for the average case, failing

exactly when the mix shifts.

A limit on how many requests may be in progress at once has none of that

trouble, because it is self-correcting. When requests become slower, fewer of

them finish, so the count in progress stays high, so fewer new ones are let in.

Nobody retunes anything, and the service converges on whatever rate it can

sustain for the work it is actually being given today.

Retries, which are how a dip becomes an outage

One mechanism reliably turns thirty seconds of trouble into forty minutes, and it lives in the clients, not the server.

The lesson stops here

7 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Mostly Waiting
  2. 02The Average Minute Does Not Existopening only
  3. 03Reading the Weights Once for Everybodyopening only
  4. 04The Two Jobs That Get in Each Other's Wayopening only
  5. 05Where the Complaints Actually Liveopening only
  6. 06Saying No While You Still Canyou are here
  7. 07Help That Arrives Nine Minutes Lateopening only
  8. 08A Number You Can Be Held Toopening only

Read alongside