Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Engineering Large Systems When You're Not Googl...
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Charity Majors
April 30, 2018
Technology
5.7k
20
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Engineering Large Systems When You're Not Google Or Facebook (test in prod)
lightning talk at Clever, 4/30/18
Charity Majors
April 30, 2018
More Decks by Charity Majors
See All by Charity Majors
The situational ethics of stickers (with speaker notes)
charity
0
34
The situational ethics of stickers (lightning talk, no talk track)
charity
0
33
The Twin Mandate of Observability
charity
4
2.2k
In Praise of "Normal" Engineers (LDX3)
charity
4
2.9k
In Praise of "Normal" Engineers (with full speaker notes)
charity
1
290
AIOps: Prove It! (An Open Letter to Vendors Selling AI for SREs)
charity
1
85
SRECon 2024 Keynote: Is It Already Time To Version Observability? (Signs Point To Yes)
charity
3
550
CTO Craft Con Keynote: Observability is due for a version change: are you ready for it?
charity
4
1.5k
Case Studies: Modern Development Practices In Highly Regulated Environments
charity
6
4.4k
Other Decks in Technology
See All in Technology
『自分で判断できるか』を基準に、プロダクトのハンズオン研修でAI利用の線を引いてみた / Where We Drew the Line on AI in Hands-on Training
honyanya
1
840
Nav2、Nav3 ... はたまた自作?〜 作って理解する Nav3 の設計意図 〜 / Nav2, Nav3 ... or Build Your Own? — Understanding Nav3's design intent by building it from scratch
yanzm
0
180
生成AI時代の クレデンシャルとパーミッション設計
nrinetcom
PRO
3
1.3k
Amazon S3 Tablesに全部任せてみた結果——コンパクション/スナップショット管理は本当に手放せるか
shigeruoda
0
180
Claude Codeの体系的な理解と知識のフック
oikon48
10
6.6k
Digitization部 紹介資料
sansan33
PRO
2
7.8k
研究開発部の紹介 / Sansan R&D Profile
sansan33
PRO
4
25k
Introduction to Sansan for Engineers / エンジニア向け会社紹介
sansan33
PRO
6
77k
AI時代におけるプロダクト横断勉強会の設計
zozotech
PRO
0
120
Continuous Delivery! It is not what you think it is
tdpauw
0
180
Sony-DroidKaigi2026
sony
0
290
指示待ちから変化に応じるClaude Codeへ!~環境からAgentへの帰り道を作る~
gotalab555
9
1.8k
Featured
See All Featured
Money Talks: Using Revenue to Get Sh*t Done
nikkihalliwell
0
480
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
3k
Agile that works and the tools we love
rasmusluckow
331
22k
More Than Pixels: Becoming A User Experience Designer
marktimemedia
3
510
Statistics for Hackers
jakevdp
799
230k
The Cost Of JavaScript in 2023
addyosmani
55
10k
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
WCS-LA-2024
lcolladotor
0
820
Making the Leap to Tech Lead
cromwellryan
135
10k
ラッコキーワード サービス紹介資料
rakko
1
4.7M
The innovator’s Mindset - Leading Through an Era of Exponential Change - McGill University 2025
jdejongh
PRO
1
320
Abbi's Birthday
coloredviolet
3
9.7k
Transcript
Engineering Large Systems When You’re Not Google Or Facebook Some
Advice By Charity Majors
None
I blame this guy: Testing in production has gotten a
bad rap.
None
how they think we are how we really are
but *why*?
monitoring => observability known unknowns => unknown unknowns LAMP stack
=> distributed systems
“Complexity is increasing” - Science
Many catastrophic states exist at any given time. Your system
is never entirely ‘up’
We are all distributed systems engineers now the unknowns outstrip
the knowns why does this matter more and more?
Distributed systems are particularly hostile to being cloned or imitated
(or monitored). (clients, concurrency, chaotic traffic patterns, edge cases …)
Distributed systems have an infinitely long list of almost-impossible failure
scenarios that make staging environments particularly worthless. this is a black hole for engineering time
unit tests integration tests functional tests basic failover test before
prod: … the basics. the simple stuff. known-unknowns
behavioral tests experiments load tests (!!) edge cases canaries rolling
deploys multi-region test in prod: unknown-unknowns
test in staging? meh
unit tests integration tests functional tests “What happens when …”
(you know the answer) “What happens when …” (you don’t) behavioral tests experiments load tests (!!) edge cases canaries rolling deploys multi-region test before prod: test in prod:
Only production is production. You can ONLY verify the deploy
for any env by deploying to that env
1. Every deploy is a *unique* exercise of your process+
code+system 2. Deploy scripts are production code. If you’re using fabric or capistrano, this means you have fab/cap in production.
Staging is not production.
Why do people sink so much time into staging, when
they can’t even tell if their own production environment is healthy or not?
That energy is better used elsewhere: Production. You can catch
80% of the bugs with 20% of the effort. And you should. @caitie’s PWL talk: https://youtu.be/-3tw2MYYT0Q
feature flags (launch darkly) high cardinality tooling (honeycomb) canary canary
canaries, shadow systems (goturbine, linkerd) capture/replay for databases (apiary, percona) also build or use: plz dont build your own ffs
Failure is not rare Practice shipping and fixing lots of
small problems And practice on your users!!
Failure: it’s “when”, not “if” (lots and lots and lots
of “when’s”)
Does everyone … know what normal looks like? know how
to deploy? know how to roll back? know how to canary? know how to debug in production? Practice!!~
None
None
None
• Charity Majors @mipsytipsy