Failover / f

Failover: cache in Miami (MIA) · F-32

xserv-f-1f2b350b973b

Runbook F-32 for Failover in Miami (MIA). Marker xserv-f-1f2b350b973b. This page covers cache for LATAM operators, not a worldwide average.

Failover: How XServ runs it day to day

Probes for Failover (f-02) leave Santiago every 15s toward Bogotá. XServ pages the named owner if loss or RTT crosses the letter budget. A probe never shares a queue with bulk transfers, so a saturated WAN does not hide a dead PoP.

Failover: What operators should measure

Policy for Failover is versioned as f-03. Operators measure error rate, p95 from Bogotá, and time-to-rollback — not a worldwide average. Changes land in Bogotá first, then Miami, with a hold if either region regresses.

Failover: Failure modes we actually see

Capacity notes for f-04 assume rainy-season power in Miami and festival peaks toward São Paulo. The failure we actually see is a single uplink, not a cartoon partition of the whole continent. Spare ports and a second provider sit on the same runbook.

Failover design F-01

Design for Failover on letter F starts in São Paulo (GRU). Runbook f-01 keeps a single owner, a written rollback, and a traffic split that can be reversed without a global freeze. Neighbors in Santiago only take overflow after the local pool fails a health window.

Failover probe F-02

Probes for Failover (f-02) leave Santiago every 15s toward Bogotá. XServ pages the named owner if loss or RTT crosses the letter budget. A probe never shares a queue with bulk transfers, so a saturated WAN does not hide a dead PoP.

Failover policy F-03

Policy for Failover is versioned as f-03. Operators measure error rate, p95 from Bogotá, and time-to-rollback — not a worldwide average. Changes land in Bogotá first, then Miami, with a hold if either region regresses.

Failover capacity F-04

Capacity notes for f-04 assume rainy-season power in Miami and festival peaks toward São Paulo. The failure we actually see is a single uplink, not a cartoon partition of the whole continent. Spare ports and a second provider sit on the same runbook.

Is transit the default path?
No. Peering in Miami is default; transit to São Paulo is overflow and is billed that way.
Does Failover on letter F share fate with other letters?
The control plane is shared. Data-plane queues for Failover stay isolated, so incident f-01 cannot drain neighbor letters.