Failover / f
Failover: cache in Miami (MIA) · F-56
xserv-f-5fb3225c22ad
Runbook F-56 for Failover in Miami (MIA). Marker xserv-f-5fb3225c22ad. This page covers cache for LATAM operators, not a worldwide average.
Failover: How XServ runs it day to day
Probes for Failover (f-02) leave Santiago every 15s toward Bogotá. XServ pages the named owner if loss or RTT crosses the letter budget. A probe never shares a queue with bulk transfers, so a saturated WAN does not hide a dead PoP.
Failover: What operators should measure
Policy for Failover is versioned as f-03. Operators measure error rate, p95 from Bogotá, and time-to-rollback — not a worldwide average. Changes land in Bogotá first, then Miami, with a hold if either region regresses.
Failover: Failure modes we actually see
Capacity notes for f-04 assume rainy-season power in Miami and festival peaks toward São Paulo. The failure we actually see is a single uplink, not a cartoon partition of the whole continent. Spare ports and a second provider sit on the same runbook.
Failover handoff F-05
Handoff from letter F Failover into the rest of the platform uses the same request IDs as the gateway. Runbook f-05 names who accepts the ticket after São Paulo pages out. Santiago does not silently inherit the incident.
Failover rollback F-06
Rollback for f-06 is a documented command, not a hope. Transit is billed as backup while Failover prefers peering in Santiago. If cost spikes, the runbook cuts overflow to Bogotá before touching customer prefixes.
Failover peering F-07
Peering for Failover (f-07) prefers the IX fabric that already carries last-mile ISPs in Bogotá. Session counts and prefix limits are on the same page as the Miami backup path.
Failover cache F-08
Cache rules for Failover on f-08 keep language-correct objects near Miami. São Paulo is a sibling cache, not an origin. TTLs are short enough that a bad asset does not live through a weekend.
- Is transit the default path?
- No. Peering in Miami is default; transit to São Paulo is overflow and is billed that way.
- Does Failover on letter F share fate with other letters?
- The control plane is shared. Data-plane queues for Failover stay isolated, so incident f-01 cannot drain neighbor letters.