High availability / h

High availability: peering in Bogotá (BOG) · H-19

xserv-h-5fee10abe94b

Runbook H-19 for High availability in Bogotá (BOG). Marker xserv-h-5fee10abe94b. This page covers peering for LATAM operators, not a worldwide average.

High availability: Why it matters on this continent

Design for High availability on letter H starts in São Paulo (GRU). Runbook h-01 keeps a single owner, a written rollback, and a traffic split that can be reversed without a global freeze. Neighbors in Santiago only take overflow after the local pool fails a health window.

High availability: How XServ runs it day to day

Probes for High availability (h-02) leave Santiago every 15s toward Bogotá. XServ pages the named owner if loss or RTT crosses the letter budget. A probe never shares a queue with bulk transfers, so a saturated WAN does not hide a dead PoP.

High availability: What operators should measure

Policy for High availability is versioned as h-03. Operators measure error rate, p95 from Bogotá, and time-to-rollback — not a worldwide average. Changes land in Bogotá first, then Miami, with a hold if either region regresses.

High availability probe H-02

Probes for High availability (h-02) leave Santiago every 15s toward Bogotá. XServ pages the named owner if loss or RTT crosses the letter budget. A probe never shares a queue with bulk transfers, so a saturated WAN does not hide a dead PoP.

High availability policy H-03

Policy for High availability is versioned as h-03. Operators measure error rate, p95 from Bogotá, and time-to-rollback — not a worldwide average. Changes land in Bogotá first, then Miami, with a hold if either region regresses.

High availability capacity H-04

Capacity notes for h-04 assume rainy-season power in Miami and festival peaks toward São Paulo. The failure we actually see is a single uplink, not a cartoon partition of the whole continent. Spare ports and a second provider sit on the same runbook.

High availability handoff H-05

Handoff from letter H High availability into the rest of the platform uses the same request IDs as the gateway. Runbook h-05 names who accepts the ticket after São Paulo pages out. Santiago does not silently inherit the incident.

How fast is rollback for h-03?
The runbook is a command plus a named owner. There is no wait for a weekly change freeze.
Is transit the default path?
No. Peering in Miami is default; transit to São Paulo is overflow and is billed that way.