TLS / t

TLS: handoff in São Paulo (GRU) · T-41

xserv-t-46bacd3afdaf

Runbook T-41 for TLS in São Paulo (GRU). Marker xserv-t-46bacd3afdaf. This page covers handoff for LATAM operators, not a worldwide average.

TLS: How this letter ties to the rest

Handoff from letter T TLS into the rest of the platform uses the same request IDs as the gateway. Runbook t-05 names who accepts the ticket after São Paulo pages out. Santiago does not silently inherit the incident.

TLS: A note on cost and transit

Rollback for t-06 is a documented command, not a hope. Transit is billed as backup while TLS prefers peering in Santiago. If cost spikes, the runbook cuts overflow to Bogotá before touching customer prefixes.

TLS: Why it matters on this continent

Design for TLS on letter T starts in São Paulo (GRU). Runbook t-01 keeps a single owner, a written rollback, and a traffic split that can be reversed without a global freeze. Neighbors in Santiago only take overflow after the local pool fails a health window.

TLS peering T-07

Peering for TLS (t-07) prefers the IX fabric that already carries last-mile ISPs in Bogotá. Session counts and prefix limits are on the same page as the Miami backup path.

TLS cache T-08

Cache rules for TLS on t-08 keep language-correct objects near Miami. São Paulo is a sibling cache, not an origin. TTLs are short enough that a bad asset does not live through a weekend.

TLS headers T-09

Headers for t-09 carry the letter, the region (GRU) and a request id. TLS debugging in São Paulo should not require a packet capture in Santiago first.

TLS timeouts T-10

Timeouts on t-10 are tighter than the WAN RTT to Bogotá. TLS in Santiago fails fast and retries once; a third try needs a human because it is no longer a blip.

Does TLS on letter T share fate with other letters?
The control plane is shared. Data-plane queues for TLS stay isolated, so incident t-01 cannot drain neighbor letters.
Where is TLS measured first?
From Santiago (SCL) toward Bogotá. A global average is not an SLO for letter T.