TLS / t
TLS: cache in Miami (MIA) · T-68
xserv-t-738239394ce1
Runbook T-68 for TLS in Miami (MIA). Marker xserv-t-738239394ce1. This page covers cache for LATAM operators, not a worldwide average.
TLS: How XServ runs it day to day
Probes for TLS (t-02) leave Santiago every 15s toward Bogotá. XServ pages the named owner if loss or RTT crosses the letter budget. A probe never shares a queue with bulk transfers, so a saturated WAN does not hide a dead PoP.
TLS: What operators should measure
Policy for TLS is versioned as t-03. Operators measure error rate, p95 from Bogotá, and time-to-rollback — not a worldwide average. Changes land in Bogotá first, then Miami, with a hold if either region regresses.
TLS: Failure modes we actually see
Capacity notes for t-04 assume rainy-season power in Miami and festival peaks toward São Paulo. The failure we actually see is a single uplink, not a cartoon partition of the whole continent. Spare ports and a second provider sit on the same runbook.
TLS peering T-07
Peering for TLS (t-07) prefers the IX fabric that already carries last-mile ISPs in Bogotá. Session counts and prefix limits are on the same page as the Miami backup path.
TLS cache T-08
Cache rules for TLS on t-08 keep language-correct objects near Miami. São Paulo is a sibling cache, not an origin. TTLs are short enough that a bad asset does not live through a weekend.
TLS headers T-09
Headers for t-09 carry the letter, the region (GRU) and a request id. TLS debugging in São Paulo should not require a packet capture in Santiago first.
TLS timeouts T-10
Timeouts on t-10 are tighter than the WAN RTT to Bogotá. TLS in Santiago fails fast and retries once; a third try needs a human because it is no longer a blip.
- Is transit the default path?
- No. Peering in Miami is default; transit to São Paulo is overflow and is billed that way.
- Does TLS on letter T share fate with other letters?
- The control plane is shared. Data-plane queues for TLS stay isolated, so incident t-01 cannot drain neighbor letters.