Operational sharp edges — refresh storms, mapping explosions and hot shards
The most expensive Elasticsearch outages aren't algorithmic — refresh storms, mapping explosions, hot shards, and deep-pagination OOMs are each a misuse of a knob a previous scene already introduced.
Approximations are mathematical. The next class of failures is operational — same cluster, same algorithms, scale or cardinality has just crept past what one knob's default was set for.
Scene 11
Operational sharp edges
- Watch
- Try it
- Predict
- Capture
Steady state: 3 hot nodes serving live indices, 2 warm nodes holding 30-day-old data, 1 cold node holding searchable snapshots. Status is GREEN — every primary and every replica is assigned. ILM (Index Lifecycle Management) ages indices hot → warm → cold → frozen → deleted on a 90-day schedule.
Where this sits in Build a distributed search engine (Elasticsearch / OpenSearch style)
Scene 11 of 12. Refresh storm, mapping explosion, hot shard, deep pagination — the four most expensive Elasticsearch outages are misuses of knobs the earlier scenes already introduced.
Up next. Knowing which knob to turn for which workload is the test. A cache-style index isn't a security-analytics index isn't a logs-archive index — and the same primitives configure all three differently.
All 12 scenes in Build a distributed search engine (Elasticsearch / OpenSearch style) · Every curriculum