Operational sharp edges — refresh storms, mapping explosions and hot shards

The most expensive Elasticsearch outages aren't algorithmic — refresh storms, mapping explosions, hot shards, and deep-pagination OOMs are each a misuse of a knob a previous scene already introduced.

Previously

Approximations are mathematical. The next class of failures is operational — same cluster, same algorithms, scale or cardinality has just crept past what one knob's default was set for.

Scene 11

Operational sharp edges

  1. Watch
  2. Try it
  3. Predict
  4. Capture
GREENevery primary + replica assignedNODES · 6N1 · hothotshards28heap52%index/s8k/ssearch/s1.2k/sN2 · hothotshards30heap55%index/s8k/ssearch/s1.2k/sN3 · hothotshards26heap50%index/s8k/ssearch/s1.2k/sN4 · warmwarmshards22heap38%index/s1k/ssearch/s0.3k/sN5 · warmwarmshards24heap40%index/s1k/ssearch/s0.3k/sN6 · coldcoldshards18heap32%index/s—search/s0.05k/sINCIDENT CARDSRefresh storm↳ scene 4 · refresh / flush / translogMapping explosion↳ high-cardinality dynamic mapping (corpus)Hot shard↳ scene 5 · hash(routing) mod NDeep pagination↳ scene 7 · scatter, reduce, fetch
What to watch for

Steady state: 3 hot nodes serving live indices, 2 warm nodes holding 30-day-old data, 1 cold node holding searchable snapshots. Status is GREEN — every primary and every replica is assigned. ILM (Index Lifecycle Management) ages indices hot → warm → cold → frozen → deleted on a 90-day schedule.

Continue unlocks when the animation finishes.

Where this sits in Build a distributed search engine (Elasticsearch / OpenSearch style)

Scene 11 of 12. Refresh storm, mapping explosion, hot shard, deep pagination — the four most expensive Elasticsearch outages are misuses of knobs the earlier scenes already introduced.

Up next. Knowing which knob to turn for which workload is the test. A cache-style index isn't a security-analytics index isn't a logs-archive index — and the same primitives configure all three differently.

All 12 scenes in Build a distributed search engine (Elasticsearch / OpenSearch style) · Every curriculum

Built with Arqly
Every scene in Build a distributed search engine (Elasticsearch / OpenSearch style) builds on the one before it.All 12 Build a distributed search engine (Elasticsearch / OpenSearch style) scenes