Timeout and retry budget — bounded patience
Retrying without a budget turns one slow backend into a 243× retry storm; a retry budget caps total retry concurrency to a small fraction of normal traffic so retries cannot become the outage.
Once the proxy picked a replica and the replica is slow, the proxy has to decide how long to wait and whether to try again — and that decision, scaled across the fleet, is where outages are born.
Scene 06
Timeout and retry budget — bounded patience
- Watch
- Try it
- Predict
- Capture
S5 is failing. Each upstream hop retries 3 times per attempt. Watch the per-hop counter climb back up the chain — the badge above the diagram lands on 243× (3^5), the load S5 actually sees per single client request.
Highlighted lines are the ones running in the diagram right now.
def send_with_retry(req):for attempt in range(retries + 1):resp = try_send(req, deadline = per_try_timeout,)if resp.ok:return respsleep(backoff_with_jitter(attempt))return ERROR
# Hop 1 retries 3x on failure.# Hop 2 inherits all of hop 1's load,# and retries 3x of each failure too.# Every hop multiplies, not adds.## load_on_tail = retries ^ hops# = 3 ^ 5# = 243x per single client request
def admit_retry(cluster):budget = budget_percent / 100 # e.g. 0.20active = cluster.active_request_countretrying = cluster.active_retry_countcap = max(active * budget,min_retry_concurrency,)if retrying >= cap:return DROP_RETRY # honor the capreturn ALLOW_RETRY
route:timeout: 30s # whole call, incl. retriesretry_policy:retries: 3per_try_timeout: 5s # bound on one attemptretry_budget:budget_percent: 20.0 # cap retries at 20% of trafficmin_retry_concurrency: 3
Where this sits in Build a Service Mesh (Envoy / Istio style)
Scene 06 of 13. Naive multi-hop retries amplify load 243x on a failing backend. A retry budget caps total retries as a fraction of normal traffic so retries can't become the outage.
Up next. A budget caps retries fleet-wide, but it doesn't tell the proxy when to stop talking to one specific replica that's broken.
All 13 scenes in Build a Service Mesh (Envoy / Istio style) · Every curriculum