Stop the bomb at every door — relabeling, per-scrape sample and per-tenant series limits

Each door stops a cardinality explosion by failing something different: a rule at the scraper drops a dangerous metric before it becomes a series, a per-scrape sample limit fails the whole scrape and silences that target's alerts, and a per-tenant series limit refuses only new series, isolating teams only if each team is its own tenant.

Previously

Churn and bad labels create series faster than anyone expects, so the cluster needs doors that stop an explosion before it takes everyone down.

Scene 14

Stop the bomb at every door

  1. Watch
  2. Try it
  3. Predict
  4. Capture
instrumentno scrape gatecollectno tenant limitstorequeryalertnotifyTIME TO DETECT≈ 3 minexamplecheckout podsnormal week · no Friday deploy · gates idleSHARED INGESTERS · MEMORY┆ budget linewithin budgetDOORno door: nothing stops itPRICEnothing stops it: every team's lane goes quiet once theingesters run out of memorytenants: one shared by all teamstenant: shared by all teamsTEAM ALERT LANESPayments● alerts workingUPup = 1up = 1ALERTalerts OKalerts OKTTD≈ 3 min (example)≈ 3 min (example)Checkout● alerts workingUPup = 1up = 1ALERTerror-rate alert: armederror-rate alert: armedTTD≈ 3 min (example)≈ 3 min (example)Search● alerts workingUPup = 1up = 1ALERTalerts OKalerts OKTTD≈ 3 min (example)≈ 3 min (example)Normal week at Shopfront: three teams, one shared cluster, every lane's alerts working.
What to watch for

Where can a cardinality explosion be stopped, and what does each stopping point cost? Start with the answer nobody wants: nowhere. Three teams share one cluster, and the Friday deploy you have met before adds customer_id to checkout's request metric with no door in its way. Watch the rose chip leave checkout's pods, pass the scraper untouched, and turn into series inside the cluster, and watch the memory bar climb toward the budget line while all three lanes still look healthy.

Continue unlocks when the animation finishes.
Implementation

Highlighted lines are the ones running in the diagram right now.

Scraper.relabel
drops a whole metric before it can become a series
def relabel(samples): # metric_relabel_configs
kept = []
for s in samples:
# runs as the last step before ingestion
if drop_rule_matches(s.name):
continue # never becomes a series
kept.append(s)
return kept
Scraper.enforce_sample_limit
one scrape, kept whole or thrown away whole
def enforce_sample_limit(target, samples):
# sample_limit default 0 = off
if not sample_limit or len(samples) <= sample_limit:
commit(samples)
write(up = 1)
return
rollback(pending_append)
for series in series_from(target):
write_stale_marker(series)
write(up = 0)
Ingester.create_series
the ceiling is checked only for a series that does not exist yet
def create_series(tenant, series, sample):
# the ceiling counts every series in this tenant
if series in tenant.active_series:
append(series, sample)
return # existing series keep ingesting
# churn leaves old series in this count too
# max_global_series_per_user = 150000
if tenant.active_series.count() >= limit:
discard(series, 'per_user_series_limit')
return
tenant.active_series.add(series)
append(series, sample)

Where this sits in Metrics / Monitoring System

Scene 14 of 18, in the Cardinality act — Churn, defenses, aggregation, then design it.. Each door stops a cardinality explosion by failing something different: relabeling drops the metric, a per-scrape limit fails the whole scrape and silences that target, a tenant limit refuses only new series.

Up next. Now that every defense stops the explosion by dropping, blinding or refusing something, the next question is how to keep people's questions answerable while storing far fewer series.

All 18 scenes in Metrics / Monitoring System · Every curriculum

Built with Arqly
Every scene in Metrics / Monitoring System builds on the one before it.All 18 Metrics / Monitoring System scenes