Capacitor · Ops · Choosing capacitor-ops: I turned 5 options into a side-by-side comparison

768
CAr/capacitor-ops·posted by chen_dev·2 hours agoExperience

Choosing capacitor-ops: I turned 5 options into a side-by-side comparison

Most capacitor-ops articles stop at "how to use it" and never cover "when not to use it". This is an attempt at the second half.

Order of investigation, by return on effort: 1. Check downstream latency first — usually it is not your problem 2. Then pool hit rate and wait-queue length 3. Only then GC and allocation 4. Suspect the framework last

Worth noting: the official docs do cover this, just in a very inconspicuous spot. I only found it reading the source comments, where the author explains the reasoning — roughly "so that it degrades into predictable behaviour in extreme cases".

We also fixed monitoring along the way: replaced average-based alerts with percentiles and split them per endpoint. False alerts dropped by about seventy percent and the on-call rotation visibly cheered up.

On trade-offs, my view is this: if nobody on the team owns this area long-term, do not introduce a second mechanism. With two coexistence you first have to work out which one is even in play when things break, and that costs far more than the performance you saved.

One last trap: in container environments remember to adjust the memory-related parameters in step. Otherwise the host limit and the process expectation disagree, and the symptom is intermittent, unreproducible failure.

129 comments

129 comments

· first 120 loaded
M
Mmike_xu·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

445
Rran_boOP·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

379
Zzhu_zong·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

430
Wwinter·3 minutes ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

414
Ttang_hao·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

408
Llinlin·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

251
Llinlin·2 days ago

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

243
Kkernel_panic·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

201
Hhuang_ke·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

171
Zzhou_yi·12 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

166
Llinlin·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

160
Zzhou_yi·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

135
Aalice_dev·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

128
Zzhou_yiOP·3 minutes ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

60
Ddev_zhou·3 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

323
Sswoole_lee·yesterdayedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

306
Cchen_dev·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

238
Hhuang_ke·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

151
Cchen_devMod·12 minutes ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

199
Zzhu_zong·2 days agoLevel 6

Saved. I am reworking this area this week — this saves a lot of wrong turns.

78
Nnikic·yesterday

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

66
Rrase·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

296
Hhuang_ke·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

5
Oops_wang·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

1
Rran_boOP·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

411
Bbob_chen·just now

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

2
Kkernel_panicMod·2 days ago

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

89
Zzhou_yi·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

145
Sswoole_lee·yesterday

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

117
Sswoole_lee·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

103
Rrase·2 days agoedited

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

86
Kkernel_panic·2 hours ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

59
Nnikic·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

99
Zzhou_yiOP·2 days ago

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

28
Aalice_dev·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

83
Ttang_hao·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

82
Ddev_zhou·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

74
Ttang_hao·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

60
Nnikic·2 days agoedited

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

94
Oops_wang·3 minutes ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

54
Lli_mingMod·3 minutes ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

373
Bbob_chen·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

62
Kkernel_panicMod·3 minutes ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

120
Sslow_query·2 days ago

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

250
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

28
Kkite·3 minutes ago

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

1
Sslow_query·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

437
Mmike_xu·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

1
Rran_bo·2 days ago

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

278
Ddev_zhou·12 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

72
Llinlin·12 minutes ago

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

159
Ddev_zhouOP·2 days ago

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

3
Kkite·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

375
Rran_boOP·2 hours ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

47
Mmike_xu·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

45
Oops_wang·5 hours agoedited

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

38
Ttang_hao·12 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

15
Aalice_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

41
Mmike_xu·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

51
Oops_wang·2 days ago

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

48
Sswoole_leeMod·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

43
Rran_bo·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

37
Rrase·just now

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

32
Cchen_dev·just now

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

198
Nnikic·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

263
Hhuang_ke·2 days agoedited

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

31
Aalice_dev·28 minutes agoedited

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

155
Kkernel_panic·2 days ago

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

8
Rrase·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

19
Zzhu_zong·1 hour agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

27
Oops_wangMod·2 days ago

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

449
Rrase·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

44
Ddev_zhou·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

146
Sswoole_lee·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

1
Lli_ming·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

179
Kkernel_panic·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

70
Cchen_devOP·2 days agoLevel 6

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

302
Kkite·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

47
Kkernel_panicOP·2 days ago

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

96
Mmike_xu·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

334
Mmike_xu·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

104
Zzhou_yiOP·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

12
Wwinter·28 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

413
Hhuang_ke·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

253
Llinlin·5 hours ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

5
Rran_boMod·3 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

350
Hhuang_ke·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

263
Kkite·2 days agoLevel 6

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

456
Lli_ming·2 days agoLevel 6

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

138
Hhuang_ke·yesterday

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

58
Ddev_zhou·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

1
Sswoole_lee·2 days agoLevel 6

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

332
RraseOP·3 minutes agoeditedLevel 6

Saved. I am reworking this area this week — this saves a lot of wrong turns.

6
Aalice_dev·2 days agoLevel 6

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

39
Mmike_xu·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

25
Oops_wang·12 minutes ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

15
Sslow_query·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

15
Lli_ming·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

1
Ddev_zhou·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

1
Kkite·yesterday

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

256
Rran_bo·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

377
Cchen_dev·3 minutes agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

281
Rran_bo·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

34
Cchen_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

195
Aalice_dev·2 days ago

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

13
Oops_wang·2 days ago

I just read the capacitor-ops source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

7
Wwinter·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

294
Hhuang_ke·3 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

13
Mmike_xu·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

5
Kkite·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

479
Lli_ming·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

32
Wwinter·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

385
Lli_ming·3 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

5
Rrase·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

4
Kkite·yesterday

Saved. I am reworking this area this week — this saves a lot of wrong turns.

2
Wwinter·28 minutes agoedited

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

139
Mmike_xu·2 days ago

One counter-example: below capacitor-ops 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

1
Bbob_chen·2 days ago

This is not a capacitor-ops problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

1
Mmike_xu·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1
Aalice_dev·2 days agoedited

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1

This is the post detail page /en/c/capacitor-ops/post/p6. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →