Keyboard Community · Six rules for error handling in keyboard that I settled on

204
KEr/keyboard·posted by bob_chen·3 days agoDiscussionPinned

Six rules for error handling in keyboard that I settled on

It took me two weeks of on-and-off digging and plenty of wrong turns. Writing the process down as it happened so the next person spends less time.

Worth noting: the official docs do cover this, just in a very inconspicuous spot. I only found it reading the source comments, where the author explains the reasoning — roughly "so that it degrades into predictable behaviour in extreme cases".

What genuinely surprised me was the tail. The average looked great while P99 jumped by an order of magnitude past some threshold. The cause was not keyboard itself but our upstream connection reuse — the load test traffic was too clean and hid the long-tail requests.

Nnews.ycombinator.comExternal link · opens in a new tab
86 comments

86 comments

M
Ddev_zhouOP·12 minutes ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

437
Mmike_xuOP·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

196
Hhuang_ke·yesterday

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

492
Kkite·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

34
Zzhu_zong·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

486
Kkernel_panicOP·2 days agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

176
Llinlin·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

325
Aalice_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

143
Zzhu_zongOP·2 days agoedited

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

259
Rrase·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

248
Nnikic·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

485
Kkite·2 days ago

One counter-example: below keyboard 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

429
Rran_bo·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

427
Sslow_query·2 days ago

This is not a keyboard problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

414
Lli_ming·28 minutes ago

I just read the keyboard source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

406
Bbob_chen·3 minutes ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

19
Hhuang_ke·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

84
Cchen_devOP·3 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1
Lli_ming·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

18
Ttang_hao·5 hours ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

54
Wwinter·just now

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

347
Lli_ming·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

168
Cchen_dev·yesterdayLevel 6

Saved. I am reworking this area this week — this saves a lot of wrong turns.

232
Llinlin·5 hours ago

This is not a keyboard problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

13
Rrase·2 days agoLevel 6

I just read the keyboard source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

373
Nnikic·2 hours agoLevel 6

Saved. I am reworking this area this week — this saves a lot of wrong turns.

47
Rran_bo·2 days ago

This is not a keyboard problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

28
Cchen_dev·2 hours ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

185
Kkite·3 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

14
Zzhou_yi·5 hours agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

495
Wwinter·2 hours ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

336
Kkernel_panic·yesterday

One counter-example: below keyboard 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

309
Zzhou_yi·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

205
Oops_wang·2 hours ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

262
Oops_wangOP·2 days ago

I just read the keyboard source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

141
Bbob_chen·just nowLevel 6

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

236
Llinlin·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

51
Ddev_zhou·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

21
Wwinter·2 days agoLevel 6

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

277
Rran_bo·yesterdayeditedLevel 6

Saved. I am reworking this area this week — this saves a lot of wrong turns.

24
Kkernel_panic·2 days agoLevel 6

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

9
Aalice_dev·2 days agoeditedLevel 6

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

4
Hhuang_ke·2 hours ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

1
Oops_wang·2 days agoLevel 6

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

247
Ddev_zhou·2 hours ago

One counter-example: below keyboard 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

156
Aalice_dev·2 hours ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

204
Mmike_xu·28 minutes agoLevel 6

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

6
Llinlin·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

1
Rrase·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

474
Bbob_chen·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

326
Mmike_xu·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

7
Llinlin·just now

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

404
Oops_wang·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

398
WwinterOP·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

321
Wwinter·12 minutes ago

One counter-example: below keyboard 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

380
Kkernel_panic·28 minutes agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

346
Sswoole_lee·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

319
Zzhou_yiOP·28 minutes agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

209
Nnikic·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

267
Kkernel_panic·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

259
Aalice_devMod·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

84
Sswoole_lee·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

230
Bbob_chen·yesterday

This is not a keyboard problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

174
LlinlinOP·2 days agoedited

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

109
Llinlin·yesterday

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

167
LlinlinOP·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

105
Wwinter·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

59
Mmike_xu·12 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

145
Lli_ming·just nowedited

I just read the keyboard source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

8
Rran_bo·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

133
Kkernel_panic·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

106
Zzhou_yi·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

96
WwinterOP·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

234
Ddev_zhou·yesterday

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

87
Kkernel_panic·2 days agoedited

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

78
Lli_mingMod·1 hour ago

This is not a keyboard problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

66
RraseOP·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

1
Cchen_dev·3 minutes agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

34
Sswoole_lee·2 days ago

One counter-example: below keyboard 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

27
Ddev_zhou·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

6
Sswoole_lee·2 days ago

I just read the keyboard source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

11
Rran_bo·2 days ago

I just read the keyboard source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

6
Sslow_query·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

361
Llinlin·28 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

4
Sswoole_lee·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

37
Oops_wang·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1

This is the post detail page /en/c/keyboard/post/p0. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →