Monitoring · Advanced · monitoring-pro logging: what separates "readable" from "usable"

1.7K
MOr/monitoring-pro·posted by ops_wang·2 days agoReview

monitoring-pro logging: what separates "readable" from "usable"

It took me two weeks of on-and-off digging and plenty of wrong turns. Writing the process down as it happened so the next person spends less time.

What genuinely surprised me was the tail. The average looked great while P99 jumped by an order of magnitude past some threshold. The cause was not monitoring-pro itself but our upstream connection reuse — the load test traffic was too clean and hid the long-tail requests.

The first thing was to collapse the variables. We were changing config and upgrading the version at the same time, and afterwards nobody could say which change caused what. We rolled back to moving one variable at a time, re-ran three times, and only then did the curve settle. Tedious, but not skippable.

We also fixed monitoring along the way: replaced average-based alerts with percentiles and split them per endpoint. False alerts dropped by about seventy percent and the on-call rotation visibly cheered up.

On trade-offs, my view is this: if nobody on the team owns this area long-term, do not introduce a second mechanism. With two coexistence you first have to work out which one is even in play when things break, and that costs far more than the performance you saved.

747 comments

747 comments

· first 120 loaded
M
Oops_wang·2 days ago

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

509
Kkernel_panicOP·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

338
Lli_ming·3 minutes ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

461
Ttang_hao·1 hour ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

271
Ttang_hao·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

454
Rrase·2 hours ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

411
Oops_wangOP·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

326
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

237
Lli_ming·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

375
Sswoole_lee·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

273
Nnikic·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

257
Hhuang_ke·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

254
Kkernel_panic·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

245
Ddev_zhou·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

236
Sswoole_lee·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

59
Rrase·2 days agoedited

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

6
Lli_ming·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

352
Aalice_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

18
Llinlin·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

220
Rrase·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

196
Hhuang_ke·12 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

192
Rrase·1 hour ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

192
Bbob_chen·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

220
Sswoole_lee·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

9
Aalice_dev·1 hour ago

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

183
Kkite·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

152
Hhuang_ke·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

162
Mmike_xu·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

1
Kkite·2 days ago

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

160
Nnikic·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

151
Zzhou_yiOP·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

4
Cchen_dev·2 days ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

151
Hhuang_ke·5 hours ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

151
Llinlin·2 days agoedited

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

142
LlinlinMod·2 days ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

141
Kkernel_panic·5 hours ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

130
Zzhu_zong·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

121
Ddev_zhou·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

114
Wwinter·12 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

1
Zzhu_zong·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

108
Bbob_chenOP·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

54
Kkite·2 days ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

114
Hhuang_ke·just now

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

72
Kkernel_panicOP·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

10
Lli_ming·2 hours ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

68
Zzhu_zong·12 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

52
Llinlin·12 minutes agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

474
Rrase·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

67
Bbob_chen·12 minutes agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

110
Zzhu_zong·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

24
LlinlinOP·yesterday

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

373
Ttang_hao·2 days ago

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

353
Rrase·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

55
Aalice_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

463
Sslow_query·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

391
Hhuang_ke·2 days agoLevel 6

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

179
Wwinter·2 days ago

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

389
Lli_ming·2 hours agoLevel 6

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

52
Aalice_dev·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

382
Kkernel_panic·3 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

1
Bbob_chen·just nowedited

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

53
Hhuang_ke·2 hours agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

81
Llinlin·2 days agoLevel 6

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

338
Ttang_hao·2 days agoedited

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

29
Bbob_chen·2 days agoedited

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

80
Llinlin·2 days agoLevel 6

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

254
KkiteMod·yesterday

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

1
Oops_wang·3 minutes ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

49
Hhuang_ke·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

479
Wwinter·2 days ago

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

243
Ttang_hao·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

17
Ddev_zhou·12 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

147
Rran_bo·2 days agoLevel 6

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

117
Hhuang_ke·28 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

3
Cchen_devOP·2 hours ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

85
Zzhu_zongOP·just now

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

480
Rran_bo·2 days ago

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

111
Llinlin·just now

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

104
Wwinter·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

49
Kkernel_panic·2 hours ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

1
Lli_ming·12 minutes agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

98
Bbob_chen·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

334
Bbob_chen·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

24
Hhuang_ke·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

16
Sswoole_leeOP·12 minutes ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

8
Zzhou_yi·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

40
Sslow_query·3 minutes ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

38
Sslow_query·just now

Saved. I am reworking this area this week — this saves a lot of wrong turns.

262
Sslow_query·1 hour ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

38
Ddev_zhouMod·yesterdayedited

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

327
Kkite·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

369
Sswoole_lee·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1
Nnikic·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

485
Wwinter·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

25
Zzhou_yi·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

33
Kkite·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

26
Lli_ming·5 hours ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

19
Nnikic·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

24
Aalice_dev·3 minutes ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

18
Mmike_xu·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

17
Nnikic·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

18
Rrase·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

16
Nnikic·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

13
Mmike_xuMod·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

13
Zzhu_zong·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

11
Wwinter·3 minutes agoedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

9
Sswoole_lee·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

9
Bbob_chen·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

9
Rrase·2 days ago

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

368
Ttang_hao·2 days agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

49
Hhuang_keOP·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

2
Rran_bo·3 minutes ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

123
Hhuang_ke·2 days ago

One counter-example: below monitoring-pro 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

369
Kkite·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

6
Cchen_dev·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

2
Cchen_dev·yesterday

This is not a monitoring-pro problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

11
Ttang_hao·3 minutes ago

I just read the monitoring-pro source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

1
Kkernel_panic·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

1
Zzhu_zongMod·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

243
Oops_wang·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

39

This is the post detail page /en/c/monitoring-pro/post/p13. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →