NixOS · Toolchain · Those easily-missed type details in nixos-tools

1.6K
NIr/nixos-tools·posted by bob_chen·3 hours agoTranslation

Those easily-missed type details in nixos-tools

Some background first. Our setup is nixos-tools plus three downstream services, seven figures of daily requests, peaking around nine in the evening.

One last trap: in container environments remember to adjust the memory-related parameters in step. Otherwise the host limit and the process expectation disagree, and the symptom is intermittent, unreproducible failure.

We also fixed monitoring along the way: replaced average-based alerts with percentiles and split them per endpoint. False alerts dropped by about seventy percent and the on-call rotation visibly cheered up.

What genuinely surprised me was the tail. The average looked great while P99 jumped by an order of magnitude past some threshold. The cause was not nixos-tools itself but our upstream connection reuse — the load test traffic was too clean and hid the long-tail requests.

On trade-offs, my view is this: if nobody on the team owns this area long-term, do not introduce a second mechanism. With two coexistence you first have to work out which one is even in play when things break, and that costs far more than the performance you saved.

868 comments

868 comments

· first 120 loaded
M
Wwinter·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

484
Ttang_hao·2 days ago

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

456
Sslow_query·5 hours ago

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

115
Zzhu_zong·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

413
Mmike_xu·yesterday

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

405
Ddev_zhou·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

397
Ddev_zhou·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

397
Zzhou_yi·2 days agoedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

396
Zzhou_yi·3 minutes ago

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

386
Ddev_zhou·1 hour ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

385
Ddev_zhou·just now

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

46
Ttang_haoOPMod·2 hours ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

174
Nnikic·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

76
Zzhou_yi·2 hours agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

190
Ddev_zhou·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

443
Zzhu_zong·2 days agoLevel 6

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

482
Kkite·2 days agoLevel 6

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

310
Cchen_dev·2 days agoLevel 6

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

233
Hhuang_ke·12 minutes agoLevel 6

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

94
Sslow_query·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

131
Lli_ming·2 days agoLevel 6

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

18
Wwinter·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

7
Aalice_dev·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

38
RraseMod·3 minutes ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

363
Zzhou_yi·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

8
Cchen_dev·2 hours agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

5
Bbob_chen·just now

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

417
Kkernel_panic·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

103
Oops_wang·2 days agoLevel 6

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

1
Ddev_zhou·12 minutes ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

222
Rran_bo·12 minutes agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

398
Oops_wang·2 days agoLevel 6

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

241
Wwinter·2 days agoLevel 6

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

52
Hhuang_ke·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

116
Bbob_chen·2 days ago

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

88
Rran_bo·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

64
Sslow_query·1 hour ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

4
Sslow_query·yesterday

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

361
Wwinter·2 days ago

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

397
Aalice_dev·yesterday

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

72
Nnikic·2 days agoLevel 6

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

133
Rran_bo·2 days ago

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

361
Rran_bo·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

381
Ddev_zhou·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

155
Nnikic·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

377
Ttang_hao·5 hours ago

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

352
Zzhou_yiMod·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

350
Zzhou_yi·yesterday

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

350
Ttang_hao·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

300
Ttang_hao·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

292
Lli_mingMod·2 days agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

257
Zzhu_zongOP·2 days ago

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

157
Oops_wangOP·2 days ago

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

146
Zzhou_yiOP·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

155
Mmike_xu·28 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

6
Hhuang_ke·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

1
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

176
Ddev_zhou·2 days agoedited

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

163
Cchen_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

125
Llinlin·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

2
Sswoole_lee·just now

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

123
Llinlin·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

115
Ttang_hao·28 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

225
Wwinter·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

96
Aalice_devMod·2 days agoedited

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

372
Bbob_chen·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

79
Zzhu_zong·2 days ago

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

75
Aalice_devMod·2 days ago

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

315
Bbob_chen·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

475
Oops_wang·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

21
Mmike_xu·2 days ago

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

169
Rran_bo·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

13
Ttang_hao·2 days agoedited

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

154
Lli_ming·2 days ago

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

6
Kkernel_panic·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

314
Kkernel_panic·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

73
Rran_bo·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

54
Zzhou_yi·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

42
Cchen_dev·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

40
Ddev_zhou·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

34
Kkernel_panic·5 hours ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

25
Ddev_zhou·yesterday

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

25
Hhuang_ke·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

20
Hhuang_ke·2 days agoedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

19
Ddev_zhou·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

257
Lli_mingMod·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

233
Rrase·2 days ago

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

210
Rrase·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

518
Bbob_chenOP·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

111
Aalice_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

31
Kkernel_panicMod·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

141
Lli_ming·2 days agoedited

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

15
Kkite·12 minutes ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

17
Rran_boOP·2 days ago

I just read the nixos-tools source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

34
Zzhu_zong·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

1
NnikicOP·2 days agoedited

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

5
Ddev_zhou·2 days agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

266
Oops_wang·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

10
Lli_ming·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

3
Aalice_devOP·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

8
Ttang_hao·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

26
Bbob_chen·just now

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

8
Rran_bo·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

8
Zzhou_yi·3 minutes ago

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

7
Rrase·2 days ago

This is not a nixos-tools problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

492
Sswoole_lee·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

6
Bbob_chen·12 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

6
Hhuang_keMod·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

1
Nnikic·5 hours ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

4
Zzhu_zong·2 days agoedited

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

2
Aalice_devMod·2 days agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

2
Oops_wang·3 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

1
Ttang_hao·2 days agoedited

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

1
Zzhu_zong·1 hour ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

461
Cchen_dev·2 days ago

One counter-example: below nixos-tools 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

101
Aalice_dev·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

99
Rrase·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

286
Ttang_hao·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

172
Lli_ming·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

43
Oops_wang·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

1

This is the post detail page /en/c/nixos-tools/post/p2. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →