OWASP · Open source · Discussion: is the owasp-opensource ecosystem being replaced by another stack?

514
OWr/owasp-opensource·posted by li_ming·5 minutes agoTooling

Discussion: is the owasp-opensource ecosystem being replaced by another stack?

It took me two weeks of on-and-off digging and plenty of wrong turns. Writing the process down as it happened so the next person spends less time.

We also fixed monitoring along the way: replaced average-based alerts with percentiles and split them per endpoint. False alerts dropped by about seventy percent and the on-call rotation visibly cheered up.

On trade-offs, my view is this: if nobody on the team owns this area long-term, do not introduce a second mechanism. With two coexistence you first have to work out which one is even in play when things break, and that costs far more than the performance you saved.

Worth noting: the official docs do cover this, just in a very inconspicuous spot. I only found it reading the source comments, where the author explains the reasoning — roughly "so that it degrades into predictable behaviour in extreme cases".

246 comments

246 comments

· first 120 loaded
M
Hhuang_ke·28 minutes ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

504
Sslow_queryOP·1 hour ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

41
Bbob_chen·1 hour ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

335
Sswoole_lee·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

45
Lli_ming·2 hours ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

8
Wwinter·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

364
Lli_ming·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

109
LlinlinMod·2 days agoLevel 6

Saved. I am reworking this area this week — this saves a lot of wrong turns.

212
NnikicMod·5 hours agoLevel 6

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

157
Cchen_dev·2 days agoLevel 6

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

108
Zzhu_zong·2 days ago

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

15
Kkernel_panicMod·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

1
Sslow_query·12 minutes ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

154
Zzhu_zong·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

13
KkiteMod·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

91
Sslow_query·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

413
Oops_wang·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

62
Rran_bo·12 minutes agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

412
Bbob_chen·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

429
Ttang_hao·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

68
Ttang_hao·2 days agoLevel 6

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

1
Ttang_hao·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

3
Aalice_devMod·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

133
Bbob_chen·2 days ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

481
Kkernel_panic·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

458
Wwinter·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

450
Kkite·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

448
Sslow_query·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

442
Zzhu_zong·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

381
Zzhu_zong·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

433
Aalice_dev·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

389
Ttang_hao·2 days ago

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

85
Ttang_hao·1 hour ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

428
Aalice_dev·2 days ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

4
Kkite·1 hour ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

427
Hhuang_keOP·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

366
Zzhu_zong·1 hour ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

406
Sswoole_lee·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

404
Ttang_hao·12 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

388
Rrase·1 hour ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

367
Wwinter·2 days agoedited

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

3
Oops_wang·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

78
Cchen_dev·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

17
Ttang_haoOP·just now

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

279
Zzhu_zong·1 hour ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

298
Llinlin·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

514
Kkite·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

516
Aalice_dev·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

409
Aalice_dev·2 days ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

86
Kkernel_panic·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

3
Sslow_query·2 days ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

75
Sslow_query·yesterday

Saved. I am reworking this area this week — this saves a lot of wrong turns.

1
Hhuang_ke·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

246
Zzhu_zong·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

214
Ddev_zhouMod·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

159
Bbob_chen·2 days ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

158
Ttang_hao·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

139
Sswoole_leeOP·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

65
Sslow_query·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

112
Kkernel_panic·3 minutes ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

258
Rran_boOP·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

95
Bbob_chenOP·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

62
Rran_boMod·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

48
Sswoole_lee·2 days ago

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

72
Oops_wang·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

193
NnikicOP·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

45
RraseOP·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

10
Rran_bo·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

105
Zzhou_yi·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

101
Oops_wang·2 days ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

93
Nnikic·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

349
Sslow_query·2 days ago

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

92
Lli_mingOP·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

248
Ddev_zhou·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

371
Sswoole_lee·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

11
Hhuang_ke·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

79
Ttang_hao·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

66
Cchen_devOP·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1
Ttang_hao·2 days ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

60
Kkite·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

37
Kkite·just now

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

36
Rrase·5 hours ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

32
Ttang_hao·12 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1
Bbob_chen·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

493
Lli_ming·2 days agoedited

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

62
Sswoole_lee·2 days ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

173
Hhuang_ke·2 days agoLevel 6

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

4
Ddev_zhou·2 days agoLevel 6

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

3
Hhuang_ke·2 days ago

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

8
Mmike_xu·12 minutes ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

500
Lli_ming·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

19
Bbob_chen·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

321
Sslow_query·2 days ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

168
Sslow_query·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

495
Mmike_xu·3 minutes ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

128
Sswoole_lee·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

418
Wwinter·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

27
Nnikic·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

17
Sswoole_lee·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

17
Oops_wang·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

14
Nnikic·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

79
Sslow_queryOP·28 minutes ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

6
Llinlin·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

276
Rran_bo·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

1
Ttang_hao·2 days ago

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

6
Ttang_hao·2 days ago

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

288
Cchen_dev·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

6
Sslow_queryMod·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

12
Llinlin·2 days agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

5
Cchen_dev·just now

This is not a owasp-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

4
Rran_bo·just now

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

4
Kkernel_panic·1 hour ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

2
Aalice_dev·1 hour ago

I just read the owasp-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

150
Mmike_xu·1 hour ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

109
Zzhu_zongOP·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

111
Sswoole_lee·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

2
Wwinter·2 days agoedited

One counter-example: below owasp-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

2
Ttang_hao·28 minutes ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

2
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

1
Sslow_query·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

1

This is the post detail page /en/c/owasp-opensource/post/p7. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →