HNHacker News
TopNewBestAskShowJobs

mattklein123

75 karma · joined September 14, 2016

submissionscomments
mattklein123··on Announcing Envoy: C++ L7 proxy and communication bus
Mainly just years of experience at different companies watching ZK, etcd, etc. fall over at scale and require teams of people to maintain them.

We have had zero outages caused by our eventually consistent discovery system with active health checking (knock on wood), and haven't really touched the discovery service code in months. It just runs.

I'm not saying that a system using ZK, etc. can't be made to work. It certainly can since many companies do it. It's mostly that I think those solutions are actually making the overall problem a lot more complicated and prone to failure than it has to be.

mattklein123··on Announcing Envoy: C++ L7 proxy and communication bus
Visualization is going to be a big area of future investment for us. We already have some pretty cool tools internally and obviously lots of dashboards, etc. but we would love to have a dedicated UI for Envoy. If you know any good UI devs who would want to work on this please send them our way. :)
mattklein123··on Announcing Envoy: C++ L7 proxy and communication bus
Currently we support SNI for client connections, not for server connections. There is no reason for this, just that we have not needed server-side SNI ourselves yet. Adding server SNI support would be a small change. Please file a GitHub issue and we can look into adding support (or can help you with the patch!).
mattklein123··on Announcing Envoy: C++ L7 proxy and communication bus
Hi,

I work at Lyft. To answer your questions:

1) There is added cost, though it varies depending on how many things Envoy is configured to do (e.g., logging, tracing, stats, rate limiting, health checking, etc.). Even in complex scenarios (Envoy being used to proxy both inbound connections into a service, as well as proxy outbound connections to Mongo or Dynamo), we measure Envoy overhead to be < 1ms, which for almost all applications is negligible. There are definitely certain cases where this might be prohibitive, but in general we find the common functionality we get (again stats, tracing, etc.) to be invaluable in a production setting.

2) Envoy supports hot restart (https://lyft.github.io/envoy/docs/intro/arch_overview/hot_re...), as well as graceful drain of existing connections, so there is limited/no impact to existing clients. There is one enhancement that we would like to make to our HTTP/2 graceful draining to make it even more seamless, but that is more complicated than I can type here. :)

3) Right now Envoy does not support HTTP/2 priority so all streams are treated equally. We are currently working on priority support at the routing layer, with different connection pools available for high and low priority traffic, as well as circuit breaking settings. In the future we will likely merge this back into a single HTTP/2 connection with proper priority support. In practice though, within the DC, head of line blocking at the TCP layer isn't too much of an issue.

mattklein123··on Announcing Envoy: C++ L7 proxy and communication bus
We will fix the docs, apologies. FYI, your README still says that "HTTP/2 support is in progress".