Book

All Things Distributed

by Werner Vogels · 2008 · 1 reading card

AuthorWerner VogelsShelvesData warehousing

1 card

  1. All Things Distributed · 2008

    A backup never tested by restoring is an assumption, not a backup.

    In the cloud, compute is separated from storage and elastic: you pay per second or per query, buy no hardware, upgrades belong to the vendor, regions are a click away. The reverse: data egress costs, unbounded queries that produce surprise bills, vendor dependence and data residency, which for regulated data demands a European region and keys you manage. On-prem: predictable cost at steady load, full control, low latency to internal systems, sensitive data that never leaves. The reverse: capacity planning (you pay for the peak all year), upgrades, people, a single site. The decision rests on a few variables, not fashion: how variable the load is, what regulation demands, what the team knows, what licences already exist, how much goes out as egress. Hybrid is legitimate: the identity vault at home, token-keyed facts in the cloud. And Vogels' sentence holds in both places: the disk fails in your data centre too, the vendor has outages too. So backups tested by restoring, not by existing; recovery drills; two zones. "Where" is the small question; "what happens when it fails" is the big one.

    Everything fails, all the time.

    Open the card