[HN Gopher] Let's Encrypt API v2 Service Disruption (12 Sep 2021)
       ___________________________________________________________________
        
       Let's Encrypt API v2 Service Disruption (12 Sep 2021)
        
       Author : frutiger
       Score  : 24 points
       Date   : 2021-09-12 19:45 UTC (3 hours ago)
        
 (HTM) web link (letsencrypt.status.io)
 (TXT) w3m dump (letsencrypt.status.io)
        
       | throwaway20371 wrote:
       | I think the OP was referencing this:
       | https://letsencrypt.status.io/pages/history/55957a99e800baa4...
       | September 12, 2021 20:30 UTC           Service disruption
       | September 12, 2021 05:39 UTC           Production planned
       | maintenance                September 12, 2021 02:33 UTC
       | Degraded API and OCSP Performance
       | 
       | And then you see this planned maintenace for the 20th:
       | September 20, 2021 16:30 - 17:00 UTC           API Database
       | Maintenance
       | 
       | I'm curious what kind of database and maintenance. The one useful
       | thing about Cloud-managed NoSQL databases is the potential for
       | zero-downtime maintenance. Making it stable enough is a hercluean
       | task for the Cloud provider, but the customer never has to think
       | about it.
        
         | traceroute66 wrote:
         | > Cloud-managed NoSQL databases is the potential for zero-
         | downtime maintenance.
         | 
         | Aah yes... that magical "zero-downtime" cloud, lots of promises
         | are made by the cloud providers in that area but all eventually
         | broken at some point. Its a fact of life with technology
         | unfortunately. :)
         | 
         | No need for the cloud with ScyllaDB[1], CockroachDB[2] and
         | others all being used in production.
         | 
         | LetsEncrypt chose their setup for perfectly valid reasons they
         | described on their blog[3]. Please describe your expertise for
         | saying they're "doing it wrong", because its clear from their
         | blog they put a lot of time thinking about it.
         | 
         | [1]https://www.scylladb.com/ [2]https://www.cockroachlabs.com/
         | [3]https://letsencrypt.org/2021/01/21/next-gen-database-
         | servers...
        
           | throwaway20371 wrote:
           | I'm not an expert, and I'm not saying they're doing it wrong.
           | 
           | But, for what it's worth, just because they thought for a
           | long time doesn't mean they made the right choices. Some of
           | their design decisions have been not great. You can still
           | create perfectly valid domain certs with a variety of common
           | attacks. I think they know this and they chose a simpler
           | design that's more flawed.
        
         | abraham wrote:
         | https://letsencrypt.org/2021/01/21/next-gen-database-servers...
        
           | throwaway20371 wrote:
           | _" Database performance is the single most critical factor in
           | our ability to scale while meeting service level
           | objectives."_
           | 
           | Ah, that's unfortunate. It's hard to get RDBMS
           | reliability/performance "right" in the face of changes, and
           | scaling it isn't easy. But at least all the problems are
           | well-known.
        
       ___________________________________________________________________
       (page generated 2021-09-12 23:01 UTC)