Skip site navigation (1) Skip section navigation (2)

Re: Sync Rep Design

From: "Kevin Grittner" <Kevin(dot)Grittner(at)wicourts(dot)gov>
To: <simon(at)2ndquadrant(dot)com>
Cc: <greg(at)2ndquadrant(dot)com>,<hannu(at)2ndquadrant(dot)com>, <heikki(dot)linnakangas(at)enterprisedb(dot)com>, <robertmhaas(at)gmail(dot)com>, <stefan(at)kaltenbrunner(dot)cc>, <josh(at)postgresql(dot)org>, <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Sync Rep Design
Date: 2011-01-02 17:11:33
Message-ID: (view raw, whole thread or download thread mbox)
Lists: pgsql-hackers
Simon Riggs  wrote:
> Do you agree that requiring response from 2 sync standbys, or
> locking up, gives us 94% server availability, but 99.9992% data
> durability?
I'm not sure how to answer that.  The calculations so far have been
based around up-time and the probabilities that you have a machine up
at any moment and whether you can have confidence that if you do, you
have all committed transactions represented.  There's been an implied
assumption that the down time is unplanned, but not much else.  The
above question seems to me to get into too many implied assumptions
to feel safe throwing out a number without pinning those down a whole
lot better.  If, for example, that 2% downtime always means the
machine irretrievably went up in smoke, hitting unavailable means
things are unrecoverable.  That's probably not the best assumption
(at least outside of a combat zone), but what is?


pgsql-hackers by date

Next:From: Simon RiggsDate: 2011-01-02 17:43:02
Subject: Re: Sync Rep Design
Previous:From: Heikki LinnakangasDate: 2011-01-02 16:54:29
Subject: Re: Sync Rep Design

Privacy Policy | About PostgreSQL
Copyright © 1996-2017 The PostgreSQL Global Development Group