Zalando's Search & Browse team experienced a self-inflicted DoS attack when an internal application sent resource-intensive faceting queries on high-cardinality fields to their Elasticsearch cluster. The incident caused search slowdowns and empty results for customers. The team mitigated by splitting markets across clusters,
•14m read time• From engineering.zalando.com
Table of contents
Who We AreAnthology of the System Under High LoadThe IncidentImmediate Actions TakenThe MarketsAdditional Load Shedding: Making the Cluster Breathe AgainNew Investigation and Finally, Root CauseBefore the Dawn: Cluster RecoveryThe RevelationWhy wasn't this detected earlier?Some theory on Elasticsearch DoS via Faceting Queries on High Cardinality FieldsFollow-up Actions and Lessons LearnedUseful Links2 Comments
Sort: