<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reliability on Kuldeep Pisda</title><link>https://kdpisda.in/tag/reliability/</link><description>Recent content in Reliability on Kuldeep Pisda</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 19 Sep 2026 09:00:00 +0530</lastBuildDate><atom:link href="https://kdpisda.in/tag/reliability/index.xml" rel="self" type="application/rss+xml"/><item><title>Retry Budgets Don't Stop Retry Storms. Uber's Error Ownership Protocol Does</title><link>https://kdpisda.in/uber-error-ownership-retry-storms/</link><pubDate>Sat, 19 Sep 2026 09:00:00 +0530</pubDate><guid>https://kdpisda.in/uber-error-ownership-retry-storms/</guid><description>&lt;p&gt;Retry budgets are the standard answer to retry storms: cap retries at each hop to some percentage of traffic, and the theory is that a struggling downstream service never gets hit with more than a bounded multiple of its normal load. Uber&amp;rsquo;s engineering team published the math showing why that theory is wrong for any call chain with real depth, and shipped a fix that&amp;rsquo;s been running across their service mesh: a header-based protocol that tells each service whether an error it&amp;rsquo;s looking at is actually its own to retry, or someone else&amp;rsquo;s.&lt;/p&gt;</description></item></channel></rss>