正在加载内容...

963963 Chat Wiki Portal Independent coverage of news

A Field Guide to Schema Migration

By Sarah Jenkins · · 1218 words
A Field Guide to Schema Migration

Consent is ongoing. A person can withdraw it at any point, including after previously agreeing or after an activity has begun. If they say stop, move away, become unresponsive or otherwise indicate discomfort, pause immediately and ask what they want. Do not argue, bargain or demand an explanation.

Log Analysis: You can often replace a coordination problem with an idempotency key. Log Analysis: Anything that grows without a bound will eventually hit one. Log Analysis: Documentation that is not tested tends to describe the previous version.

API Design: If a metric has no owner, it will drift until it causes an incident. API Design: The cheapest optimisation is usually removing work nobody asked for. API Design: Aggregating at write time trades flexibility for predictable read cost.

Storage Tiers: A design that cannot be rolled back is a design that cannot be changed safely. Storage Tiers: Latency budgets are easier to defend when every hop has a stated ceiling. Storage Tiers: Caching helps only until the invalidation rules become the bottleneck.

If a metric has no owner, it will drift until it causes an incident. This is most visible in content delivery. Consider content delivery specifically. The cheapest optimisation is usually removing work nobody asked for. Content Delivery: Aggregating at write time trades flexibility for predictable read cost.

Access Control: Periodic jobs should be safe to run twice, because they will be. Access Control: You rarely need a new component to fix a boundary problem. Access Control: The signal you want is often already logged, just not aggregated.

A useful way to think about consent is that it should be voluntary, informed, specific and ongoing. “Voluntary” means a person is choosing without force, threats or pressure that undermines their choice. “Informed” means they understand what they are agreeing to. Specificity means the agreement applies to what was actually discussed, not to a broader assumption. These are educational principles; the precise legal test depends on local law.

Access Control: Configurations should be reviewable in a diff, not only in a console. Access Control: The best time to add an index is before the table gets large. Access Control: Failures are usually correlated, so plan for the shared dependency.

Teams working on log analysis usually discover this the hard way. Serving static bytes is the cheapest thing you can do at the edge. A schema is an interface; changing it is a migration, not an edit. This is most visible in log analysis. Consider log analysis specifically. Track the denominator as carefully as the numerator.

A boundary is a limit a person sets around their own body, time, privacy or emotional wellbeing. In a relationship, it might concern which kinds of physical contact feel welcome, whether a person wants to use a barrier method during sex, how personal information is shared, or when they need time alone. Boundaries can be broad, but clear examples are easier to understand and respect.

Consent requires the ability to make and communicate a choice. Someone who is asleep or unconscious cannot agree at that time. Alcohol or other drugs can affect judgment and communication, but the legal rules for assessing capacity vary. The relevant question is not simply whether someone has consumed a substance; it is whether they can understand the choice and make it freely. If that is unclear, do not proceed.

Content Delivery: The first thing to settle is the failure mode, not the happy path. Measurements taken once are anecdotes; you need a baseline that repeats. That applies to content delivery as well. In practice, content delivery behaves differently: Costs usually concentrate in a small number of operations, so find those first.

Teams working on observability usually discover this the hard way. If the rollback plan needs a meeting, it is not a rollback plan. Small pages that stay small are easier to keep fast than large ones made fast. This is most visible in observability. Consider observability specifically. Write the invariant down; otherwise it lives only in someone's memory.

Backup Strategy: A queue smooths spikes but also hides how far behind you are. Backup Strategy: Retries without jitter turn a small outage into a large one. Backup Strategy: Separating the reads from the writes buys room to change either side.

Monitoring Alerts: Periodic jobs should be safe to run twice, because they will be. You rarely need a new component to fix a boundary problem. That applies to monitoring alerts as well. In practice, monitoring alerts behaves differently: The signal you want is often already logged, just not aggregated.

Log Analysis: If a metric has no owner, it will drift until it causes an incident. Log Analysis: The cheapest optimisation is usually removing work nobody asked for. Log Analysis: Aggregating at write time trades flexibility for predictable read cost.

Edge Caching: You can often replace a coordination problem with an idempotency key. Edge Caching: Anything that grows without a bound will eventually hit one. Edge Caching: Documentation that is not tested tends to describe the previous version.

The interesting number is not the average, it is the 99th percentile. That applies to rate limiting as well. In practice, rate limiting behaves differently: Adding a cache in front of a slow query is a fix; fixing the query is a cure. Every abstraction you add is a place where behaviour can differ from intent. The same reasoning holds for rate limiting.

Talking about boundaries can make intimacy clearer and safer, but it may feel awkward at first. A boundary is a limit or condition that describes what you are comfortable with; it is not a demand that another person must feel the same way. A step-by-step conversation can help both partners understand what is welcome, what is not, and how to respond when feelings or circumstances change.

If a metric has no owner, it will drift until it causes an incident. This is most visible in queue design. Consider queue design specifically. The cheapest optimisation is usually removing work nobody asked for. Queue Design: Aggregating at write time trades flexibility for predictable read cost.

You can often replace a coordination problem with an idempotency key. The same reasoning holds for rate limiting. For rate limiting, the constraint matters more than the feature list. Anything that grows without a bound will eventually hit one. Teams working on rate limiting usually discover this the hard way. Documentation that is not tested tends to describe the previous version.

Search Indexing: Periodic jobs should be safe to run twice, because they will be. Search Indexing: You rarely need a new component to fix a boundary problem. Search Indexing: The signal you want is often already logged, just not aggregated.

Queue Design: A design that cannot be rolled back is a design that cannot be changed safely. Queue Design: Latency budgets are easier to defend when every hop has a stated ceiling. Queue Design: Caching helps only until the invalidation rules become the bottleneck.

For storage tiers, the constraint matters more than the feature list. If a metric has no owner, it will drift until it causes an incident. Teams working on storage tiers usually discover this the hard way. The cheapest optimisation is usually removing work nobody asked for. Aggregating at write time trades flexibility for predictable read cost. This is most visible in storage tiers.

Related reading