Salesforce EngineeringScott Nyberg5 min readadvanced
How Intelligent Load Shedding Prevents Cascading Failures in Tier-0 Systems
Summary
Salesforce's Cloud Atlas team redesigned service protection for their Tier-0 identity platform to prevent cascading failures from unpredictable traffic. They implemented intelligent load shedding based on queue time and coordinator-free global quota management to ensure five nines availability and tenant fairness.
- Per-instance rate limiting becomes insufficient with autoscaling and dynamic traffic, leading to outdated limits and inefficient capacity usage.
- Multi-tenant systems require global quota management to prevent 'noisy neighbors' from consuming shared resources and impacting other tenants.
- Intelligent load shedding monitors queue time as an early indicator of system pressure, allowing graceful degradation before cascading failures begin.
- Coordinator-free global quota management enables servers to make independent throttling decisions, avoiding a central bottleneck while ensuring fairness.
Engineers building highly available, multi-tenant distributed systems can learn practical strategies for preventing cascading failures and managing unpredictable traffic in critical services.
7/10



