Full Transcript

·YouTLDR

CS75 (Summer 2012) Lecture 9 Scalability Harvard Web Development David Malan

1:45:42EnglishTranscribed Jul 25, 2026
0:09

welcome back to computer science s75

0:11

this is lecture nine our very last it

0:13

has been a pleasure having everyone in

0:15

the course this semester um so tonight

0:17

we talk about scalability so we try to

0:19

revisit some of the topics that we

0:20

looked at earlier in the semester and

0:22

think about how we can deploy

0:24

applications not just on say a virtual

0:26

machine on your laptop or desktop as

0:28

we've been doing with the appliance but

0:30

you can scale to servers on the internet

0:32

and indeed multiple servers on the

0:33

internet so that you can handle hundreds

0:35

or thousands or tens of thousands or

0:37

even more than that in theory so some of

0:40

the issues that we'll inevitably

0:42

encounter is how to go about doing this

0:44

so when it comes time to put something

0:46

on the Internet recall from lecture zero

0:47

that we talked about web host so this is

0:49

by no means a list of recommendations

0:51

per se it's just some representative

0:53

ones that we happen to recommend um if

0:55

only because the teaching fellows and I

0:57

have had prior experiences with these

0:59

particular vendors um but you can Google

1:01

around and you can see that there's many

1:02

many many different options these days

1:04

however among the takeaways hopefully

1:06

from the summer thus far has been what

1:09

kinds of featur should you be looking

1:10

for or expecting minimally in any web

1:13

hosting company that you might

1:16

choose and in fact not all of these even

1:19

have those features

1:21

necessarily

1:25

accessibility example I have

1:28

Aver Daddy my access isos Ser to have s

1:34

to the post interesting okay good so if

1:37

you're if you're country or your work or

1:39

really any network that you happen to be

1:41

on or people that you know happen to be

1:42

on block access to certain IP ranges

1:45

among them for instance God daddies in

1:47

this case YouTube is a popular thing to

1:49

block Facebook is a popular thing to

1:50

block um that can be a sticking point so

1:53

doing a bit of do diligence or testing

1:55

first can be a good thing what else

1:58

should you look for in a hosting company

2:01

company Isaac SFTP good SFTP in contrast

2:06

with what FTP FTP and why because ft

2:10

SFTP is secure okay good so the S

2:13

literally stands for secure and what

2:14

that means is that all of your traffic

2:16

is encrypted and this maybe isn't a big

2:18

deal for the files that you're

2:19

transferring because after all if you're

2:21

uploading like gifs and jpegs and video

2:23

files that are meant to be downloaded by

2:25

people on the web well then who really

2:26

cares if you encrypt those between your

2:28

machine and the server but it is

2:30

important to have what data

2:32

encrypted Jack usernames passwords

2:35

anything of exactly usernames and

2:37

passwords right I mean that's one of the

2:39

biggest failings of something like FTP

2:41

which granted is a fairly dated or older

2:43

protocol is that it sends also your

2:45

username and password in the clear which

2:47

means anyone sniffing wirelessly around

2:49

you anyone sniffing the wi Network

2:51

between point A and B can see in the

2:53

clear what your username and password

2:54

are yeah we looked at some hosting

2:57

companies that offer unlimited

2:59

everything for a really low price that

3:01

could be due to um um virtual hosting

3:06

and if you want to implement A system

3:08

that can grow by itself you maybe don't

3:10

want to share the same computers the

3:12

same the same server with many others

3:15

good so dream host in particular I think

3:17

we pulled up their feature list and it

3:19

was ridiculous how many features they

3:21

give you unlimited bandwidth unlimited

3:23

storage space unlimited Ram or something

3:25

like that and that just can't possibly

3:27

be uh real if you're only paying like

3:31

$9.95 a month so there's some catch and

3:33

in general the catch is that they're

3:35

making that offer to you and to 100 to

3:37

hundreds of other customers all of whom

3:40

might be on that same machine so you're

3:42

contending now for resources and the

3:43

reality is they're probably banking in

3:45

the fact that 90 something per of their

3:46

customers don't need that many resources

3:49

but for the one person or two persons

3:50

that do probably going the way of a

3:52

shared host is not necessarily in your

3:54

best interest certainly not something to

3:55

try to build a bigger business on and so

3:58

there's alternatives to things like web

3:59

hosting companies there's vpss a virtual

4:02

private server that you can essentially

4:05

rent for yourself and what's the

4:07

fundamental distinction between a VPS

4:09

and a shared web

4:11

post Axel well VPS is like our Linux

4:16

it's a it's it's virtual own machine

4:18

running on a box but it's it's

4:20

completely its own system okay good well

4:22

and so be to be clear the operating

4:24

system is largely irrelevant since dream

4:26

host and shared web host could also be

4:27

running Fedora or any operating system

4:29

but what's key is that you get your own

4:31

copy of Fedora or Ubuntu or whatever

4:34

operating system they happen to be

4:35

running because in the world of VPS is

4:37

what they do is they take generally a

4:38

super fast server with lots of ram lots

4:40

of CPU lots of dis space and they chop

4:43

it up into the illusion of multiple

4:45

servers using something called a

4:46

hypervisor something like a product from

4:48

VMware or Citrix or other companies and

4:52

even open source providers have

4:53

platforms that allow you to do this run

4:56

multiple uh virtual machines on a

4:58

physical machine and so in this world

5:00

you're still sharing resources but

5:02

different typ uh in a different way

5:04

you're instead getting some slice of

5:07

Hardware to yourself and no one else has

5:10

user accounts on that particular virtual

5:12

machine now with that said the system

5:14

administrators the owners of the VPS

5:17

company they themselves depending on

5:19

what hypervisor they're using they might

5:21

actually have access to your virtual

5:22

machine and to your files and frankly if

5:24

you have physical access to the machine

5:26

you undoubtedly have access to your

5:28

files because they can always reboot the

5:30

virtual machine for instance in what's

5:32

called single user mode or diagnostic

5:34

mode and at that point it's not they're

5:35

not even prompted for a root password so

5:37

realize that even when you're using a

5:39

VPS your data might be more secure more

5:42

private from other customers but

5:44

definitely not the web hosting company

5:46

itself if you want even more privacy

5:48

than that you're probably going to have

5:49

to operate your own servers that only

5:51

you or your colleagues have physical

5:53

access to so here's just a list of some

5:55

of the popular VPS companies there is

5:57

one catch in order to get these

5:59

additional features or these uh

6:01

properties in a VPS you generally pay

6:04

more so instead of $10 a month $20 a

6:06

month you're probably starting it $50 a

6:08

month or something like that maybe even

6:10

in the hundreds depending on how many

6:12

how much you want in the way of um uh

6:15

resources and toward the end of today

6:17

we'll talk about one particular vendor

6:20

of vpss um namely Amazon uh web services

6:24

Amazon ec2 their elastic compute Cloud

6:27

that essentially lets you self-service

6:29

and spawn as many virtual machines as

6:31

you want so long as you're willing to

6:33

pay some number of cents per minute to

6:35

have that virtual machine up and running

6:37

and it's actually a wonderful way to uh

6:39

plan for uh unexpected growth because

6:43

you can even automate the process of

6:44

spawning more web servers more database

6:46

servers if you happen to suddenly get

6:48

popular even overnight or because you've

6:50

been slash dotted or posted on Reddit or

6:52

the like and then you can have those

6:54

machines automatically power off when

6:56

interest in your product or website has

6:58

started to subside all right so how

7:01

suppose you are the fortunate sufferer

7:04

of a good problem which is that your

7:05

website all of a sudden is super super

7:07

popular and this website has maybe some

7:09

static web content HTML files gifs and

7:12

the like Dynamic content like PHP code

7:15

uh maybe even some database stuff maybe

7:18

some uh database stuff like MySQL well

7:22

how do you go about scaling your site so

7:24

that it can handle more users well the

7:28

most straightforward approach which is

7:29

generally what's called vertical scaling

7:31

vertical in the sense that well if

7:33

you're running low on Ram or you're kind

7:35

of exhausting your available CPU Cycles

7:38

or you're running low on disk space

7:40

what's the easiest most obvious solution

7:42

to that

7:43

problem AEL get a better processor and

7:46

more RAM good get more RAM more

7:48

processor more disk space and just throw

7:50

resources or equivalently money at the

7:52

problem unfortunately there is a catch

7:54

here there's sort of a a seiling on what

7:57

you can do why why is vertical scaling

8:00

not necessarily a full solution well you

8:04

can only upgrade one machine so much

8:06

after a while you can't upgrade yeah

8:08

exactly there's some real world

8:09

constraints here where you can only buy

8:11

a machine that's you know maybe 3

8:13

gigahertz these days and maybe only has

8:16

a few a handful of maybe a couple dozen

8:18

CPUs or cores but at some point you're

8:22

either going to exhaust your own

8:23

financial resources or just the

8:25

state-of-the-art in technology because

8:27

just the world hasn't made a machine

8:29

that has as many resources as you need

8:31

so you need to get a little smarter but

8:33

at least within here you have some

8:34

discretion so in terms of CPUs these

8:37

days most servers have at least two CPUs

8:41

sometimes three or four or more and in

8:43

turn each of those CPUs typically has

8:45

multiple cores in fact most of the

8:46

laptops you guys have here these days

8:48

are generally at least dual core

8:51

sometimes even quad core which means

8:53

that you effectively have the equivalent

8:54

of four CPUs or four brains inside of

8:57

your computer even though they're all

8:58

inside of the same chip essentially what

9:01

does that mean concretely it means if

9:03

you have a quad core machine you can

9:05

your computer can literally do four

9:07

things at once whereas in yesterday year

9:09

when you had single core single CPU

9:11

machines they could only do one thing at

9:13

a time and even though we humans seem to

9:16

think that you're simultaneously

9:18

printing something you're pulling up a

9:19

Google map you're getting email and all

9:21

this stuff seems to be happening

9:22

simultaneously the reality is the

9:24

operating system is scheduling each of

9:26

those programs to get just a Split

9:28

Second of CPU time before giving another

9:31

program then another program a split

9:33

second of CPU time and we humans are

9:35

just so slow relative to today's uh

9:37

processors that we don't even notice

9:39

that things are actually happening

9:40

serially as opposed to uh in parallel

9:43

but when you actually have quad core

9:45

especially in a server that means

9:47

whereas in yesterday year with a single

9:49

core machine you could handle one web

9:51

request at a time now for instance you

9:53

could handle at least four at a time

9:55

truly in parallel and even then a server

9:58

will typically spawn what are called

9:59

multiple processes or multiple threads

10:01

so in reality you can at least give the

10:04

impression that you're handling many

10:06

more than even four requests per second

10:08

so in short machines these days have

10:10

gotten more and more and more CPUs as

10:13

well as more cores and yet the funny

10:15

thing here is that we humans also aren't

10:17

very good at figuring out what to do

10:19

with all of this available Hardware

10:21

right most of you even if you have a

10:22

dual core machine you don't really need

10:24

a dual core machine to check your mail

10:26

or to like write an essay for school

10:28

right you were able to do that 5 10

10:29

years ago with far fewer computational

10:31

resources now In fairness there's bloat

10:34

and software and Mac OS and windows and

10:36

office are just getting bigger and

10:37

bigger so we're using those resources

10:39

but one of the really nice results of

10:43

this trend toward more and more

10:44

computational resources is that the

10:46

world has been able all the more easily

10:48

to start chopping up bigger servers into

10:51

smaller vpss and indeed that's how

10:53

Amazon and other Cloud providers so to

10:55

speak uh are able to provide people with

10:57

the self-service capability ility as

10:59

we'll discuss a bit later so within

11:01

these things there are few things you

11:03

have discretion over uh if you've ever

11:05

built a computer you might be familiar

11:07

with uh parallel ATA or IDE or SATA or

11:12

SAS anyone Axel what are these refer to

11:15

yeah SATA has to do with hard drives

11:17

okay good so SATA has to do with hard

11:19

drives in fact all three of those have

11:20

to do with hard drives years ago

11:22

parallel ATA or IDE hard drives were

11:25

very much in Vogue they you might still

11:27

have them in older computers these days

11:29

desktop computers uh pretty much but you

11:31

wouldn't buy a new uh parallel ATA Drive

11:34

these days instead you'd most likely get

11:35

a SATA drive whether 3.5 in for a

11:38

desktop or 2 and 1 12 in for a laptop

11:41

and if you have servers or you have lots

11:44

of money and a fancy desktop computer

11:46

you can go with the SAS Drive um SAS is

11:49

serial attached scuzzy and this really

11:52

just boils down to faster for instance

11:54

whereas parallel ATA and SATA drives

11:56

typically ran at 7200 RPMs per minute uh

12:01

revolutions per minute um SAS drives

12:03

anyone know what they typically spin

12:06

at and for those unfamiliar inside of a

12:09

mechanical hard drive there is a one or

12:11

more metal platters that literally spins

12:13

much like an old school record player

12:16

where the bits are now stored what what

12:19

speed does a SAS Drive spin it's more

12:21

than 7200 RPM Excell is it 15,000 uh

12:25

yeah so 15,000 is where um they would

12:27

typically perform sometimes 10,000 but

12:29

15,000 so just twice as fast so that

12:31

alone gives you a bit of a speed bump of

12:33

course it comes at a price literally

12:35

more money but that's one way of

12:37

speeding things up so in oftentimes what

12:39

people will do is for a given website

12:42

that they're creating if it has a

12:43

database databases tend to write to disk

12:46

quite a bit right every Facebook update

12:48

requires writing to disk and then

12:50

reading back out some number of times so

12:52

really where you might be touching disc

12:54

a whole lot people can throw things like

12:56

SAS drives um in their database so that

12:59

their data can be read or written even

13:01

more quickly and what's even faster than

13:04

um mechanical drives these days Axel

13:07

solid state drives yeah solid state

13:09

drives ssds which have no moving parts

13:11

and as a result electrically perform

13:13

much better than mechanical drives but

13:15

those two cost more money and they tend

13:17

to be smaller in size so whereas you can

13:19

buy like a 4 terabyte uh SATA drive

13:23

these days 3 and 1/2 in for your desktop

13:25

you can buy maximally a 768 G

13:29

SSD these days for a lot more money

13:32

typically all right

13:35

so let's skip uh let's skip raid for now

13:41

so horizontal scaling so this is in

13:43

contrast with what we just discussed

13:44

throwing money and throwing more of

13:46

everything at a problem horizontal

13:48

scaling is sort of accepting the fact

13:50

that there's going to be the ceiling

13:51

eventually so why don't we instead

13:53

architect our system in such a way that

13:55

we're not going to hit that rather we

13:57

can kind of stay below loow it by even

14:00

using not state-of-the-art hardware and

14:01

the F most expensive stuff we can buy

14:03

but cheaper Hardware servers that might

14:05

be a few years old or at least are not

14:08

uh the topof the line so that they'll be

14:10

less expensive so rather than get few or

14:13

one really good machine why don't we get

14:15

a bunch of slower or at least cheaper

14:18

machines instead plural number of

14:20

machines so this is just a picture of a

14:22

data center which is just meant to

14:23

conure up the idea of scaling

14:25

horizontally and actually using multiple

14:27

servers to build out your topology but

14:30

what does this actually mean well if you

14:34

have a whole bunch of servers now

14:36

instead of just one how what's the

14:39

relationship now with lecture zero where

14:41

we talked about HTTP and DNS right the

14:45

world was very simple a few weeks ago

14:47

when you had a server and it had an IP

14:49

address and that IP address might have a

14:51

domain name or host name associated with

14:53

it and we told that story of what

14:54

happens when you type in something.com

14:56

enter on your laptop and you get back

14:58

the pages on that single server but now

15:00

we have a problem if we have a whole

15:02

Isles worth of web servers Axel well

15:05

you're going to have to have a

15:09

way

15:13

okayest okay good so now if we get an

15:15

inbound HTTP request we somehow want to

15:18

distribute that request over all of the

15:21

various web servers that we might have

15:23

whether it's two web servers or 200 the

15:25

problem really is still the same if it's

15:27

more than one we have to somehow figure

15:29

that out so let me put up a fairly

15:32

generic picture here let me flip fast

15:34

those to this guy here so if we have a

15:37

whole bunch of servers on the bottom

15:39

here server one two dot dot dot and on

15:41

the top we have some number of clients

15:43

just random people on the internet we

15:45

need to interpose now some kind of black

15:47

box that's generally called a load

15:49

balancer depicted here as a rectangle so

15:52

that the traffic coming from people on

15:54

the Internet is somehow distributed or

15:56

balanced across our various backend

15:59

servers so to speak so it might still be

16:02

the case that server one and two and so

16:04

forth have unique IP addresses but now

16:08

when a user types in something.com and

16:10

hit hits

16:12

enter what IP address should we

16:15

return how do we go about achieving the

16:18

equivalent of this man in the middle who

16:20

can somehow balance load across all in

16:23

servers well let

16:26

the return the IP addresses the load

16:29

balancer send the request to the load

16:31

balancer and then let the load balancer

16:34

handle which computer send it to okay

16:36

good so instead of in DNS returning the

16:39

IP address of server one or server 2 or

16:41

server dot dot dot you could instead

16:43

return the equivalent of the IP address

16:44

of this black box the load balancer and

16:47

then let the load balancer figure out

16:49

how to actually route data to those

16:52

backend servers so that's actually

16:53

pretty clean so now if the load balancer

16:55

has a public IP address the backend

16:57

server is now technically you don't even

16:59

need public IP addresses they can

17:00

instead have private addresses and what

17:03

was the key distinction between public

17:04

and private IPS back in lecture

17:09

zero any anyone over here yeah Le the

17:13

rest of the world see private exactly so

17:17

the rest of the World by definition of

17:18

private can't see private IP addresses

17:21

then so that seems to have some nice uh

17:24

privacy properties and that if no one

17:25

else can see them they can't address

17:27

them so those servers just by nature of

17:29

this privacy can't be contacted at least

17:32

directly by random adversaries bad guys

17:34

on the internet so that's a plus

17:36

moreover the world has been running out

17:38

of uh version 4 IP addresses the 32-bit

17:41

IP address has come into scarcity for

17:43

some time now so it's just hard or

17:46

sometimes expensive to get enough IP

17:48

addresses to handle the various servers

17:50

that you might buy so this alleviates

17:51

that pressure now we need one IP and not

17:54

multiple for our servers because we can

17:56

give these backend servers like a a

17:58

number like 192.168 which most of you

18:00

have in your home routers probably or

18:02

10. something or 17216 something all of

18:05

those to Mark the start of a private IP

18:08

address so that works all right so the

18:10

load balancer has its own IP address now

18:12

it gets a request from some client on

18:14

the internet how using jargon from

18:17

lecture zero onward can the load

18:19

balancer decide or get that data to one

18:23

of the backend servers how could we go

18:26

about implementing that actually

18:28

well you would probably first want to

18:30

figure out which server to send it to so

18:32

you want to check um if somebody has

18:35

available CPU cycles that they're not

18:38

using okay so and once you see that

18:40

there's one server with enough CPU

18:42

Cycles to handle that request s a local

18:44

request the same request but locally

18:46

inside your server Network okay to that

18:49

machine um get back whatever it is that

18:52

the client requested and then the load

18:54

balance s excellent so this request

18:57

arrives then at the load balance

18:58

balancer the load balancer decides to

19:00

whom he wants to send this packet server

19:02

one or two or dot dot dot and you can

19:04

make that decision based on any number

19:06

of factor so Axel propose doing it based

19:08

on load like who is the busiest versus

19:10

the least busy odds are I should send my

19:13

request to the least busy server in the

19:15

interest of uh optimizing performance

19:18

all around so let's assume that there's

19:20

some way as Demar demarcated by those

19:22

black arrows of like talking to those

19:24

backend servers and saying hey how busy

19:25

are you let me know so now the load

19:27

balancer figures out it wants to send

19:29

this particular request to server one so

19:31

it sends that request to server one

19:33

using similar mechanisms tcpip much like

19:36

the packet how it traveled to the load

19:38

balancer in the first place the server

19:39

then gets the packet does its thing and

19:42

says oh they want some HTML file here it

19:44

is the response goes to the load

19:46

balancer the load balancer then responds

19:48

to the client and voila so that works

19:51

what are some alternatives to load

19:53

balancing based on the

19:56

actual load on these server so load in

20:00

general refers to how busy a server is

20:02

so what's an even simpler approach than

20:04

that because that frankly that sounds a

20:05

little complex we've not talked at all

20:07

about how one device can query another

20:09

for uh characteristics like how busy are

20:11

you even though it's possible

20:13

Axel first let me point out inite that

20:16

you need to have every file um every

20:18

file the website has on every server so

20:21

if you would instead uh say have one

20:23

server containing all the HTML and one

20:26

running and containing all the P you

20:29

would then see well oh okay bad example

20:32

one example one server with all the

20:34

images and one with all the HTML client

20:36

requests an image it sends it to the

20:38

image server okay and if it's an HTML

20:41

request to the HTML server okay good so

20:43

the implication of the previous story

20:44

that Axel told is that under this model

20:46

server one two and so forth all need to

20:48

be identical have the same content which

20:51

is nice and that then it doesn't matter

20:53

to whom you send the request the

20:54

downside is now you're using n times

20:57

this much dis space as you might

20:59

otherwise need to but that's perhaps the

21:01

price you pay for having this redundancy

21:03

or to having this uh horizontal

21:05

scalability or instead you could have

21:07

dedicated servers these are for HTML

21:09

these are for gifs these are for movie

21:11

files and the like and you could do that

21:13

just by having different URLs different

21:15

host names this is for instance images.

21:18

something.com this is videos.

21:20

something.com and then the load balancer

21:22

could take into account the host HTTP

21:25

header to decide which direction it

21:27

should go in so could work for us all

21:29

right so what's an even simpler fistic

21:32

than asking a backend server how busy

21:34

are you right now like if you have no

21:36

idea how to do that how instead could we

21:38

balance load across an arbitrary number

21:40

of

21:42

servers think again back to lecture zero

21:45

we can do all of this with only lecture

21:48

zero under our

21:53

belt so let's quickly tell the story I

21:55

type in something.com into a browser I

21:57

hit enter what

22:01

happens Jack we create a packet to send

22:04

okay packet to send to whom do we send

22:06

it we send it to uh some place that will

22:09

determine the IP address where we're

22:11

sending it okay good something that will

22:12

determine the IP address of where we're

22:14

sending it to what's that thing called

22:16

uh Isaac what's that called router uh

22:19

not router routers get involved

22:22

but DNS the DNS server domain name

22:25

system server so that server in the

22:26

world a whole bunch of of them that

22:29

whose purpose in life is to translate

22:30

host names to IPS and vice versa so I'm

22:34

going to pause the story there that

22:36

seems to be an opportunity now for us to

22:39

return something yeah could you do some

22:43

DNS tricks and return different IP

22:46

addresses based on what the user

22:48

requested good so this black box this

22:50

load balance or maybe it's just a fancy

22:52

DNS setup whereby instead of returning

22:54

the IP address of the load balancer

22:56

itself maybe in instead the DNS server

22:59

just Returns the IP address of server

23:01

one the first time someone asks for

23:03

something.com and the next time someone

23:05

requests something.com it Returns the IP

23:07

address of server two followed by server

23:09

three followed by dot dot dot and then

23:11

wrapping around eventually to server one

23:13

again so this is actually generally

23:14

called round robin and you can do this

23:17

fairly easily this is just a snippet of

23:19

a popular DNS server called bind berley

23:22

internet name uh name demon I believe is

23:26

the D and this just suggests that if you

23:28

want to have multiple IP addresses for a

23:30

host name called dubdub duub you mention

23:33

a which is denotes a record in just

23:35

refers to an inp pointer here but a is

23:38

the same as in lecture zero and then you

23:40

just enumerate the IP address one after

23:42

the other and by default this particular

23:45

uh DNS server very popular one

23:48

bind will return a different IP address

23:52

for each request so that's nice it's

23:54

simple again uses only some knowledge

23:56

from lecture zero even though granted

23:58

you have to know how to configure the

23:59

DNS server but you don't need any fancy

24:01

bidirectional communication with the

24:03

backend servers in this model so that's

24:04

nice but there's a price we pay for this

24:08

Simplicity if we only do round robin

24:11

where again we just spit out a different

24:13

IP address each time and let me make

24:15

this more concrete just so this isn't

24:17

quite as abstract let me open up a

24:19

terminal program here and do NS lookup

24:22

for name server lookup of google.com

24:25

this is exactly what Google does at

24:27

least part their their load balancing

24:30

solution is more sophisticated than this

24:32

list suggests but indeed Google's DNS

24:35

server returns multiple IP addresses

24:36

each time so

24:39

if this is so simple to implement what's

24:43

the

24:45

catch uh Axel well it's not a very smart

24:48

solution

24:49

because just there could be the case

24:52

could be that one server gets all the

24:55

really tough and hard requests that a

24:57

lot processing power and the other ones

24:59

just get the Fe the HTML files and

25:01

there's no way to know that good so just

25:03

by bad luck one of the servers could

25:05

just get a really a real power user

25:08

someone who's really doing something

25:10

computationally difficult like I don't

25:12

know uh what's a good examp sending lots

25:16

of mail whereas someone else is just

25:17

kind of logging in and poking around at

25:19

a much slower rate and you we could come

25:21

up with even more sophisticated examples

25:22

than that but over time server one might

25:25

just happen to get more heavyweight

25:28

users than other servers so what's the

25:30

implication well round robin is still

25:33

going to keep sending more and more

25:35

users to that server one nth of the time

25:38

just by nature of round robin so that's

25:41

not so good um what

25:44

else causes

25:47

problems here or what else breaks

25:53

potentially so back to the lecture zero

25:56

story I type something.com I hit enter

25:58

my browser sends a request to the DNS

26:00

server or my operating system sends a

26:02

request to the DNS server gets the IP

26:04

address and in this model it's the IP

26:06

address of one of these servers then I

26:09

send my packet as Jack proposed to that

26:11

particular server get back a response

26:14

stories ends but then a few seconds

26:16

later I visit another link on

26:18

something.com and hit enter which part

26:20

of the story now

26:22

changes Jack is it now going to send to

26:25

the same server request do it send to a

26:28

new server good

26:31

question where it's coming from so what

26:34

how does the story change and that'll

26:36

give us the answer here Axel well it has

26:38

to send it to

26:40

Aver oh ideally yes so if you want a

26:43

truly uniform distribution across all n

26:45

servers then the DNS server has to

26:47

return another response and I'd argue

26:48

the DNS server will return a different

26:51

response the next time it is queried but

26:54

oh oh it's not queried why because it's

26:58

saved or no but

27:01

it's IP address

27:03

isor Open Session it's it's really

27:06

useless to query the DNS server for the

27:08

same thing over and over again good so

27:09

recall these caches back in lecture Z we

27:12

talked about the implications of the

27:14

good parts of caching whereby as ael's

27:16

proposing there's no reason for Chrome

27:18

or IE to send the same DNS request every

27:21

single time you click a link on

27:23

something.com that would just be a waste

27:24

of time um you're going to lose some

27:26

number of milliseconds every time time

27:27

that happens or worse yet a second or

27:29

two so instead your operating system

27:31

typically caches these responses your

27:33

browser typically caches these responses

27:36

as well and so you just don't need to do

27:38

those lookups so if you do happen to be

27:40

that power user who's doing a heck of a

27:42

lot of work of whatever sort on server

27:45

one the next guy is going to be sent to

27:47

server two not you with your subsequent

27:50

requests so caching too can contribute

27:53

to a disproportionate amount of load on

27:55

certain servers largely and due to to

27:57

bad luck indeed in DNS we didn't spend

28:00

much time on this particular detail but

28:02

there's typically expiration times ttls

28:04

time to live values associated with an

28:07

answer from a DNS server and that's

28:09

typically an hour or five minutes or a

28:12

day it totally depends on who controls

28:14

the DNS server what that value is but

28:16

that suggests too that if you are this

28:18

power user on server one it might be a

28:20

few minutes or hours or even days until

28:23

you get assigned to some other server

28:26

simply because you're TTL has expired by

28:29

then so it's nice and simple we can do

28:31

it with a simple configuration change

28:32

but it doesn't necessarily solve all of

28:34

our problems so in fact the approach

28:36

Axel proposed first is actually pretty

28:39

good whereby you don't use dns-based

28:41

round robin rather a more sophisticated

28:44

approach would be to let the load

28:45

balancer decide to whom to send you in

28:48

the back end and the load balancer can

28:49

make that decision using any number of

28:51

her istics it could even use round robin

28:54

or Randomness because at that point you

28:56

don't have to worry about caching issues

28:58

because the DNS server has only returned

29:00

one IP so but that still leads you to

29:02

the risk that you'll be putting too much

29:04

load on some server so we could take for

29:06

instance server load into account at

29:08

that point but there is something else

29:10

that breaks if we fast forward

29:11

mid-semester to when we started talking

29:13

about cookies and

29:16

HTTP and sessions in

29:19

PHP to spark discussion I propose that

29:23

sessions have just broken in PHP if our

29:26

backend servers are PHP based

29:30

websites and they are using the session

29:33

super Global load balancing seems to

29:36

break this model why Jack because now

29:39

the different different servers have

29:41

different people sessions so Al one

29:43

might have my session if I then am

29:46

redirected from server one to server two

29:49

server two might not have my session

29:51

exactly so sessions recall tend to be

29:54

specific to the given machine we saw

29:56

examples involving sltm which is a

29:58

temporary directory on a Linux system

30:00

where sessions are typically saved as uh

30:02

text files serialized text files so that

30:05

means though that your session might be

30:06

sitting on the hard drive of server one

30:08

and yet if by a random chance you are

30:10

sent via round robin into server two or

30:12

server three instead of server one in

30:15

the worst case you're going to see the

30:16

same website but you're going to be told

30:18

to log in again for instance because

30:20

that Server doesn't know that you've

30:21

logged in more okay fine you kind of

30:23

bite your tongue and you type in your

30:25

username and password again and hit

30:26

enter and suppose you're a really good

30:29

sport and you do this for all end

30:30

servers you have no idea why

30:32

something.com keeps prompting you to log

30:34

in but eventually you will have a

30:35

session cookie on all of those servers

30:37

the catch then though is that if

30:39

something.com is an e-commerce site and

30:41

you're adding things to your shopping

30:42

cart now you literally have put a book

30:44

in your cart over here a different book

30:46

in this card a different book in this

30:48

card and when you check out you can't

30:49

check out the Aggregates so this is a

30:52

very non-trivial problem now Axel um but

30:56

this wouldn't happen if you

30:57

if you had dedicated machines

30:59

Distributing dedicated files one machine

31:01

running PHP and then one maching all the

31:04

images very true so if we have

31:06

horizontally scaled in the sense that we

31:08

factored out disparate services this is

31:10

our PHP server this is our uh GIF server

31:13

this is our video server then indeed

31:15

this problem would not arise because

31:16

presumably all the the PHP traffic would

31:19

get routed to the PHP server but an

31:21

obvious push back to that solution is

31:24

what you're Isaac well if one of them

31:27

crashes you lose all images okay good so

31:31

there's no redundancy which is not good

31:33

for uptime if anything breaks Axel and

31:35

also well at some point in time if you

31:39

get popular enough that one PHP server

31:41

is not going to be able to handle

31:42

everything

31:43

good then the story is the same as soon

31:45

as you get popular you have too much

31:47

load for a single PHP server then we

31:49

have to solve this problem anyway so how

31:52

do we go about solving this problem this

31:54

seems to be a real pain this one

31:58

and to be clear the problem now is that

31:59

in as much as sessions are typically

32:02

implemented per server in the form of

32:04

like a text file like we saw in sltm

32:08

then you can't really use round robin

32:10

you can't really use loow true load

32:13

balancing taking into account each

32:14

server's load because you need to make

32:16

sure that Alice if she's initially sent

32:18

to server one subsequently gets sent to

32:20

server one again and again and again for

32:23

at least you know an hour or a day or

32:25

some amount of time so that her is

32:27

useful

32:34

Jack started there and excellent yes so

32:37

absolutely we could just continue this

32:39

idea of factorization and factor out not

32:42

the various types of files but a service

32:45

like session States so if we instead had

32:47

a file server you know like a big

32:49

external hard drive so to speak that is

32:52

connected to all of the servers one and

32:54

two and three so that anytime they store

32:57

session data they store it there instead

33:00

of on their own hard drive then this way

33:02

we could share state so indeed that

33:04

could be a solution here

33:06

Axel I I don't know if a load balancer

33:09

has that function but maybe the instead

33:11

of having an extra server that all the

33:13

other servers need query load balancer

33:16

because all traffic goes through that

33:17

anyhow but if the load balancer session

33:20

okay so that's not bad at all so we

33:22

already have a man in the middle here

33:23

it's a black box but there's no reason

33:25

it couldn't be a server with hard dis

33:27

so want to put the sessions on the load

33:29

balancer that could absolutely work so

33:31

let me be difficult then and whether we

33:33

put the sessions in the load balancer or

33:35

whatever that it's no longer a load

33:36

balancer then it's obviously doing more

33:38

it's more of a a server that happens to

33:40

be balancing load and storing sessions

33:42

whether we put sessions there in that

33:44

black box or elsewhere in a new box on

33:46

the screen we seem to have introduced uh

33:51

weakness now in our Network topology

33:54

because what if that machine breaks

33:57

it would seem to be the case that even

33:59

though we have n servers which in theory

34:01

those guys are never all going to die at

34:03

once assuming that it's not the power

34:05

electricity or something stupid like

34:06

that that's somehow related to all of

34:08

them but odds are they're not all just

34:10

going to up and die simultaneously so we

34:12

have really good redundancy in our

34:14

server model right now but as soon as we

34:15

introduce just a database or file server

34:18

for our sessions if that guy dies then

34:21

what was the point of spending all this

34:23

money on all these backend servers our

34:25

whole site goes down because we have no

34:27

ability to remember that people are

34:28

logged in if we can't remember they're

34:29

logged in no one can buy anything so how

34:31

do we fix that problem so we've solved

34:33

one problem but if you think of that

34:35

sort of old uh visual where you have

34:38

like a garden hose with lots of leaks in

34:39

it and you plug one of them with one

34:41

hand all of a sudden a new leak Springs

34:43

up elsewhere that's kind of what's

34:44

happened here we've solved the problem

34:46

of shared state but now we've sacrificed

34:50

some uh some robustness some redundancy

34:54

how do we now fix the

34:55

ladder

35:03

Exel probably not

35:14

the okay good so we could just use a

35:17

sort of different approach to storing

35:19

our data and rather than just store it

35:21

on the hard disk as usual we could use

35:23

something called raid so actually this

35:24

is a good way to tie in the thing we

35:26

skipped over a moment ago let me just

35:29

pull up something to write on

35:31

here

35:35

uh

35:37

so redundant array of independent discs

35:40

is a technology more succinctly known as

35:43

raid raid can actually be used in

35:44

desktop computers these days um even

35:47

though it's not all that common some

35:48

companies like Dell and apple make it

35:51

relatively easy to use Raid on your

35:53

system and what does this mean well raid

35:55

can come in a few different forms

35:56

there's something called raid zero

35:58

there's something called raid 1 there's

36:00

something called raid five there's

36:02

something called raid six there's

36:03

something called RAID 10 and there's

36:05

even more but these are some of the

36:07

simplest ones to talk about so all of

36:09

these techn all of these variants of

36:12

raid assume that you have multiple hard

36:14

drives in your computer for different

36:16

purposes potentially so in the world of

36:18

raid one of raid zero you typically have

36:21

uh two hard drives that are of identical

36:23

size terabyte 2 terabytes 512 me G

36:27

whatever it is two identical hard drives

36:30

and you do what's called stripe data

36:32

across them whereby every time the

36:35

operating system wants to save a file

36:36

especially big files it will first write

36:39

to this drive a bit then to this one

36:41

then to this one then to this one the

36:43

motivation being these hard drives are

36:44

typically large and mechanical with

36:46

spinning platters like we discussed

36:48

earlier and so it might take this guy a

36:50

little while to write out some number of

36:53

bits now it's going to be split second

36:54

in reality but that's a split second we

36:56

don't really have when we're trying to

36:57

service lots of users so striping allows

37:00

me to write some data here then here

37:02

then here then here then here then here

37:04

effectively doubling the speed at which

37:06

I can write files especially large ones

37:07

to diss so raid zero is nice for

37:10

performance however raid one gives you a

37:12

very different property with raid one

37:14

you still have two hard drives but you

37:16

mirror data so to speak across them so

37:19

that anytime you write out a file you

37:21

store it both places simultaneously

37:24

there's a bit of performance overhead to

37:25

writing it in two places albe it in

37:27

parallel but the upside now is that

37:30

either of these drives can die and your

37:32

data is still perfectly intact and it's

37:34

actually an amazing technology because

37:37

if even if you just have this in your

37:38

desktop computer you have two drives one

37:40

of them dies just because of bad luck it

37:42

was there was a defect or it's multiple

37:44

years old and it just upped and died so

37:46

long as the other one is still working

37:47

the theory behind raid is that you can

37:49

then run to the store buy another hard

37:51

drive that's at the same size or bigger

37:54

plug it into your computer boot back up

37:57

and most typically automatically The

38:00

Raid array will rebuild itself whereby

38:03

all of the data that's on the remaining

38:05

drive will copy itself automatically

38:07

over to the new one and after a few

38:08

minutes or hours you're back to a safer

38:11

place whereby now even the other Drive

38:13

can up and die sometimes you have to run

38:15

a command or choose a menu option to

38:16

induce that but typically it's automatic

38:18

you can do it even sometimes in some

38:20

machines while the computer's still on

38:22

so you don't even have to suffer any

38:23

downtime so that's great RAID 10 is a

38:26

essentially the combination of those two

38:27

you typically use four drives and you

38:29

have both striping and redundancy so you

38:32

sort of get the best of both worlds but

38:33

costs you twice as much because you need

38:35

twice as many hard diss raid five and

38:37

raid six are kind of nice middle grounds

38:40

with raid one uh or nice variants of

38:42

raid one whereby raid one's kind of

38:43

pricey right rather than buy two one

38:46

hard drive I literally have to spend

38:48

twice as much and get two hard drives

38:50

raid five is a little more versatile

38:53

whereby I typically have say three

38:55

drives four drives five drives but only

38:58

one of them is used for redundancy so if

39:00

I get five 1 tbte drives I have four

39:04

terabytes of usable space so I'm only

39:07

sacrificing oneth in that case of my

39:10

available disc capacity whereas in raid

39:12

one you're sacrificing one one over one

39:14

half so 50% of it so raid five you just

39:17

get better economy of scale whereby you

39:19

can grow bigger and you still have some

39:22

redundancy so in raid five if you have

39:24

three or four or five hard drives in in

39:26

the array one of them can die any of

39:28

them you run to the store put in a new

39:30

one and you haven't lost any data raid

39:33

six is even better what does raid six do

39:36

do you think Axel I think two drives can

39:38

die exactly in raid six any two drives

39:41

can die you still won't have lost any

39:43

data and so long as you run to the store

39:44

fast enough and put in one or both

39:46

drives again you'll be good to go of

39:48

course the price you pay with rate six

39:50

is literally another hard drive but at

39:51

least now you can maybe sleep a bit

39:53

better at night knowing that man two of

39:55

my hard drives has to die before I have

39:57

to really worry about this so these are

40:00

really nice Technologies and so as Axel

40:02

proposes here the upside of using

40:04

something like that in whatever uh file

40:07

server we're storing our shared sessions

40:09

is we can at least decrease the

40:10

probability of downtime at least related

40:12

to hard diss unfortunately it still has

40:16

a power cord that someone could trip

40:17

over or the power supply could die it

40:19

still has Ram that could go on the fritz

40:21

a motherboard that could die any number

40:23

of things could still happen but at

40:25

least we can throw redundant inside of

40:27

the confines of a single server and this

40:29

can definitely help with our uptime and

40:31

with our robustness and indeed with

40:33

actual servers that you would buy for a

40:35

data center not so much the home it's

40:38

very common for computers to have not

40:40

only multiple hard drives and lots of uh

40:43

multiple Banks of RAM and they would

40:45

often have multiple power supplies as

40:48

well and it's actually a really cool

40:49

technology there too if one of your

40:50

power supplies dies you can literally

40:52

pull it out the machine keeps running

40:54

you put in a new one and then it spreads

40:56

the amperage across two power supplies

40:59

once both are back up and running all

41:01

very hot swappable amazing technology

41:03

these days and as an aside if you still

41:04

own a desktop computer there is no

41:06

reason you shouldn't use Raid these days

41:08

it is just very good practice since it

41:10

will uh allow you to avoid downtime and

41:13

data loss with higher

41:15

probability okay but someone tripped

41:18

over the power cord someone tripped over

41:20

both power cords in the case of

41:22

redundant power suppli so axle solution

41:24

and even mine with redundant power

41:25

supply hasn't solved the problem of

41:28

shared storage becoming all of a sudden

41:31

a single point of failure so what else

41:33

could we do to still get the property of

41:37

shared state so it doesn't matter what

41:39

backend server I end up on but I instead

41:42

get I still get the ability to suffer

41:46

some downtime well shared storage is can

41:48

to come in a bunch of different ways so

41:50

we talked really about things as a file

41:51

server but this can be incarnated with

41:53

very specific Technologies and just to

41:55

Rattle them off even though we won't

41:56

talk about them in much technical detail

41:58

fiber channel FC is a very fast very

42:01

expensive technology that you can use in

42:04

offices and data centers not so much the

42:06

home to provide very fast shared storage

42:08

across servers so that's just one type

42:10

of file server if you will um I scuzzy

42:13

is another technology that uses uh IP

42:16

Internet Protocol and uses ethernet

42:18

cables to exchange data with servers so

42:20

that's a nice somewhat cheaper way of

42:22

exchange of having a shared file server

42:25

that um uh that can be used by multiple

42:29

actually in the case of iuz you

42:30

typically use it with single servers um

42:33

so let me retract that that is not a

42:34

solution to our current cookie problem

42:36

um but what about MySQL right we use

42:38

that for a couple weeks MySQL seems to

42:42

be a nice candidate because it's already

42:43

a separate server potentially could not

42:46

the backend servers just write their

42:48

session objects to a database they

42:51

definitely could so just because you're

42:53

storing things in a just because we

42:56

usually store things like user data and

42:58

user generated data in a database

43:00

doesn't mean we can't store metadata

43:01

like our cookie information as well or

43:04

that too comes from users though NFS

43:06

Network file system this is just a

43:07

protocol that you can use to implement

43:10

the idea that Axel proposed of a shared

43:12

file system it just means you've got one

43:14

server and you're exposing your hard

43:16

disk to multiple other computers but

43:18

again we haven't really solved the

43:20

problem of share of downtime so what's

43:24

the most obvious way of mitigating the

43:27

risk that your single file server will

43:29

go

43:31

down Axel keep the cop of session loc

43:35

good right if it's not if you don't have

43:38

um if you're worried about the one file

43:40

server going down well the obvious

43:41

solution even though money um and some

43:44

technical complexity will just get two

43:46

now somehow you have to figure out how

43:47

to sync the two so that one has a copy

43:51

of the other's data and vice versa so

43:53

let's actually come back to that issue

43:55

it's generally known as rep application

43:56

but it is something we can potentially

43:59

achieve but before we segue to um

44:05

distribution of things let's finish out

44:08

this load balancer question so how do

44:10

you go about implementing this black box

44:12

well these days you actually have a

44:13

bunch of options um in software you can

44:16

do things relatively easily with a

44:17

browser pointing and clicking using

44:20

things like Amazon's elastic load

44:21

balancer a scenario for which we'll talk

44:23

about a bit later ha proxy High

44:26

availability proxy is free open source

44:28

software that you can run on a server

44:30

that can do load balancing as well using

44:31

any either of the heris stics we

44:33

discussed earlier round robin or

44:35

actually taking load into account

44:36

somehow um Linux virtual server LVS is

44:39

another free software a piece of

44:41

software you can use and then in the

44:42

world of Hardware people have made big

44:44

business out of load balancers Barracuda

44:47

Cisco Citrix F5 are some of the most

44:49

popular vendors here um most of whom are

44:51

atrociously overpriced for what they do

44:54

so case in point like Citrix is a

44:57

popular company that sells load

44:58

balancers take a guess as to what a load

45:01

balancer might cost you these days it's

45:02

a highly variable range but there's

45:04

different models but take a guess how

45:07

much did that black bux cost Isaac in

45:09

the thousands definitely in the

45:11

thousands

45:14

indeed in fact we have a small one so to

45:17

speak on a small one relatively speaking

45:19

on campus that was

45:22

$220,000 and guess what that one's cheap

45:27

so you can literally spend on these

45:28

kinds of things granted not this is this

45:30

is not what the costs that await you

45:31

right after the semester ends today um

45:34

but $100,000 for a load balancer or even

45:37

generally a pair of load balancers so

45:39

that either of them can die and the

45:41

other one can stay alive so in the world

45:43

of Enterprise Hardware these ideas we're

45:45

talking about are ridiculously priced

45:47

typically because of support contracts

45:49

and the like so just realize software is

45:51

number one on the list because there are

45:53

other ways to achieve this much more

45:55

inexpensive indeed for years um one of

45:57

the courses I teach we used ha proxy to

46:00

balance load because it was so

46:02

relatively easy to set up and 100% free

46:04

so realize these same ideas can be both

46:06

bought and set up uh on your own quite

46:10

readily these days all right um let's

46:15

pause here and when we come back we'll

46:16

take a look at some issues of like

46:18

caching of replication in databases and

46:20

also how we can speed up PHP a bit let's

46:22

take our five minute break

46:24

here

46:27

all right we are back and I almost

46:29

forgot we have one other solution to

46:31

this problem of the need for sticky

46:33

sessions sticky sessions meaning that

46:36

when you visit a website multiple times

46:39

your session is somehow preserved even

46:42

if there are multiple backend servers so

46:45

shared storage was the idea we really

46:47

vetted quite a bit and we didn't quite

46:49

get to a perfect solution since even

46:52

though we factored out the storage and

46:55

and put everyone's cookies or session

46:57

objects on the same server we feels like

46:59

we need some redundancy but we'll come

47:01

back to that in the context of MySQL in

47:03

just a bit but what about cookies I

47:05

propose that cookies themselves could

47:09

offer a solution to the problem of

47:12

sticky sessions and again Sticky session

47:14

means even if you visit a website

47:17

multiple times you're still going to end

47:19

up with the same session object or more

47:21

specifically you're still going to end

47:22

up on the same backend server

47:33

Axel which server you want to go to in a

47:36

cie

47:38

okay store everything in cookies but

47:40

that's that's store okay yeah so storing

47:43

everything in cookie is probably bad

47:45

because one then it's really starting to

47:47

violate privacy because rather than

47:48

store a big key you're going to store

47:50

like the isbns of all of the books in

47:52

your shopping cart and that might be

47:53

fine but feels like your roommates and

47:55

family members don't don't need to know

47:56

what is in your cookies moreover cookies

47:58

typically have a finite size of a few

48:01

kilobytes so there's definitely going to

48:02

be circumstances in which you just can't

48:03

fit everything you want to in the cookie

48:05

so you know an interesting idea but

48:07

probably not the best so you could store

48:09

the ID of the server in a cookie so that

48:12

the user the second and third and fourth

48:14

times they visit your website as by

48:16

following links or coming back some

48:19

other time they are going to present the

48:22

equivalent of a hand stamp saying hey I

48:24

was on backend server one send me there

48:27

again so that's a pretty nice idea there

48:29

is one at least one downside here what

48:32

do you like what do you not like

48:34

potentially about this idea of storing

48:35

in a cookie that gets put on the user's

48:38

browser that they subsequently transmit

48:40

back to you the number of or the ID of

48:42

the server to which they should be

48:47

sent maxel well for one expiration

48:50

expiration in what sense well cookie

48:53

expires Okay so eventually cookie is

48:56

going to expire though we saw a couple

48:58

lectures ago we could make it expire in

49:01

10 years if we really wanted to and

49:03

frankly we're never going to avoid that

49:05

even if we had a single server cookies

49:06

could eventually expire so at least

49:08

that's not a new problem so I'm not too

49:09

worried about expiration now because

49:12

that's not a problem new to us simply

49:15

because of load

49:18

balancing does anything not feel right

49:21

about storing the ID of the server in

49:23

the

49:24

cookie

49:32

yeah so if we just put like the backend

49:34

IP so the private IP address in the

49:36

cookie you know what if the IP changes

49:38

what if that uh what if the IP changes

49:40

so that's a little problematic and it's

49:42

also one of these principled things like

49:44

you don't really need to reveal to the

49:46

world what your IP address scheme is

49:48

it's not necessarily something they

49:50

could exploit but it's just the whole

49:52

world doesn't need to know that moreover

49:54

we can implement the same idea by still

49:56

storing a cookie on the user's computer

49:57

but why don't we take the PHP approach

49:59

of let's just store a big random number

50:01

and then have the load balancer remember

50:03

that that big random number belongs to

50:05

server one and this other big random

50:07

number belongs to server two and so

50:10

forth so a little more work on the load

50:11

balancer but in this way then we're

50:13

really not putting any state that might

50:17

change or might be a little privacy

50:19

revealing on the actual user's computer

50:21

moreover we also take away the ability

50:23

for them to spoof that cookie

50:26

just to get access to some other server

50:28

now whether or not they could do

50:29

anything with that uh trick is unclear

50:31

but at least we take the bill away that

50:33

ability Al together so there's no

50:35

surprises all right so cookies indeed

50:37

are something that these black boxes of

50:39

load balancers tend to do whereby you

50:41

can configure them to insert a cookie

50:43

themselves it doesn't just have to be a

50:45

back-end web server that generates

50:46

cookies the load balancer similarly

50:49

could be inserting a cookie with the set

50:51

cookie header that the end user then

50:54

subsequently sends back so that we can

50:56

remember what backend server to send the

50:58

user to now if the user has cookies

51:00

disabled well then this whole system

51:02

breaks down but again so does a lot of

51:04

functionality we've discussed thus far

51:06

this semester but there are sometimes

51:08

some workarounds so a word on PHP PHP

51:12

and interpreted languages in general

51:13

tend to get a bad WAP for performance

51:15

because they tend not to be as high

51:17

performing as a compiled language like

51:18

C++ or C or the like however there are

51:22

some ways to mitigate this there's this

51:23

notion of PHP acceleration

51:26

whereby you can run a PHP program The

51:29

Source Code Through php.exe The

51:32

Interpreter on the system and it turns

51:34

out that PHP does typically compile that

51:37

file in a sense down to something that's

51:39

more efficiently executed much like Java

51:41

compile something down to something

51:42

called bik code but you typically PHP

51:46

throws the results of that compilation

51:49

away whereby it does it again and again

51:52

for every subsequent request however

51:54

with very simple

51:56

uh with relatively straightforward and

51:58

freely available software you can

52:00

install a PHP accelerator here are just

52:03

four possibilities that essentially

52:05

eliminate that discarding of the PHP op

52:09

codes and instead keep them around so

52:11

another words the first time someone

52:12

visits your site the PHP file is going

52:14

to be interpreted and some op codes for

52:16

performance generated but they're not

52:19

going to be thrown away because the next

52:21

time you or someone else visits the site

52:23

that PHP file is not going to have to be

52:24

rep first and reinterpreted the op codes

52:27

are just going to be executed so you get

52:28

the benefit of some added performance

52:30

now the only gotcha is if you ever

52:32

change any of your. PHP files you have

52:35

to uh throw away the cached op codes but

52:40

uh these various tools typically do that

52:42

for you python has a similar mechanism

52:44

where you'll get py files or your source

52:46

code files but pyc files are the

52:49

compiled versions that can be executed

52:51

more quickly so the same idea as at play

52:54

here so this is one of the these things

52:55

that is relatively easy and free to

52:58

enable and gives you all the more

53:00

performance specifically the ability to

53:02

handle all the more requests per second

53:04

in the context of a PHP based website so

53:07

what about caching too caching in

53:09

general is a great thing it solved some

53:10

of our DNS concerns early on but it

53:12

introduced it others because caching can

53:15

be a bad thing if some uh value has

53:17

changed but you have the old one but

53:19

caching can be implemented in the

53:21

context of dynamic websites in a few

53:23

different ways so I propose that through

53:25

HTML through MySQL and through something

53:27

called MCD we can achieve some caching

53:30

benefits here so this is a screenshot of

53:33

one of the most 1990s websites out there

53:36

and this was not even taken in the 1990s

53:38

this was taken a couple years ago and I

53:40

just visited out of curiosity Craigslist

53:41

today still looks the same so what's

53:44

interesting about Craigslist though is

53:46

that it is a dynamic website and that

53:48

you can fill out a form and post a for

53:50

sale ad or a roommate ad or the like and

53:53

the website does actually change but

53:55

it's if we zoom in on this and it's

53:57

going to be a little blurry because of

53:58

the screenshot the URL that's up there

54:01

is actually do HTML even though it's

54:04

barely readable at this resolution which

54:07

is to suggests that Craigslist is

54:09

apparently accepting user input through

54:11

forms for instance whoever uh wrote up

54:14

this uh job advertisement some time ago

54:17

but then Craigslist is spitting it out

54:19

as a HTML file as opposed to storing it

54:24

where or in

54:27

what

54:34

Axel yeah so this is in stark contrast

54:36

to what we've done for project zero

54:39

project one using PHP as the back end

54:41

whereby you store data like this like

54:43

server side in maybe an XML file or more

54:46

realistically in an in a mySQL database

54:48

or similar and then you generate a page

54:50

like this dynamically so why is

54:53

Craigslist doing this apparently

54:56

could just be they're stuck in the 90s

54:58

but there's a compelling reason too AEL

55:01

well if they store the actual HTML file

55:03

then they don't have to regenerate it

55:06

every time it's visited yeah exactly if

55:08

they're storing the HTML file they just

55:09

don't have to regenerate it every time

55:11

it's Revisited so this itself is caching

55:14

it's not caching in any particularly

55:15

fancy way you're just generating the

55:17

HTML and saving it something called like

55:19

something. HTML and storing it on dis

55:22

and the upside of this is that web

55:23

servers like Apache are really really

55:25

really good and fast at just spitting

55:27

out bits just spitting out raw static

55:30

content like a gif a JPEG an HTML file

55:33

right the performance optimizations

55:34

these days generally relate to the

55:36

languages like PHP and Python and Ruby

55:39

where you're trying to fine-tune

55:40

Performance but if all you have to do is

55:42

respond to a tcpi tcpip request with a

55:45

bunch of bites from dis that's

55:46

relatively straightforward these days

55:48

and so they're taking advantage of the

55:50

performance presumably of serving up

55:52

static content but this comes at a cost

55:55

what's the downside of this file based

55:58

caching

56:02

approach someone

56:05

else nothing we've done thus far is sort

56:08

of a complete win there's always a

56:10

gotcha Lou space okay so space so we're

56:14

storing it on disk and you know if

56:16

you've ever posted on Craigslist they're

56:18

also storing it somewhere in a database

56:20

because they do let you go back and edit

56:22

it it's just Craigslist is one of these

56:25

where reads are probably much more

56:27

common than writes indeed when people

56:29

visit Craigslist they're probably

56:30

flipping through Reading Pages as

56:32

opposed to posting lots and lots and

56:33

lots of ads all at the same time so

56:37

there's some redundancy there that's

56:38

unfortunate

56:39

AEL

56:41

yeah just build upon that you

56:45

willing of code that you use on every

56:48

page again plus it's not a very elegant

56:50

solution to have a big folder on your on

56:52

your server containing 10,000 CLS okay

56:54

okay good so there's redundancy well

56:56

actually with all these thousands of

56:58

files there's redundancy too just in the

56:59

basic stuff like you have the same HTML

57:01

tag the same body tag the same link tag

57:04

the same script tag in every single page

57:07

if they're indeed just static HTML files

57:09

so whereas you get some benefits of

57:11

using something like PHP and recall our

57:13

MVC discussion where we factored out

57:15

template code like the header and the

57:17

footer so that we started it one place

57:19

and not thousands of places Craigslist

57:21

is kind of sacrificing that feature and

57:24

going with this instead so in the end

57:26

it's probably a calculated tradeoff you

57:27

get much better performance presumably

57:30

from just sving up the static content

57:32

but the price you pay is more disk space

57:35

but at the same time you know for a few

57:36

hundred dollars you can typically get

57:37

even bigger hard drives these days so

57:39

maybe that's actually the lesser of the

57:41

evils but there is one got there's

57:43

another big gotcha here if you've

57:45

generated tens of thousands of

57:46

Craigslist pages that look like this

57:49

what's the implication now and maybe why

57:51

are they stuck in the 90s well I decid

57:54

to add we change the background color

57:57

good change the design entirely which is

57:59

necessary I can't do that without

58:01

editing each one of those um 10,000

58:04

files and that's that could be done

58:06

automatically but it's much harder than

58:08

just uh editing a generic template that

58:10

generates it exactly if you want to

58:12

change the Aesthetics of the page and

58:14

add a background color change the CSS or

58:16

make it the font something other than

58:17

Times New Roman it's non-trivial now

58:20

because assuming this is a fully intact

58:22

HTML file with no server include

58:25

mechanism no like require mechanism like

58:27

you have in PHP you have to now change

58:30

the background color in tens of

58:32

thousands of files and less maybe you at

58:34

least put it in a CSS file but even then

58:37

if it's a less trivial change than color

58:39

suppose you want to restructure the HTML

58:41

of the page then you really have to do a

58:42

massive find and replace or more

58:45

realistically probably regenerate all

58:47

10,000 plus pages and I'm we latched on

58:50

to 10,000 arbitrarily but it's a lot of

58:53

pages in this case so upsides and

58:56

downsides they're one of the few people

58:57

on the internet who do this particular

58:59

approach um but it does have some value

59:01

and I think the last time I read up on

59:03

statistics they get by with relatively

59:04

little Hardware as a result which is

59:06

definitely compelling so myle query

59:09

cache this is a mechanism that we didn't

59:10

use but it's so easily enabled on a

59:14

typical server with mySQL there's a file

59:16

called my.cnf for your configuration

59:19

file and you can simply add a directive

59:21

like query cach type equals one and then

59:24

restart the server to enable the query

59:26

cache which pretty much does what it

59:28

says the ne if you execute a command

59:30

like select Fu from bar where baz equals

59:33

123 that will be could be slow the first

59:36

time you execute it if you don't have an

59:38

index or if you have a really huge table

59:42

but the next time you execute it if the

59:44

query cache is on and that row hasn't

59:46

changed the response is going to come

59:47

back much more quickly so MySQL provides

59:50

this kind of caching for identically

59:52

executed queries which might certainly

59:54

happen a lot if a user is navigating

59:56

your website going forward and back

59:58

quite a bit mcash is an even more

1:00:01

powerful U mechanism um Facebook has

1:00:04

made great use of this over the years

1:00:06

especially initially mcash is a memory

1:00:08

cache so it is a piece of software a

1:00:11

server that you run on a server it can

1:00:12

be on the same server as your web server

1:00:15

it can be on a different box altogether

1:00:17

but it essentially is a mechanism that

1:00:19

stores whatever you want in Ram and it

1:00:23

does this with in the PHP context with

1:00:25

code like this so this mcash can be used

1:00:28

by all sorts of languages here is php's

1:00:31

own interface to it and you use mcash as

1:00:34

follows you first connect to the mcash

1:00:36

server using mcash connect which is very

1:00:38

similar in spirit to mySQL connect which

1:00:40

you might recall from a few lectures

1:00:42

back then we try in this example to get

1:00:45

a user so the context here is it's

1:00:47

pretty expensive to do select star from

1:00:49

users on my database table because I've

1:00:52

got millions of users in this table and

1:00:54

I'd really rather not execute that query

1:00:56

more often than I have to I'd rather

1:00:58

execute it once save the results in Ram

1:01:01

and the next time I need that user go

1:01:03

into the ram go into cache to get that

1:01:05

user rather than touching the database

1:01:07

so there's this sort of tier of

1:01:10

performance objectives disc is slow

1:01:12

right spinning discs especially slow but

1:01:15

it's fast to serve up so generally you

1:01:18

might want to store something instead of

1:01:19

on disk you want to store it in a table

1:01:21

that has indexes so that you can search

1:01:24

it more quickly for instance think back

1:01:26

to project zero the XML file it's

1:01:28

relatively small but at the same time

1:01:30

anytime you wanted to search it you had

1:01:31

to load it from disc build up a Dom

1:01:33

thanks to the simple XML API then search

1:01:36

it kind of annoying it'd be nice if we

1:01:38

could skip the disk step so that things

1:01:40

would just be faster and thus was born

1:01:42

MySQL in Project one MySQL is a server

1:01:45

which means it's always running it's

1:01:46

using some Ram so in that case you have

1:01:48

the ability to execute queries on data

1:01:51

that's hopefully in Ram but even if it

1:01:53

isn't you at least have the opportunity

1:01:54

to Define indexes primary Keys unique

1:01:57

keys index Fields so that at least you

1:01:59

can search that data more readily than

1:02:01

you can with say XPath in XML so the

1:02:04

next step is not even to use a database

1:02:06

because database queries can be

1:02:08

expensive relative to just a cash which

1:02:10

is just a key value store I want to give

1:02:13

you x equals y and the next time I ask

1:02:15

for X you give me Y and I want it quick

1:02:17

much faster than a database would return

1:02:19

it so here we've gone and connected to

1:02:21

the memory cache demon the server in the

1:02:23

second line

1:02:25

I am trying to get something from the

1:02:27

cache the arguments to mem cach get take

1:02:30

the first argument is a uh a reference

1:02:34

to the cache that you want to grab

1:02:35

something from and then dollar sign ID

1:02:38

just represents something like one two3

1:02:39

the ID of the user that I want to get if

1:02:42

the user is null what's the implication

1:02:45

apparently Isaac well you do the quy all

1:02:49

over again okay good but in what case

1:02:51

would uh user be null do you think um

1:02:54

when they don't exist good when they're

1:02:56

not in the cache when user One Two Three

1:02:58

or whoever I'm looking for is not in the

1:02:59

cache that variable is going to be null

1:03:01

and so we do this if condition as Isaac

1:03:03

says and here there's some somewhat

1:03:05

familiar code PDO which relates to my

1:03:07

SQL in our case um we connect to the

1:03:11

database uh using that user and pass we

1:03:13

then execute the query function in PDO

1:03:16

in this case select star from users

1:03:18

where ID equals ID I'm not using my I'm

1:03:21

not um escaping ID because in this case

1:03:24

I'm assuming that I know it's an integer

1:03:25

so it's not a dangerous string just to

1:03:27

be clear then I'm calling fetch to get

1:03:29

back an associative array of my data the

1:03:32

user's name email address ID whatever

1:03:35

else I've got in my database but then

1:03:37

the last thing I do before apparently

1:03:40

nothing else because this is out of

1:03:41

context before actually using that user

1:03:44

for anything what am I doing with him

1:03:46

Axel you're storing it in the exactly

1:03:50

I'm storing a key value pair in the

1:03:52

cache whereby the key is the the user's

1:03:54

ID so this implies that there's an ID

1:03:57

field in the user object that came back

1:03:59

from the database from this line here

1:04:01

and the value is the user object itself

1:04:04

so again a memcache in this case is a

1:04:06

key value storage mechanism and the next

1:04:09

time I want to look up this user I want

1:04:10

to look him up by his ID and case in

1:04:14

point that's what I did in line two up

1:04:16

top now caches are finite because Ram is

1:04:21

finite and even disk is finite so what

1:04:24

could happen eventually with my

1:04:26

cash just by nature of that those

1:04:29

constraints Axel it gets so big can't on

1:04:33

Ma good So eventually the cash could get

1:04:35

so big you can't keep it on the machine

1:04:36

so what would be a reasonable thing to

1:04:39

do at that point when you've run out of

1:04:41

Ram or dis space for your

1:04:46

cash you're the person implementing

1:04:48

mcash itself now what do you do in that

1:04:50

case you could just kind of quit

1:04:52

unexpected error but that would kind of

1:04:56

be bad and completely

1:05:00

unnecessary what could you

1:05:03

do is it

1:05:06

sorry yeah so some kind of garbage

1:05:08

collection and what which things would

1:05:10

you collect what things would you uh

1:05:12

remove from

1:05:18

memory

1:05:19

good so we can essentially expire

1:05:22

objects based on when they were put in

1:05:24

so if I put in user 123 yesterday and I

1:05:28

haven't touched him since or needed him

1:05:30

since and I need more space well out

1:05:32

goes user 123 and I can reuse that space

1:05:35

that memory for user 456 if user 456 is

1:05:39

the next person I'm trying to insert

1:05:41

into the cache so indeed this is a very

1:05:43

common mechanism whereby the first one

1:05:46

in is the first one out if that object

1:05:49

has not been needed since by contrast if

1:05:52

123 is just one of these power users who

1:05:54

logging in quite a bit and he he he or

1:05:56

she is logging in again and again and

1:05:58

again well I should remember every time

1:06:00

and we don't see it in the code here but

1:06:02

every time I get a cach hit and I

1:06:05

actually find user 123 in the cache I

1:06:08

could somehow execute another mcash

1:06:10

function that just touches the user

1:06:13

object so to speak thereby updating his

1:06:15

timestamp to be this moment in time so

1:06:17

that you remember that he was just

1:06:20

selected and hopefully mcash get itself

1:06:22

would do that for us and indeed it does

1:06:24

I don't need to do this manually the

1:06:25

cache software would remember oh you

1:06:28

asked for user 1 two 3 I should move

1:06:30

probably move him back to the front of

1:06:31

the line so that the person at the end

1:06:32

of the line is the first one to get

1:06:34

evicted next time around so it's a

1:06:37

wonderfully useful mechanism and

1:06:38

Facebook is very read heavy or very

1:06:40

right

1:06:42

heavy if you're a

1:06:47

user it's kind of both these days you

1:06:50

know early on it was much more read

1:06:52

heavy than write heavy because there

1:06:54

were no like status updates and you

1:06:56

would just have your profile and that

1:06:57

was about it so these days there's

1:06:59

definitely more rights but I'm going to

1:07:00

guess that reads are still more common

1:07:03

than not right when you log if you're a

1:07:04

Facebook user and you log into your uh

1:07:07

account and you see your newsfeed you

1:07:09

know you might have 10 20 whatever

1:07:10

friends show up in that Newsfeed that's

1:07:12

potentially like 10 or 20 queries of

1:07:15

some sort and yet you're probably not

1:07:17

going to update your status 30 times at

1:07:20

in that same unit of time so odds are

1:07:22

Facebook is still a little more read

1:07:24

heavy which makes cashes all the more

1:07:26

compelling because if your own profile

1:07:28

isn't changing all that often at least

1:07:31

you might get 10 page views 100 page

1:07:33

views by friends or random strangers

1:07:35

before you actually update your status

1:07:36

or your profile again that's an

1:07:38

opportunity for optimization so early on

1:07:40

and this day Facebook uses things like

1:07:42

mcash quite a bit so that they're not

1:07:44

hitting their various databases just to

1:07:46

generate your profile they're instead

1:07:48

just getting the results of some

1:07:50

previous lookup unless it has since

1:07:53

expired

1:07:55

well on to mySQL optimization so that

1:07:58

you can squeeze all the more performance

1:07:59

out of your setup so this table is a

1:08:01

little more overwhelming right now than

1:08:02

it needs to be but recall our discussion

1:08:04

of MySQL storage engine some time ago

1:08:07

and we talked briefly about my Isam and

1:08:09

INB does anyone remember at least one of

1:08:12

the distinguishing characteristics of

1:08:14

those two storage engines and again a

1:08:16

storage engine was just like the

1:08:17

underlying format that was used to store

1:08:20

your database data um I think in

1:08:24

support transaction good so INB which is

1:08:28

the default these days so you haven't

1:08:30

really needed to think about this much

1:08:32

since project one um in ODB supports

1:08:34

transactions whereas my Isam does not my

1:08:37

Isam uses locks which are full table

1:08:39

locks but T does tend to have some other

1:08:42

properties and these this list here is a

1:08:45

very long list of the various

1:08:47

distinctions among these several storage

1:08:49

engines um transactions is one of them

1:08:52

um but there's a few other storage

1:08:54

engines here that I thought I would just

1:08:55

draw our attention to so

1:08:59

one you have a memory engine uh

1:09:02

otherwise known as a heap engine this is

1:09:05

a table that's intentionally only stored

1:09:07

in Ram which means if you lose power

1:09:09

server dies or whatnot the entire

1:09:11

contents of these memory tables will be

1:09:13

lost but still kind of a nice feature if

1:09:16

you yourself want to implement a cache

1:09:18

relatively easily by writing keys and

1:09:21

values into your database into two

1:09:22

columns Maybe you yourself can Implement

1:09:25

some kind of cash to avoid having to

1:09:27

touch maybe much larger tables that you

1:09:29

yourself have so that's an option to you

1:09:32

archive storage engine haven't had to

1:09:34

use this but take a guess as to what it

1:09:37

does besides archiving

1:09:41

something what does this engine do for

1:09:43

you do you

1:09:52

think

1:09:56

and what what was the last sentence the

1:09:57

last part of your

1:10:02

comments oh it doesn't store anything in

1:10:04

cash you have to query it all the time

1:10:05

not quite so the property you're

1:10:07

actually getting and you can kind of see

1:10:10

it here um but there's some footnotes on

1:10:13

the other storage engines is it's

1:10:15

compressed by default so archive tables

1:10:18

are actually slower to query but they're

1:10:21

automatically compressed for you so they

1:10:23

take up much much less space so a common

1:10:25

case uh common use case for archive

1:10:28

tables might be log files where you want

1:10:31

to keep the data around and you want to

1:10:32

write out a whole bunch of key of values

1:10:35

in a row every time someone hits your

1:10:37

web server anytime something buys

1:10:39

someone but suppose you rarely query

1:10:41

that data you're keeping it for

1:10:42

posterity for research purposes for

1:10:44

Diagnostic purposes but you're not going

1:10:46

to do any selects on it any time soon so

1:10:48

it would just be a waste to keep use

1:10:50

more dis space than you need to so

1:10:52

you're willing to sacrifice some future

1:10:54

performance when you do need to query it

1:10:56

for some long-term dis saving so the

1:10:58

archive format allows you to do that NDB

1:11:01

is a network uh storage engine which is

1:11:03

used for clustering so that actually

1:11:05

there is a way of addressing the issue

1:11:08

of single points of failure that we

1:11:09

discussed earlier with shared storage

1:11:11

but we'll see a simpler approach in just

1:11:13

a

1:11:14

moment so in the world of datab bases

1:11:18

like MySQL they typically offer this

1:11:20

replication feature that I mentioned

1:11:22

earlier so replication is all about

1:11:24

making automatic copies of something and

1:11:26

the terminology generally goes as

1:11:27

follows you generally have a master

1:11:29

database which is where you read data

1:11:32

from and write data to but just for good

1:11:35

measure that Master has one or more

1:11:37

slave databases attached to it via

1:11:39

network connection and their purpose in

1:11:42

life is to get a copy of every row

1:11:45

that's in the master database you can

1:11:47

think of it rather simply as anytime a

1:11:49

query is executed on the master that

1:11:51

same query is copied down to one or more

1:11:53

slaves and they do the exact same thing

1:11:55

so that in theory the master and all of

1:11:58

these slaves are identical to one

1:11:59

another so what's the upside now of

1:12:02

having databases one two three and four

1:12:05

all of which are copies of one another

1:12:07

apparently what problems does this solve

1:12:09

for us if

1:12:11

any AEL

1:12:17

datab good so if something if database

1:12:19

one dies because of human error you trip

1:12:21

over the court hard drive dies r Fizzles

1:12:24

out whatever the case may be you have

1:12:26

literally three backups that are

1:12:28

identical so there's no tapes involved

1:12:30

there's no backup server I mean these

1:12:31

are full-fledged databases and in the

1:12:33

simplest case you could just unplug the

1:12:36

master plug in the slave and voila you

1:12:38

now have a new master and you might have

1:12:40

to do a bit of reconfiguration in the

1:12:42

databases to make him to promote him to

1:12:44

master so to speak and then leave

1:12:46

servers three and four as the New Slaves

1:12:48

while you fix server number one but that

1:12:51

would be one approach here so so you

1:12:53

have some redundancy even though you

1:12:54

might have a little bit of downtime at

1:12:56

least you can get back up and running

1:12:57

quickly and indeed you could automate

1:12:59

this process if you notice that the

1:13:00

master is down you could uh take him

1:13:02

offline completely promote the slave and

1:13:05

reconfigure them all just by writing a

1:13:07

script what

1:13:09

else how else could we take advantage of

1:13:11

this

1:13:20

topology let me ask a more leading

1:13:22

question

1:13:24

in the context of Facebook especially

1:13:26

early days how might they in particular

1:13:30

have made good use of this

1:13:36

topology AEL well maybe if you get a lot

1:13:40

of a lot of queries uhhuh you can

1:13:43

Outsource them to different slaves okay

1:13:45

so if you're getting a lot of queries

1:13:47

you could you know maybe you could just

1:13:48

load balance across database servers and

1:13:51

absolutely you could the load balancers

1:13:52

don't have to be used for HTTP alone you

1:13:54

could use it for MySQL traffic but why

1:13:56

do I say Facebook in particular early on

1:13:59

they didn't get that many queries but

1:14:01

this was still a good Paradigm for

1:14:04

them why yeah why is this good

1:14:15

perhaps so back to my hypothesis that

1:14:18

they're more read heavy than write Heavy

1:14:21

How can you

1:14:24

adapt that that reality to this

1:14:27

particular topology effectively or put

1:14:30

another way why is this a good topology

1:14:33

for a website that is very read heavy

1:14:35

and less write heavy

1:14:44

Ben

1:14:47

okay okay good so reading can be

1:14:49

expedited so if we kind of combine Ben

1:14:51

and Axel's proposals here for a read

1:14:53

heavy website like Facebook certainly in

1:14:55

the early days you could just write your

1:14:57

code in such a way that any select

1:14:58

statements go to databases two three or

1:15:02

four and any inserts updates or deletes

1:15:04

have to go apparently to server one

1:15:08

which even though that query then has to

1:15:10

propagate to servers 2 three and four it

1:15:12

is less common and that happens

1:15:14

automatically so the code wise you don't

1:15:16

have to worry about it too much and if

1:15:18

you're suffering a bit of performance

1:15:19

there well you can just throw more

1:15:20

servers at it and have even more read

1:15:22

servers to lighten the load for further

1:15:23

so this approach of having slaves that

1:15:26

can typically be used either for

1:15:27

redundancy so you just have a hot spare

1:15:30

ready to go or so that you can balance

1:15:33

read requests across them is a very nice

1:15:36

solution but of course every time we

1:15:39

solve one problem we've introduced

1:15:41

another or at least we haven't fixed yet

1:15:42

another here what is a fa what is a

1:15:45

fault in this layout

1:15:49

still be

1:15:52

paranoid

1:15:56

kind of talked about it earlier but like

1:15:58

what if one dies right unless this is

1:16:01

there's got to be some blip on the radar

1:16:04

here because we have to like promote a

1:16:06

slave and right so you still have a

1:16:08

single point of failure here at least

1:16:10

for rights we could keep Facebook Alive

1:16:12

by letting people browse profiles and

1:16:14

read profiles but status updates for

1:16:16

instance could be offline for as long as

1:16:18

it takes us to promote a slave to a

1:16:20

Master feels like it'd be nicer or at

1:16:22

least our prob ility would be better of

1:16:24

up time if we instead had not just a

1:16:26

single Master but again let's just throw

1:16:28

Hardware at the problem so another

1:16:30

common Paradigm is actually to have a

1:16:32

master master set up whereby as the

1:16:35

labels imply and as the arrows suggest

1:16:38

this time you could write to either

1:16:40

server one or two and if you happen to

1:16:42

write to server one that query gets

1:16:44

replicated on server two and vice versa

1:16:48

so now you could keep it simple you

1:16:50

could always write to one but then the

1:16:52

quer Theory goes to uh number two

1:16:55

automatically or you could write to

1:16:57

either thereby load balancing across the

1:16:58

two and they'll propagate between each

1:17:01

other but in this case here if you've

1:17:04

laid out your network connections

1:17:06

properly either one or two can go down

1:17:08

and you still have a master that you

1:17:10

could read from and you could even

1:17:11

implement this in code recall very

1:17:13

simply we had the MySQL connect function

1:17:15

weeks ago or even the PDO Constructor

1:17:18

function which tries to connect to a

1:17:19

database you could implement this in PHP

1:17:22

code if MySQL connect fails when

1:17:24

connecting to server one then just try

1:17:26

server two so you yourself could build

1:17:28

in some redundancy so that now we could

1:17:30

lose server one or two and not have to

1:17:32

intervene as humans just yet because we

1:17:34

at least still have a second master that

1:17:36

we can continue writing to even though

1:17:39

server one is Now offline for some

1:17:41

amount of

1:17:42

time all right but we still have to

1:17:44

Route traffic there so in pursuit of

1:17:47

this idea of load balancing here's a

1:17:49

more complex picture that starts to

1:17:51

unite some of our web ideas and some of

1:17:53

our database ideas so at the top there

1:17:55

we have some kind of network we have a

1:17:57

load balancer in between and then we

1:17:59

have this frontend tier so web servers

1:18:01

are typically called a tier a service

1:18:04

tier um this is a multi-tiered

1:18:06

architecture would be the jargon here

1:18:08

and those web servers now apparently are

1:18:10

routing their requests through what in

1:18:13

order to reach some MySQL slaves for

1:18:19

reads who's the man in the middle here

1:18:22

yeah AEL uh for reads it would be the

1:18:25

load balancer okay so for reads yeah we

1:18:28

have a second load balancer depicted

1:18:30

here frankly in reality they could be

1:18:32

one and the same they could be the same

1:18:33

device but just listening for different

1:18:35

types of connections but for now they're

1:18:37

drawn more simply as separate now we

1:18:39

have one MySQL master so we also have

1:18:41

wires or arrows pointing from the web

1:18:43

servers to the master and the master

1:18:45

meanwhile has some kind of connection to

1:18:47

the slaves so not bad no frankly this is

1:18:50

starting to hurt my brain because now

1:18:52

what was a very very simple class where

1:18:54

you have a nice uh self-contained

1:18:56

Appliance on your machine on your laptop

1:18:58

does everything web database caching

1:19:00

anything you wanted to do my God look at

1:19:02

all the things we have to wire up now

1:19:04

and it's still not perfect what could

1:19:05

die here where what are our single

1:19:07

points of

1:19:08

failure Jack oh Isaac

1:19:13

sure my master okay so the MySQL Master

1:19:16

we haven't really solved that problem so

1:19:18

kind of be nice to steal part of the

1:19:20

previous picture and maybe uh it into

1:19:23

here

1:19:25

Jack same thing Exel load load balancers

1:19:29

right so single point of failure is very

1:19:32

well defined like single point of

1:19:34

failure just look for any um any

1:19:37

bottlenecks here whereby things point in

1:19:40

and then go out load balancers is one

1:19:42

here load balancers one there so it

1:19:44

turns out with load balancers for your

1:19:46

$100,000 you can get two of them

1:19:48

typically in the package and what they

1:19:50

tend to do is operate also in what's

1:19:52

called um similar in spirit to master

1:19:55

master mode but in the context of load

1:19:56

balancers it's typically called active

1:19:58

active as opposed to active passive and

1:20:01

the idea here is with active active you

1:20:04

have a pair of load balancers that are

1:20:06

constantly listening for connections

1:20:08

either one of which can receive uh

1:20:11

packets from the outside world and then

1:20:13

relay them to backend servers and what

1:20:16

they typically do is they send

1:20:18

heartbeats from left to right and right

1:20:19

to left so that if this guy ever stops

1:20:22

hearing a heartbeat from this guy so to

1:20:24

speak and a heartbeat is just like a

1:20:25

packet that gets sent every second or

1:20:27

something like that if this guy stops

1:20:30

hearing a heartbeat from this guy he

1:20:31

automatically assumes that this guy must

1:20:33

have gone offline so he's completely in

1:20:35

charge now and he continues to send

1:20:38

traffic uh from the outside world in or

1:20:41

if you instead have active passive mode

1:20:43

if this is the active guy at the moment

1:20:46

rather if this is the active guy at the

1:20:47

moment and he dies this guy similarly

1:20:50

detects oo no more heartbeat and what

1:20:52

the passive guy will do is promote

1:20:53

himself to active which essentially just

1:20:55

means he takes over the other guy's IP

1:20:58

address so that all traffic now comes to

1:21:00

him so in short we definitely need

1:21:02

another load balancer in the picture how

1:21:04

it's implemented is um is uh not as

1:21:08

important to us right now but having a

1:21:10

single load balancer is probably a bad

1:21:12

thing right and this is the tragedy you

1:21:14

can throw money at you can throw a lot

1:21:16

of brainpower at various tiers here but

1:21:18

if you have a lot of web servers a lot

1:21:20

of MySQL servers but you have one look

1:21:22

balancer just cuz it was really

1:21:24

expensive or you didn't know how to

1:21:25

configure it properly like the rest of

1:21:27

it is pretty much for not because you

1:21:29

still have things things that can die

1:21:32

and take down your entire website so

1:21:35

let's make this more complex still so

1:21:37

let's now introduce two load balancers

1:21:40

and let's actually introduce an idea of

1:21:42

partitioning and this was actually

1:21:44

something that Facebook coincidentally

1:21:45

did make good use of early on back in

1:21:47

the day there was harvard. harvard. thee

1:21:50

face.com there was mit. the facebook.com

1:21:54

and the earliest partitioning that they

1:21:55

used was to essentially have a different

1:21:58

server as best Outsiders could tell for

1:22:00

each school so they literally just like

1:22:02

copied the database copied the files

1:22:04

over to another server and then voila

1:22:06

thus was born MIT mit's copy of Facebook

1:22:10

but this is actually even though this

1:22:12

would get kind of messy for 800 million

1:22:13

users and thousands and thousands of

1:22:15

universities and uh networks it's pretty

1:22:18

clean early on because it's just

1:22:21

leverages this idea of part partitioning

1:22:23

right it's kind of we didn't have a

1:22:24

Facebook didn't have a big enough server

1:22:26

to handle Harvard and MIT so why not

1:22:28

just get two and say Harvard users go

1:22:30

here MIT users go here and now we've

1:22:33

kind of avoided that problem now

1:22:35

unfortunately when bu comes on we need a

1:22:37

third server but at least we can scale

1:22:39

horizontally now there is a catch with

1:22:41

partitioning as soon as you wanted to be

1:22:43

able to poke someone at MIT or vice

1:22:45

versa you had to somehow cross that

1:22:47

Harvard MIT boundary at which point it's

1:22:50

kind of a bad thing that they're all in

1:22:51

separate databases so early on there

1:22:53

were some features that you could only

1:22:54

do within your own network um not until

1:22:57

there was more shared State could you

1:22:59

send messages and the like so

1:23:01

partitioning though could be used even

1:23:02

more simply suppose that you just had a

1:23:05

whole bunch of users well you need to

1:23:07

scale your architecture horizontally why

1:23:10

don't I just put users whose last name

1:23:11

start with a to M on half of my servers

1:23:14

and then n through Z on the others right

1:23:17

and when they log in I just send them to

1:23:18

one or the other server based on that so

1:23:20

in general partitioning is not a bad

1:23:23

idea it's very common in databases

1:23:26

because you can still have redundancy a

1:23:27

whole bunch of slaves in this case here

1:23:29

whole bunch of slaves over here but you

1:23:31

can balance load based on some highlevel

1:23:33

user information not based on load not

1:23:35

round robin you can actually take into

1:23:38

account what someone's name is and then

1:23:39

send them to this particular server so

1:23:42

partitioning is a very common Paradigm

1:23:45

and then lastly just to slap a word on

1:23:47

It High availability refers to what we

1:23:50

described in the context of load

1:23:51

balancers but it can apply to databases

1:23:53

as well whereby High availability or ha

1:23:56

is the buzz word simply refers to some

1:23:59

kind of relationship between a pair or

1:24:01

more of servers that are somehow

1:24:03

checking each other's heartbeats so that

1:24:05

if one of them dies the other takes on

1:24:07

the entire burden of the uh of the

1:24:10

service that's being provided whether a

1:24:12

database or whether a load

1:24:16

balancer so even though we finally got

1:24:19

the iPad working it's a little small to

1:24:20

draw on so what I wanted to do

1:24:23

as our final example here is let me

1:24:28

raise the screen

1:24:31

here however one of these buttons will

1:24:33

do it

1:24:37

uh all right we're going to old school

1:24:40

now our first and last piece of chalk in

1:24:42

the

1:24:43

class

1:24:44

um let's

1:24:49

see uh start with the middle one

1:24:52

[Music]

1:24:54

all right let's build ourselves a

1:24:55

network here so we have a need for uh

1:25:00

one or more web servers one or more

1:25:02

databases maybe some load balancers but

1:25:04

we're also going to try to tie together

1:25:06

last week's conversation about security

1:25:08

so we'll have to think about firewalling

1:25:09

things out now so in very simple form we

1:25:13

have here a web server which I'll draw

1:25:17

is www all right so that's our web

1:25:20

server and now my website's doing so

1:25:21

well that I need a second web server so

1:25:23

I'm going to draw it like this and now

1:25:26

we need to revisit the issue of

1:25:28

balancing load so what felt like one of

1:25:31

our best options here how do I still

1:25:35

have the internet which I'll draw as a

1:25:38

cloud

1:25:39

here connected to both of these servers

1:25:42

somehow but I want the property of

1:25:45

sticky sessions so what are my options

1:25:47

or what was my best

1:25:51

option

1:25:53

how do I Implement sticky

1:25:56

sessions AEL use load balanc keep all

1:26:00

the sessions in one place okay good so

1:26:02

use a load balancer and store all the

1:26:04

sessions in one place and that's not

1:26:07

okay so we can actually do one but not

1:26:09

necessarily both of those let me

1:26:11

interpose now the thing we started

1:26:13

calling a black box so this is some kind

1:26:15

of load balancer now I still have my

1:26:17

backend servers and here's another one

1:26:21

here okay and now this is connected here

1:26:24

but I still want sticky sessions but you

1:26:26

know what shared states that sounded

1:26:29

expensive fiber channel ice scy sounded

1:26:31

complicated there's a simpler way how do

1:26:33

I ensure that I get sticky sessions

1:26:34

using only a load balancer and no shared

1:26:37

state

1:26:44

yet how can I ensure that when Alice

1:26:47

comes in and she's sent to This Server

1:26:49

the first time that the next time she

1:26:51

comes in she sent to the same

1:26:59

oneel okay good so why don't we have the

1:27:02

load balancer listen at the HTTP level

1:27:05

and when the response comes back from

1:27:07

the first web server let's give them

1:27:09

numbers so let's call this one and this

1:27:11

guy two the load balancer can insert

1:27:13

some kind of cookie that allows it to

1:27:16

remember that this user belongs on

1:27:19

server one and how it does that I don't

1:27:20

know it's a big random number and it's

1:27:21

got a table like um PHP does for its

1:27:25

sessions and figures out which server to

1:27:27

send her to in this case all right so

1:27:29

now I have a database the easiest way I

1:27:31

know how to set up a database is to put

1:27:33

it on the web server itself so much like

1:27:35

the cs50 appliance you have a database

1:27:37

in the same box as a web server if I now

1:27:41

have a database here and here on the

1:27:43

same boxes as our web servers what's the

1:27:47

most obvious problem that now

1:27:50

arises yeah Alice shopping cart is oh

1:27:54

well if she does something to her

1:27:56

profile or whatever it's just going to

1:27:58

be on server one and not on server two

1:28:00

since she just visited server one

1:28:02

exactly so if Alice just happens to end

1:28:04

up on server one and she updates her

1:28:06

profile or credit card information or

1:28:07

something persistent not the shopping

1:28:09

cart thing because that involves the

1:28:10

session but she does something

1:28:11

persistent it's going to persist on this

1:28:13

database and that's fine because sticky

1:28:16

sessions are solving all my problems now

1:28:17

but she comes back in a week or she logs

1:28:20

in from a different computer cookie

1:28:22

expires whatever and she ends up here

1:28:24

what happened to my credit card

1:28:25

information what happened to my profile

1:28:27

I now have no profile because I'm on a

1:28:29

different database so clearly this is

1:28:31

not going to fly unless we partition our

1:28:35

users and have the load balance or

1:28:37

actually take into account who is this

1:28:39

user and then send the user based on

1:28:41

Alice's last name always to the same

1:28:43

server so that could be one approach but

1:28:45

for now let's instead factor out the

1:28:47

database and say that it's not on the

1:28:50

web servers it's separate and it's it's

1:28:52

got some kind of internet connection

1:28:53

here of course we've solved one problem

1:28:56

but introduced a new one which is

1:28:59

what

1:29:01

ISAC single point of failure yeah so

1:29:05

single point of failure again so how can

1:29:07

we mitigate this well we can do a couple

1:29:09

of things we can attach slave databases

1:29:12

off of this and that's kind of nice but

1:29:15

it then involves somehow promoting a

1:29:17

slave to a Master in the event one dies

1:29:19

so maybe the cleanest approach would be

1:29:21

something like

1:29:22

two Master

1:29:24

databases so we'll call this DB1 this

1:29:27

will be db2 and now how do I want to do

1:29:30

this connect these like

1:29:35

this Isaac you shook your

1:29:37

head well you could connect the two

1:29:40

databases to each other okay so we

1:29:42

should probably do this for master

1:29:44

master replication so that's good but

1:29:47

what about these lines good

1:29:50

bad

1:29:53

answer's

1:29:54

bad why bad Jack well you can connect

1:29:57

each one to both of the right so the

1:30:01

problem we just identified was database

1:30:03

on same server as web server bad because

1:30:05

then it's talking only to it and if

1:30:07

Alice ends up on the other server she

1:30:08

has no data that you're expecting well

1:30:10

functionally this is equivalent I've

1:30:12

just drawn a line but they're still only

1:30:13

connected to each other and if the tri

1:30:16

traffic should probably not go like that

1:30:18

so we at least need to have some kind of

1:30:19

cross connect so okay so I can do

1:30:23

this but now what do I do so now my load

1:30:27

balancing has to be done in code if

1:30:29

those are the only uh components in my

1:30:32

system right now the line suggests that

1:30:33

dubdub du1 has a network connection to

1:30:35

DB1 and db2 but that means now I have to

1:30:38

do something like an if condition only

1:30:40

in my PHP code to say if this database

1:30:42

is up right here else if this database

1:30:45

is up right there and that's not bad but

1:30:47

now your developers have to know

1:30:48

something about the topology if you ever

1:30:50

introduce a third master or something

1:30:52

like that although my SQL wouldn't play

1:30:54

nicely with that now you have to change

1:30:56

your code this is not a nice layer of

1:30:58

abstraction so how else could we solve

1:31:00

this

1:31:02

Axel I don't like the idea of connecting

1:31:04

each of my web servers to the database

1:31:07

because frankly you know what this is

1:31:08

going to get really ugly if it starts

1:31:10

looking like this right very quickly

1:31:13

this degrades into a mess yeah get

1:31:15

another machine load Balan will okay

1:31:18

good all of that so connect your um

1:31:22

your dub du dub servers to below

1:31:24

balancer and then let it handle requests

1:31:26

and then you can Implement all kinds of

1:31:28

of features like say um they are both

1:31:32

Masters right they have the same data

1:31:34

but what if only users with u last name

1:31:37

that starts with end logs in well you're

1:31:39

going to have a load on one particular

1:31:41

server but then the load balancer can

1:31:43

take all those features we talked about

1:31:44

good CPU cycles and all that and

1:31:47

actually distribute uh my SQL queries

1:31:49

across databas okay good so we insert a

1:31:52

load balancer here which is connected to

1:31:54

both the dub machines and also the

1:31:55

database servers and then he can be

1:31:58

responsible for load balancing across

1:31:59

the two masters um it's actually harder

1:32:02

for the database to do any kind of

1:32:03

intelligence load balancing based on

1:32:05

last names at this point since the MySQL

1:32:08

traffic is going to operate with binary

1:32:10

messages not with HTTP style textual

1:32:13

messages um load balancer up here can

1:32:15

look at HTP headers and make Intelligent

1:32:17

Decisions it's harder and maybe not

1:32:19

impossible but it wouldn't be very

1:32:20

common to do load balancing based on

1:32:23

application layer intelligence here you

1:32:25

would probably push that to the PHP code

1:32:27

again in that case but this isn't bad

1:32:30

but Isaac doesn't like this picture now

1:32:32

because of what it still fails at one

1:32:34

point yeah so we still have the single

1:32:36

point of failure so you just cost me

1:32:38

even more money or more complexity even

1:32:41

if I'm using free software this just

1:32:42

takes more time now so now we have load

1:32:45

balancer one load balancer two I need to

1:32:49

do something like

1:32:50

this

1:32:53

um and even though this looks a little

1:32:54

ridiculous um oh actually it's a little

1:32:56

elegant that's pretty sexy so you would

1:32:59

do this with switches or some kind of

1:33:01

ethernet cables all going into some

1:33:03

Central source so suppose instead we

1:33:06

actually did that if you've ever plugged

1:33:07

in a computer into a network Jack which

1:33:09

most of you probably have even if you

1:33:10

have a laptop you don't connect these

1:33:12

computers all to themselves you instead

1:33:14

connect them to like a big switch that

1:33:16

has lots of ethernet ports that you can

1:33:18

plug into but now Isaac what what do you

1:33:20

not like about this idea if I'm plugging

1:33:22

everything into a

1:33:24

switch still fails yeah so welcome to

1:33:27

the world of like Network redundancy so

1:33:30

really the right way to do this is to

1:33:32

have two switches so almost every one of

1:33:34

your servers database and web alike as

1:33:36

well as your load balancers would

1:33:38

typically have at least two ethernet

1:33:40

Jacks in them and one cable would go to

1:33:42

one switch another cable would go to the

1:33:43

other switch you have to be super

1:33:45

careful not to create Loops of some sort

1:33:47

so switches have to be somewhat

1:33:49

intelligent typically so that you don't

1:33:50

create this crazy mess where traffic is

1:33:52

just bouncing and bouncing around in

1:33:54

your internal Network and nothing's

1:33:55

getting in or out so there's an uh

1:33:58

there's some care that has to be taken

1:33:59

but in general this is really the theme

1:34:02

in ensuring that you have not only

1:34:03

scalability but redundancy and higher

1:34:06

probabilities of uptime and resilience

1:34:07

against failure you really do start

1:34:09

cross-connecting many different things

1:34:12

but let's push harder Isaac what suppose

1:34:14

I fix the switch issue suppose I also

1:34:16

make this two load balancers and fix

1:34:18

that

1:34:19

issue what's something else could fail

1:34:32

now can't do this on an iPad very well

1:34:35

um so this is your data center here's

1:34:38

the door to your data

1:34:39

center Jack the building burns

1:34:44

down that's good more extreme than I had

1:34:46

in mind I was thinking the power goes

1:34:47

out but that works too um so the

1:34:49

building itself burns down or goes

1:34:52

offline you have some kind of network

1:34:54

disconnect between you and your ISP the

1:34:55

whole building or um the power indeed

1:34:58

does go out and this has happened in

1:35:00

fact one of the things that happens

1:35:01

every time Amazon goes out is the whole

1:35:03

world starts to think that clouds cloud

1:35:06

computing so to speak is a a bad thing

1:35:09

because oh my god look you can't keep

1:35:10

the cloud up but the tragedy here is in

1:35:12

this perception that cloud computing

1:35:14

really just refers to Outsourcing of

1:35:16

services and sharing resources like

1:35:18

power and networking and and security

1:35:20

and so forth across multiple customers

1:35:23

so Amazon Services ec2 elastic compute

1:35:25

cloud is kind of this picture here

1:35:27

whereby you don't own the servers but

1:35:29

you do rent space on them because they

1:35:31

give you vpss that happen to be housed

1:35:33

inside of this building Amazon offers

1:35:35

things called availability zones whereby

1:35:37

this might be an availability Zone

1:35:38

called us East one so this is a building

1:35:40

in Virginia in that particular case and

1:35:43

what they offer though is Us East 2 and

1:35:45

three and four they call them A and B

1:35:47

and C and D and what that simply means

1:35:50

in theory is that there's another

1:35:52

building like this drawn over there that

1:35:54

does not share the same power source

1:35:56

does not share the same networking

1:35:58

cables and so even if something goes

1:36:00

wrong in one building in theory the

1:36:02

other shouldn't be affected however

1:36:04

Amazon has suffered outages in multiple

1:36:06

availability zones multiple data centers

1:36:09

so in addition to having servers in

1:36:10

Virginia guess where else they have

1:36:15

servers anywhere else okay anywhere else

1:36:17

yeah that's actually a pretty hard

1:36:18

question the world's a big place so the

1:36:20

west coast and in Asia and in South

1:36:22

America and in Europe as well they have

1:36:24

different regions as they call them

1:36:26

inside of which are different data

1:36:27

centers or availability zones but this

1:36:29

just means that you can really drive

1:36:31

yourself crazy thinking through all the

1:36:33

possible failure scenarios because even

1:36:34

though Jack's building burning down is a

1:36:37

little extreme things like that do

1:36:39

happen right if you have a massive storm

1:36:41

like a tornado or hurricane that just

1:36:43

knocks out power absolutely could a

1:36:45

whole building goes down go down so what

1:36:47

do you do in that case well we have to

1:36:49

have a second data center availability

1:36:51

zone I'll draw it much smaller this time

1:36:53

even though it might be this physically

1:36:54

the same so here's another one suppose

1:36:56

that inside of this building is exactly

1:36:58

that same topology so now really what we

1:37:01

have is the internet outside these boxes

1:37:04

connecting to both buildings so so

1:37:08

internet is no longer inside the

1:37:10

building so once you have two data

1:37:12

centers how do you now distribute your

1:37:15

load across to Data Centers Axel well

1:37:18

then you can use the DNS trause yeah so

1:37:21

we we didn't really spend much time on

1:37:23

it but recall that you can do load

1:37:24

balancing at the DNS level and this is

1:37:26

indeed how you can do uh geography based

1:37:29

geoloc geography based load balancing

1:37:32

whereby now when someone on the internet

1:37:34

requests the IP address of something.com

1:37:37

they might get the IP address really of

1:37:40

this building or more specifically of

1:37:41

the load balancer in this building or

1:37:44

they might get the IP address of the

1:37:45

load balancer in this building right

1:37:47

when we did the NS lookup on Google we

1:37:49

got a whole bunch of results that's not

1:37:51

because they have one building with lots

1:37:53

of load balancers inside of it that's

1:37:54

because they probably have lots of

1:37:56

separate buildings or data centers

1:37:58

different countries even that themselves

1:38:00

have different entry points different IP

1:38:02

addresses so you have Global load

1:38:05

balancing as it's typically called then

1:38:06

the request comes into a building and

1:38:08

you still have the issue of somehow

1:38:09

making sure that subsequent traffic gets

1:38:11

to the same place because odds are

1:38:13

Google is not sharing your session

1:38:14

across entirely entirely different

1:38:17

continents even though they could be but

1:38:19

that would probably be expensive or slow

1:38:21

do so odds are you're going to stay in

1:38:22

that building for some amount of time

1:38:24

but again these ideas we've been talking

1:38:26

about just get magnified the bigger and

1:38:28

bigger you start to think and even then

1:38:30

you have potential downtime because if a

1:38:32

whole building goes offline and your

1:38:34

browser or your computer happens to have

1:38:36

cashed the IP address of that building

1:38:40

that data center could take some minutes

1:38:42

or some hours for your TTL to expire at

1:38:46

which point you get rerouted to

1:38:48

something else not too long ago just a

1:38:50

few weeks I think or was offline for

1:38:52

several hours one night cuz they use

1:38:53

Amazon um a bunch of other popular

1:38:55

websites too who use Amazon Services

1:38:58

were down alt together because they were

1:39:00

in a building or a set of buildings that

1:39:02

suffered this kind of downtime and it's

1:39:05

hard like if you are having the

1:39:07

fortunate problem of way too many users

1:39:09

and lots of Revenue um it gets harder

1:39:11

and harder to actually scale things out

1:39:13

globally so typically people do what

1:39:15

they can but as Isaac has gotten very

1:39:16

good at pointing out you can at least

1:39:18

avoid as best as possible these kinds of

1:39:20

single point points of

1:39:23

failure

1:39:25

questions so a word on security then

1:39:27

let's focus only on this picture not so

1:39:29

much on the buildings what kind of

1:39:30

traffic now needs to be allowed in and

1:39:33

out of the building so let me go ahead

1:39:35

and just give myself some internet here

1:39:38

connecting to the load balancer somehow

1:39:41

what type of internet traffic should be

1:39:43

coming from the outside world in if I'm

1:39:46

hosting a website with a lamp based

1:39:48

website yeah well you would want to fire

1:39:51

that allows only for 80 connections okay

1:39:54

good so I want TCP recall um which is

1:39:57

one of the transport protocols 80 on the

1:40:00

way in that's good but you just

1:40:02

compromised my ability to have certain

1:40:05

security why you're now blocking a very

1:40:08

useful type of traffic oh yeah ENC good

1:40:10

so we also want 443 which is the default

1:40:14

Port that's used for SSL for https based

1:40:17

URLs so that's good this means now that

1:40:19

the only traffic allowed into my data

1:40:21

center is TCP 80 and 443 now those

1:40:24

familiar with SSH you've also just

1:40:26

locked yourself out of your data center

1:40:27

because you cannot now SSH into your

1:40:29

data center so you might want to allow

1:40:30

something like Port 22 for SSH or you

1:40:34

might want to have an ssl-based VPN so

1:40:36

that you can connect somehow to your

1:40:37

data center remotely and again it

1:40:39

doesn't have to be a data center this

1:40:40

can just be some web hosting comp or

1:40:42

some VPS hosting company that you're

1:40:44

using and okay so we might need one or

1:40:47

more other ports for our VPN but for now

1:40:48

that's pretty good how about the load

1:40:50

balance bancers what kind of traffic

1:40:52

needs to go from the load balancer to my

1:40:54

web

1:41:00

servers Axel well it's really a mess to

1:41:03

keep it encrypted because once it's

1:41:05

inside the data center nobody else is

1:41:07

going to listen than the people inside

1:41:09

the so you would want to drop the

1:41:11

encryption and do 80 good and that's

1:41:14

actually very common to offload your SSL

1:41:17

to the load balancer or some special

1:41:19

device and then keep everything anything

1:41:21

else unencrypted because if you control

1:41:23

this it's at least safer not 100%

1:41:25

because if someone compromises this now

1:41:27

they're going to see your traffic

1:41:28

unencrypted but if you're okay with that

1:41:30

doing the SSL termination here so

1:41:33

everything's encrypted from the internet

1:41:34

down to here but then everything else

1:41:36

goes over normal unencrypted HTTP the

1:41:39

upside of that is remember the whole

1:41:41

certificate thing you don't need to put

1:41:42

your SSL certificate on all of your web

1:41:44

servers you can just put it in the load

1:41:46

balancer or the load balancers you can

1:41:48

get expensive load balancers to handle

1:41:50

the cryptog graphy and the the

1:41:51

computational cost thereof and you can

1:41:53

get cheaper web servers because they

1:41:54

don't need to worry as much about that

1:41:56

kind of overhead so that's one option so

1:41:58

CCP 80 here and here how about the

1:42:00

traffic between the web server and the

1:42:03

databases perhaps through these load

1:42:07

balancers this is a more of a trivia

1:42:10

question but what kind of what kind of

1:42:12

traffic is it even if you don't know the

1:42:13

port number

1:42:15

yeah it's

1:42:18

query yeah uh query ex or more specific

1:42:20

it's the SQL queries like select and

1:42:22

insert and delete and so forth so this

1:42:26

is generally TCP

1:42:29

336 which is the port number that my SQL

1:42:33

uses by default so what does this mean

1:42:35

um if you do have firewalling

1:42:37

capabilities and we haven't drawn any

1:42:39

firewalls per se so we do need to insert

1:42:41

some Hardware into this picture that

1:42:43

would allow us to actually make these

1:42:45

kinds of configuration changes but if we

1:42:47

assume we have that ability in large

1:42:48

part because all of these things are

1:42:50

plugged in in as we said to some kind of

1:42:51

switch well the switch could be a

1:42:53

firewall itself and we could make these

1:42:55

configuration changes we can further

1:42:57

lock things down why I mean everything

1:43:00

just works if I don't firewall

1:43:02

things why would I want to bother

1:43:05

tightening things so that only 8 and 443

1:43:07

are allowed here and 3306 is allowed

1:43:10

here and in fact notice there's no line

1:43:12

between these

1:43:14

guys well it would be really stupid to

1:43:17

keep for example 3306 open in the

1:43:20

because then people they might not be

1:43:22

able to because of other security

1:43:24

measures but in theory they they are

1:43:26

allowed by the firewall to quer your

1:43:29

database and do

1:43:30

SQL commands good exactly there's just

1:43:33

no need for people to be able to

1:43:35

potentially even execute SQL querries

1:43:37

coming in or make MySQL connections and

1:43:39

even if you're not even listening for

1:43:40

MySQL connections it again is sort of

1:43:42

the principle of the thing you should

1:43:44

really have the uh the principle of

1:43:47

least privilege whereby you only open

1:43:49

those doors that that people actually

1:43:51

have to go through otherwise you're just

1:43:53

inviting unexpected Behavior because you

1:43:56

left the door a jar so to speak you left

1:43:57

the port open and it's not clear whether

1:44:00

someone might in fact take advantage of

1:44:02

that case in point if somehow you screw

1:44:04

up or Apache screws up or PHP screws up

1:44:06

and this server is compromised it'd be

1:44:09

kind of nice if the only thing this

1:44:11

server can do is talk via MySQL to this

1:44:14

server and cannot for instance suddenly

1:44:16

SSH to this server or poke around or

1:44:19

execute any commands on your Network

1:44:21

other than MySQL so at least if the bad

1:44:24

guy takes this machine over he really

1:44:25

can't leave this uh rectangle here that

1:44:30

I've drawn so again beyond the scope of

1:44:32

things we've done in the class and even

1:44:34

though the appliance itself actually

1:44:36

does have a firewall that allows certain

1:44:37

ports in and out um all of the ones you

1:44:40

need we haven't had to fine-tune it um

1:44:42

for any of the projects realize that you

1:44:44

that even on something like a Linux

1:44:46

based operating system so in short as

1:44:48

soon as you have the happy problem of

1:44:50

having way too many users for your own

1:44:52

good lots of new problems arise even

1:44:54

though thus far we focused pretty much

1:44:56

entirely on the software side of things

1:44:58

so that is it for computer science s75

1:45:01

I'll Stick Around for questions

1:45:02

oneon-one um we still have a final

1:45:04

section tonight um for those of you who

1:45:06

would like to dive into some related

1:45:08

topics um otherwise realize that the

1:45:10

final project two um is its deadline is

1:45:14

coming up you should have gotten

1:45:15

feedback by from your TFS about project

1:45:17

one if not just drop him or her a note

1:45:19

um or me otherwise it's been a pleasure

1:45:21

having one in the class we will see you

1:45:23

online after tonight oh that's

1:45:28

okay thanks I wasn't trying to build up

1:45:31

to that there

1:45:38

so

More transcripts

Explore other videos transcribed with YouTLDR.

Get the TLDR of any YouTube video

Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.

Try YouTLDR Free