Contents

Architecture & System Design › Distributed Systems

Heartbeat

Periodic "I'm alive" signals used to detect failed nodes.

Also known as: heartbeat, heartbeats, liveness signal

A heartbeat is a periodic “I’m alive” signal: processes, replicas and devices emit them; watchers declare death after silence exceeds a threshold. Load balancers, cluster managers, leader leases and presence systems all run on heartbeats — liveness inferred from continued arrival.

beat…beat…beat…(silence > timeout)… → presumed dead → failover/replace

The threshold trades detection speed against false positives: tight timeouts fail over fast and flap on every GC pause; loose ones ride out blips while users wait. Adaptive thresholds (phi-accrual, suspicion levels) split the difference by modelling arrival distribution instead of fixed cutoffs.

The classic mistakes:

  • Fixed aggressive timeouts. Declaring death after one missed beat turns every pause into failover churn. Timeouts must exceed worst-case pauses (GC, network blips, deploys).
  • Heartbeats on the data path. Sharing fate with traffic means congestion kills liveness signals first — exactly when accurate detection matters. Separate control channels where feasible.
  • No authentication. Spoofed or replayed heartbeats keep dead nodes “alive” or kill live ones. Sign liveness traffic.
  • Cascading failure detection. A slow detector triggering mass failover (thundering herd to standbys) converts one failure into many. Damp detection (hold-downs, staged failover).
  • Confusing silence with death. Partitioned-but-alive nodes keep beating unheard; fencing (not just detection) prevents their continued action.
  • Missing heartbeats as the only signal. Complement with active probes and application-level checks — a beating process can still serve errors.
  • Unmonitored monitor. The watcher itself failing silently freezes all detection. Watch the watchers (quorum, mutual checks).

How to tune it: thresholds from measured pause distributions, suspicion before conviction, fencing after detection, watchers watched. Liveness is inference — engineer its uncertainty explicitly.