What Orbit does not promise
Orbit tries to say what each feature does not cover where you use it. This page puts those limits in one place.
One control plane
Orbit, Kubernetes' control plane and the router that receives your traffic run on the main server only.
- If the main server is lost, the console, deployments, failover and incoming traffic stop with it, and so do the applications placed there.
- That is why Orbit does not call anything high availability, even a database with replicas on other servers.
- Keep an off-server copy of
orbit backup, and backups of your databases in external storage.
More servers add room
A service runs on the server you choose and stops if that server stops; it does not move. Several instances of an application on one server handle more load, but if that server goes down they all go with it. Autoscaling adds instances on the same server.
Databases
- Data on one disk: without backups to external storage, losing a database's server loses its data.
- Failover takes time: about a minute when a server stops and about a minute and a half when it loses its network, most of it Kubernetes waiting before it declares a server lost. See the measurements.
- Asynchronous replication can lose writes: a failover can lose what the primary accepted just before it failed. A primary cut off from its replicas keeps accepting writes from applications on its own side for up to about half a minute before it stops itself, and those writes are lost.
- Synchronous replication can stop writes: it loses no committed write, but writes stop when two of the three servers are lost.
- Losing everything: rebuilding from the archive loses the writes that had not reached it, up to about a minute.
- Where it was tested: failover and recovery were measured on a three-node cluster running as containers on one machine, not yet on separate servers.
Updates
While Orbit restarts for an update, the console is unavailable for a few seconds. Your applications keep running. See Updates.
Storage
Volumes live on the server's disk, and their sizes are requested, not enforced.