This time it was a userland bug, however, not in the kernel.
Aside: There was also a status-page-only The status-page incident in Singapore on that day had the same underlying cause. (See @PeterCxy’s comment below for more details.)
Small side note: this was actually the same incident as the one in infra-log. The increased latency was caused by… duplicate wg addresses trashing one of our edges in sin rendering it mostly useless for a while
A small graphical overview of the previous month, now that it’s complete in the Log…
April 2026
SYD×2, GraphQL, dashboard, metrics, ORD, NRT
ORD, SYD, WireGuard, certs
WireGuard, SIN, dashboard, GraphQL, IAD
deploys, MPG
See the earlier March grid for a description of the annotations.
The first four days of April (corresponding to the top row) were clear of incidents, which was certainly a nice way to start things off…
The wide red mark on April 17 was the Vault certificates store (again); this is one of the few remaining services from the era of using Raft-based clusters for global metadata/configuration (as I understand it). In the longer term, there are plans for replacing it, and a note in the companion forum thread mentioned the decentralized PetSem as the probable substitute.
The wide red stroke on April 28, eleven days later, was a global failure of deploys, due to the Machines API erroneously returning an empty list when asked about existing Machines. This event slightly straddled midnight (00:00 UTC), which is why there are two bars, two outgoing links, etc.
Aside: Four incidents didn’t make it into the Infra Log, per se. (Possibly just because there was no further commentary that could be added.) In those spots, the cell in the table links either to the real-time status page’s archives or to a post in the present forum thread, depending on what else was in the air that day.
That first one briefly affected attempts to mutate secrets, but did not stop reads (which are distributed).
Addenda: There was also a forum-only incident with FRA networking on the bottom row’s day (May 6). The recent Fresh Produce on NATing outgoing IPv6 may be the de facto postmortem for that one.
In a similar vein, the following date’s (May 7) real-time status page reported relatively brief incidents in BOM and SJC, compiled here for ease of reference in the next summary grid.
Most people don’t have Cloud Hypervisor underlying their own Machines (on Fly.io); that’s only needed for GPUs and Upstash’s backstage servers. Still, the popularity of the Upstash Redis extension resulted in considerable notice in the forum…
Aside: The real-time status page also mentioned a glitch in the Grafana logs on the top row’s day (May 11) as well as a reoccurrence of Redis on May 12.
Aside2: The Oban incident may have extended several hours into the following day (May 13).
The first row was most noticed for its short yet baleful effect on SSH connection attempts, but apparently it was a problem with Consul fundamentally.
The second was remarked upon even more, due to FRA users’ commendable (and characteristic) vigilance in the forum. The Log’s retrospective account of it describes a sticky problem with Kubernetes.
The second row’s ended with a sentence on a possible future refurb of the infrastructure for logs and metrics. Fly.io has been mentioning wanting to change the underpinnings of those for a year or more, since at least Feb 2025.
In a parallel furrow, it looks like there is news about the storage side, reduced retention windows, etc., coming in the next few days.
The petsem-certs in the entry’s title is the (upcoming) Vault replacement mentioned earlier, although it wasn’t intended to be in a position to cause any real errors yet…
There are excellent write-ups in all three of these, particularly the second one, for those who have been asking where, apart from the main blog, they might learn more about the platform’s internals, etc.
See the earlier March grid for a description of the annotations.
Making the grid itself be clickable started to get a little unwieldy, so, instead, the <details> elements below can be expanded, to get each row’s links.
Week of May 03: Grafana, secrets, SIN, FRA, BOM, SJC, certs
(In the expanded tables’ second columns, “s.f.n” is status.flyio.net, the real-time status page, which serves as a second-tier source in this context.)
May followed the (lately) typical pattern of a handful of heftier boxes within an expansive speckling of relatively minor ones. The SVG pipeline that constructed the above enforces a minimum width and height, otherwise some of these would actually barely even be visible. Since there are more pixels to work with overall now, the minimums are roughly half of what they were in earlier renderings.
Of the more memorable cases…
The widely used Redis extension went down May 11–12, due to a mismatch between Linux kernel and hypervisor versions. Pathological behavior was triggered by virtualization guest log traffic.
The essential secrets and/or certificates features glitched on May 5 and May 27, although each time for only half an hour. These were the PetSem servicecodebase, including its growing pains in expanded roles.
The West Coast proxy overloads on May 28 and a bit of May 29 affected a lot of people, due to the prominence of that part of the world in things generally Internet, but fortunately the durations of those were mainly in the 2 hour range (albeit with after-shocks).
The underlying bug recounted in this first entry of June was likely also the cause of several mysterious 6PN failures in the past, where users found that .internal glitches could be fixed simply by destroying and then re-creating an unreachable Machine.