SlideShare a Scribd company logo
Flexible Paxos:
Reaching agreement
without majorities
Heidi Howard, Dahlia Malkhi, Alexander Spiegelman
University of Cambridge, VMware Research, Technion
heidi.howard@cl.cam.ac.uk
@heidiann360
hh360.user.srcf.net
fpaxos.github.io
1
2
3
TL;DR Majorities are not necessary to safety reach
distributed consensus.
4
Aims
1. Understand the widely adopted Paxos algorithm
and how Flexible Paxos safely generalizes it
2. Introduce a broad spectrum of possibilities for
reaching consensus and
3. Promote the idea that Paxos is not the best point
on this spectrum for most practical systems
5
Defining Consensus
Reaching agreement in an asynchronous distributed
system in the face of crash failures.
More specifically:
• Compromising safety is never an option
• No clock synchronization is assumed
• Participants fail by crashing and messages may be
lost but neither can act arbitrarily
6
Consensus is not a solved
problem
• Consensus is not scalable - often limited to 3, 5 or 7
participants.
• Consensus is slow - each decision requires at least
majority agreement, more when failures occur.
• Consensus is not available - cannot handle majority
failures or many network partitions.
You pay a high price even if no failures occur. Consider by
many as “best avoided”
7
Back in the good old days
…
8
Single server system
Client
Client
Client
Server
9
Single server system
Client
Client
Client
Server
Append
10
Single server system
Client
Client
Client
Server
OK @ 4
11
Single server system
Client
Client
Client
ServerRead 4
12
Single server system
Client
Client
Client
Server
13
Single server system
Client
Client
Client
Server
14
Single server system
Client
Client
Client
Server
15
Distributed systems
came to the rescue
16
Replicate for availability
Client
Client
Client
Server
Server
Server
17
Replicate for availability
Client
Client
Client
Leader
Server
Server
Append
18
Replicate for availability
Client
Client
Client
Leader
Server
Server
19
Replicate for availability
Client
Client
Client
Leader
Server
Server
OK
OK
20
Replicate for availability
Client
Client
Client
Leader
Server
Server
OK
21
How many copies is
enough?
We refer to any group of nodes which is ‘enough’ as a
replication quorum
More copies,
More resilient
Fewer copies,
Faster replication
22
Now what happens when a
server fails?
23
Client
Client
Client
Leader
Server
Server
24
Client
Client
Client
Leader
Server
Server
Append
25
Client
Client
Client
Leader
Server
Server
26
Client
Client
Client
Leader
Server
Server
27
OK
OK
What happens when the
leader fails?
28
Client
Client
Client
Leader
Server
Server
29
Client
Client
Client
Leader
Server
Leader
30
Recall that we never
compromise safety
Thus the new leader has two jobs:
1. To stop the old leader. We cannot say for sure that
they have failed.
2. To learn about which log entries have already
been agreed and not overwrite them.
The order is important here!
31
How to stop past leaders?
They may come back to haunt us.
• Ask them to stop
• Use leases and wait for them to expire
• Ignore them by having nodes promise to stop
replicating for them
32
How many promises are
enough?
Leaders cannot wait forever.
We need a minimum of one node from each
replication quorum to promise not to replicate new
entries.
We refer to this as the leader election quorum.
33
Promises are tricky to safely
break
Let’s assume each leadership term has a unique term
number.
Problem: We don’t always know who the past
leaders are. We need a deterministic scheme for
breaking promises.
Solution: Each node stores the promise as “ignore
all smaller terms”.
34
Learn all committed entries
The new leader must never overwrite committed
entries.
It must learn about the committed entries before it
starts adding new entries without leaving holes.
35
Safely handle in-progress
commands
Any in-progress entries already replicated on the
leader election quorum nodes must be finished by
the new leader.
If there are conflicting in-progress entries from
different leaders, we choose the log entry with the
highest view.
36
Context
This mechanism of views and promises is widely
utilised. This core idea is commonly referred to as
Paxos.
It’s a recurring foundation in the literature:
Viewstamped Replication [PODC’88], Paxos
[TOCS’98], Zab/Zookeeper [ATC’10] and Raft
[ATC’14] and many more.
37
What’s changed?
Traditionally, it was thought that all quorums needed
to intersect, regardless of whether the quorum was
used for replication or leader election.
Majorities are the widely adopted approach to this.
We have just seen that the only requirement is that
leader election quorums intersect with replication
quorums.
38
Implications
In theory:
• Helps us to understand Paxos
• Generalisation & weakening of the requirements
• Orthogonal to any particular algorithm built upon Paxos
In practice:
• Many new quorum schemes now become feasible
• Introduces a new breed of scalable, resilient consensus
algorithms.
39
Quorums Systems
40
Majorities
Replication quorum Leader election quorum
41
Majorities - 1
Replication quorum Leader election quorum
42
Counting
Replication quorum + Leader election quorum =
Number of nodes + 1
More copies,
More resilient
Fewer copies,
Faster replication
43
Replication quorum = 2/6
Replication quorum Leader election quorum
44
Replication quorum = 3/8
Replication quorum Leader election quorum
45
Not all members were
created equal
• Machines and the networks which connect them
are heterogeneous
• Failures are not independent: members are more
likely to simultaneously fail if they are located in the
same host, rack or even datacenter
46
Groups
Replication quorum Leader election quorum
47
Grids
Replication quorum Leader election quorum
48
Any many more…
Weighed Voting
2
2
3
3
1
1
Grid Paths
Combined Schemes Hierarchy
49
Majorities are no longer
‘one size fits all’
Majorities are unlikely to be optimal for most practical
systems
• Requirements of real systems differ. Performance
really matters.
• Leader election is rare so often we optimize for the
common replication phase.
50
Summary
• The only quorum intersection requirement is that
leader election quorums must intersect with the
replication quorums.
• Majorities are not the only option for safely reaching
consensus and are often not best suited to
practical systems.
• Don’t give up on strong consistency guarantees.
Distributed consensus can be performant and
scalable.
51
Ongoing Work
• Adoption into existing production systems
• Building new algorithms offering interesting
compromises
• Practical analysis of quorum systems for
consensus
• Extending to other algorithms and different failures
models e.g. Flexible Fast Paxos and Flexible
Byzantine Paxos
52
Question?
Let’s continue the discussion:
Heidi Howard
heidi.howard@cl.cam.ac.uk
@heidiann360
53

More Related Content

PDF
Distributed Consensus: Making Impossible Possible [Revised]
Heidi Howard
 
PDF
Reaching reliable agreement in an unreliable world
Heidi Howard
 
PDF
Distributed Consensus: Making Impossible Possible
Heidi Howard
 
PPTX
Formal analysis-crypto-proto
Dr. Jayaraj Poroor
 
PDF
图解分布式一致性协议Paxos 20150311
Cabin WJ
 
PDF
Paxos building-reliable-system
Yanpo Zhang
 
PPS
the Paxos Commit algorithm
paolos84
 
PPTX
Understanding Consensus Mechanisms in Blockchain: Proof of Work, Proof of Sta...
NAtional Institute of TEchnology Rourkela , Galgotias University
 
Distributed Consensus: Making Impossible Possible [Revised]
Heidi Howard
 
Reaching reliable agreement in an unreliable world
Heidi Howard
 
Distributed Consensus: Making Impossible Possible
Heidi Howard
 
Formal analysis-crypto-proto
Dr. Jayaraj Poroor
 
图解分布式一致性协议Paxos 20150311
Cabin WJ
 
Paxos building-reliable-system
Yanpo Zhang
 
the Paxos Commit algorithm
paolos84
 
Understanding Consensus Mechanisms in Blockchain: Proof of Work, Proof of Sta...
NAtional Institute of TEchnology Rourkela , Galgotias University
 

Similar to Flexible Paxos: Reaching agreement without majorities (20)

PPTX
Blockchain consensus algorithms
Anurag Dashputre
 
PDF
Hyperchains
Grzegorz Uriasz
 
PDF
Building Reactive Scalable Systems
Knoldus Inc.
 
PPTX
Operating system 27 semaphores
Vaibhav Khanna
 
ODP
Everything you always wanted to know about Distributed databases, at devoxx l...
javier ramirez
 
PDF
How to Build Your Blockchain Project with Chainstack
Chainstack
 
PPTX
distributed_systems_introduction_chapter_1.pptx
ShadyAmgad4
 
PPT
Sh ch01
Jeylani Islaaw
 
PPT
Lecture_8.ppt
adil104135
 
PDF
DDB_lec_05_Concurrency_Control.pdf
AhmedImmamImmam
 
PDF
Distributed computing for new bloods
Raymond Tay
 
PDF
Consensus Algorithms: An Introduction & Analysis
Zak Cole
 
PDF
Distributed Systems Theory for Mere Mortals - GeeCON Krakow May 2017
Ensar Basri Kahveci
 
PPS
CS101- Introduction to Computing- Lecture 45
Bilal Ahmed
 
PPTX
Principles of Secure Design and its componetnts
AssadLeo1
 
PPT
Encryption and some other information and
AssadLeo1
 
PPT
Indirect communication is defined as communication between entities in a dist...
nandepovanhu
 
PDF
Distributed Systems Theory for Mere Mortals - Java Day Istanbul May 2017
Ensar Basri Kahveci
 
PPTX
Distributed Systems (3rd Edition)Introduction
saadabinibrahim
 
PPTX
Introduction
Mohamed Diallo
 
Blockchain consensus algorithms
Anurag Dashputre
 
Hyperchains
Grzegorz Uriasz
 
Building Reactive Scalable Systems
Knoldus Inc.
 
Operating system 27 semaphores
Vaibhav Khanna
 
Everything you always wanted to know about Distributed databases, at devoxx l...
javier ramirez
 
How to Build Your Blockchain Project with Chainstack
Chainstack
 
distributed_systems_introduction_chapter_1.pptx
ShadyAmgad4
 
Lecture_8.ppt
adil104135
 
DDB_lec_05_Concurrency_Control.pdf
AhmedImmamImmam
 
Distributed computing for new bloods
Raymond Tay
 
Consensus Algorithms: An Introduction & Analysis
Zak Cole
 
Distributed Systems Theory for Mere Mortals - GeeCON Krakow May 2017
Ensar Basri Kahveci
 
CS101- Introduction to Computing- Lecture 45
Bilal Ahmed
 
Principles of Secure Design and its componetnts
AssadLeo1
 
Encryption and some other information and
AssadLeo1
 
Indirect communication is defined as communication between entities in a dist...
nandepovanhu
 
Distributed Systems Theory for Mere Mortals - Java Day Istanbul May 2017
Ensar Basri Kahveci
 
Distributed Systems (3rd Edition)Introduction
saadabinibrahim
 
Introduction
Mohamed Diallo
 
Ad

Recently uploaded (20)

PDF
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
Captain IT
 
DOCX
Top AI API Alternatives to OpenAI: A Side-by-Side Breakdown
vilush
 
PDF
This slide provides an overview Technology
mineshkharadi333
 
PDF
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
PDF
Google’s NotebookLM Unveils Video Overviews
SOFTTECHHUB
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PDF
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
PDF
Why Your AI & Cybersecurity Hiring Still Misses the Mark in 2025
Virtual Employee Pvt. Ltd.
 
PDF
CIFDAQ's Teaching Thursday: Moving Averages Made Simple
CIFDAQ
 
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
AVTRON Technologies LLC
 
PPTX
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira Júnior
 
PDF
Enable Enterprise-Ready Security on IBM i Systems.pdf
Precisely
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PPTX
C Programming Basics concept krnppt.pptx
Karan Prajapat
 
PDF
CIFDAQ'S Market Insight: BTC to ETH money in motion
CIFDAQ
 
PDF
A Day in the Life of Location Data - Turning Where into How.pdf
Precisely
 
PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PDF
DevOps & Developer Experience Summer BBQ
AUGNYC
 
PDF
Software Development Company | KodekX
KodekX
 
How Onsite IT Support Drives Business Efficiency, Security, and Growth.pdf
Captain IT
 
Top AI API Alternatives to OpenAI: A Side-by-Side Breakdown
vilush
 
This slide provides an overview Technology
mineshkharadi333
 
Using Anchore and DefectDojo to Stand Up Your DevSecOps Function
Anchore
 
Google’s NotebookLM Unveils Video Overviews
SOFTTECHHUB
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
Why Your AI & Cybersecurity Hiring Still Misses the Mark in 2025
Virtual Employee Pvt. Ltd.
 
CIFDAQ's Teaching Thursday: Moving Averages Made Simple
CIFDAQ
 
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
AVTRON Technologies LLC
 
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira Júnior
 
Enable Enterprise-Ready Security on IBM i Systems.pdf
Precisely
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
C Programming Basics concept krnppt.pptx
Karan Prajapat
 
CIFDAQ'S Market Insight: BTC to ETH money in motion
CIFDAQ
 
A Day in the Life of Location Data - Turning Where into How.pdf
Precisely
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
DevOps & Developer Experience Summer BBQ
AUGNYC
 
Software Development Company | KodekX
KodekX
 
Ad

Flexible Paxos: Reaching agreement without majorities