Documentation contents

Worker consensus

Updated

Why one measurement proves nothing, and what turns many of them into a verdict.

Every published verdict is built from measurements taken by machines this platform does not control, run by people it has never met. Consensus is what makes that trustworthy rather than merely optimistic.

A measurement is about a path

When a worker pings an address, it learns about the route between itself and that address. That is all.

If the worker's own ISP is having a bad morning, it sees "unreachable" for a provider that is perfectly healthy for everybody else. A worker in the same datacentre as the target sees "healthy" right through a global routing outage. Neither is lying; both are reporting a path, and a path is not a provider.

So no single measurement, from any worker, however trustworthy, is ever published as a verdict.

What consensus adds

Three things, and they are different from each other:

  • Redundancy. Many measurements of the same target, so one odd result does not decide anything.
  • Diversity. Measurements from different networks and different places, so the failure of any one path is visible as one path failing.
  • Attribution. Every result is signed by the worker that produced it, so a worker whose results are consistently at odds with everybody else's is identifiable rather than anonymous noise.

Agreement is not unanimity

Workers disagreeing is normal and informative. The internet is not the same from everywhere, and a provider genuinely unreachable from one country and fine from three others produces exactly the disagreement you would expect. That is why disagreement is resolved per region before it is resolved globally: the regional answer is often the interesting one.

When there is no consensus

Sometimes the honest answer is that nobody knows yet. Too few workers, too few independent networks, or genuine disagreement that does not resolve produces not enough data, which is published as such.

This state is deliberately not a middle colour between healthy and outage. It is not a weak "healthy" and it is not a mild "outage": it is the absence of a verdict, and it is drawn as one.

Why this design and not self-reporting

The alternative to consensus among strangers is asking providers how they are doing. That is cheaper, more precise, and worth nothing: a provider's own status page is the last thing to report an outage, because the systems that would report it are the ones that are down, and because nobody publishes bad news about themselves quickly.

Was this page helpful?

Your answer tells us which pages need rewriting.