skip to content

Every machine in a reclaimable training fleet disappeared inside one minute - why does that happen, and what spreads the risk?

level: seniorimportance: should knowfreq 41%

answer

  1. not independent, correlated
  2. shape plus place equals pool
  3. one pool, one fate
  4. diversify the dimensions that define it
  5. diversity is paid for in validation

basics

~20 s

Reclamation is not an independent per-machine accident: it follows the provider's demand for one machine shape in one place, so identical machines from one capacity pool share a single fate. Spreading means several shapes and several zones, and a workload able to run on all of them.

solid answer

~50 s

A fleet of identical machines in one zone is drawn from one **capacity pool**, and that pool is a single correlated failure domain for reclamation. The trigger is not per machine - it is the provider needing that shape back in that place, so it takes it from everyone holding it at once. The fix is diversity in the dimensions the pool is defined by: several machine shapes and sizes, spread across the zones of the region, with the work distributor free to place a unit on any of them. That reduces, though it does not remove, correlation - demand for one scarce shape can span a whole region. Diversity is not free either: every extra shape is another configuration to validate, throughput per machine stops being uniform, and a synchronous job runs at the pace of its slowest member. So spread wide enough that one wave cannot empty the fleet, and no wider.

go deeper

for a junior

Recall that reclaimable machines can go away together rather than one at a time, and that running the same kind of machine in the same place makes that more likely.

for a middle

Explain the pool: shape plus place, reclaimed as a unit when the provider needs that capacity back. Name the diversity dimensions that follow from that definition.

for a senior

Show that you have priced the spread - validating each shape, uneven throughput, synchronous work advancing at its slowest member - and that you keep a guaranteed floor beneath the diversified half.

for a principal

Decide how much correlation the estate tolerates and who pays for the diversity, including the case where a scarce shape leaves no option but a larger guaranteed baseline.

## A capacity pool is a failure domain Providers do not hold one undifferentiated heap of machines. Capacity is organised by **shape** - a family weighted toward processors, memory, local disk or accelerators, at a given size - and by **place**, meaning a zone inside a region. The combination is a pool, and reclamation decisions are made against a pool: when guaranteed demand for that shape in that zone rises, the provider takes back the reclaimable machines of that shape in that zone. This is the mental model the scenario depends on. Reclamation is **not** a random per-machine event with a low probability that you can multiply out across a fleet. It is a **correlated** event whose unit is the pool. A hundred identical machines in one zone is one bet, made a hundred times, on the same outcome. ## Why the whole fleet goes at once - The trigger is **external to your workload** - someone else's demand, a large launch, a regional peak. Nothing about your job attracts or repels it. - The provider reclaims from the pool it needs, and a fleet built from one shape in one zone lives entirely inside that pool. - The demand that caused the reclamation is usually **correlated demand**: everyone reclaimed at the same moment is now looking for the same kind of machine at the same moment, which is why a wave is also the worst time to go shopping for replacements. ## What spreading actually means Diversity has to be in the dimensions the pool is defined by, or it is decoration: 1. **Several shapes.** Different families and sizes, so demand for one does not empty the fleet. This is the dimension teams skip, because it is the one that requires work. 2. **Several zones.** Different places inside the region, so a localised surge does not reach the whole fleet. Cheap to do, and it reduces correlation without removing it - a shortage of one scarce shape can span the region. 3. **A placement layer that is free to choose.** If the work distributor can only place units on one shape, having others available changes nothing. 4. **A mix with guaranteed capacity underneath**, so a total reclamation of the reclaimable half still leaves something running. | A fleet built from | Behaves as | On a reclamation wave | |---|---|---| | One shape, one zone | A single failure domain | Empties completely, in minutes | | Several shapes, one zone | Partly independent | Loses the shape in demand | | Several shapes, several zones | Several domains | Loses a slice; the rest keeps running | ## What diversity costs The interview is looking for the second half of the answer, because spreading is not free: - **Validation.** Every shape is another configuration the workload must be proven on - memory headroom, accelerator availability, throughput per machine. - **Uneven throughput.** A mixed fleet does not produce work at a uniform rate, so anything that assumes equal machines - static sharding of work, per-machine batch sizes - has to become dynamic. - **Synchronous work suffers most.** A job whose members exchange state at every step advances at the pace of its slowest member, so a slower shape slows everyone, and losing one member stalls the rest until it is replaced. That is an argument for making the work **asynchronous or elastic**, not an argument against diversity. - **Operational surface.** More shapes means more configuration to keep current and more ways for one of them to be quietly broken. ## Where spreading does not help Be honest about the limits. If the workload can only run on one scarce shape - it needs a specific accelerator, or a memory size only one family offers - diversity across shapes is not available, and the answer becomes a larger guaranteed baseline instead. If every unit of work is so long that a restart costs hours, spreading reduces how often you are hit but not what each hit costs; that is a checkpointing problem, not a placement one. And if the fleet's coordinating component sits in the pool too, spreading the workers is beside the point: the wave still stops everything. ## What interviewers listen for The telling moment is whether the candidate treats reclamation as independent random failure or as a correlated event with an external trigger. Everything else follows from that: a candidate holding the correlated model reaches for shape and zone diversity, a floor of guaranteed capacity and elastic work distribution, and they price the diversity honestly rather than presenting it as free.

  • The workload needs one specific accelerator shape that only one family offers. What now?
    Shape diversity is off the table, so the remaining levers are place and posture: spread across zones, and raise the guaranteed baseline until the work that must proceed can proceed without any reclaimable capacity at all. Also shorten the checkpoint interval, since you will be hit as a fleet rather than machine by machine.
  • Does spreading across zones increase any other cost?
    It can. Traffic between zones is charged on a different schedule than traffic inside one, so a fleet that exchanges a lot of state across zone boundaries pays for the spread on the transfer line rather than the compute line. For chatty synchronous work that is a real trade; for independent work units it is usually negligible.
  • How would you tell in advance that your fleet is one correlated domain?
    Inventory it along the two dimensions that define a pool - shape and zone - rather than by machine count. If one cell holds most of the fleet, that is the domain, whatever the total looks like. Reclamation history per cell over a few weeks turns the inventory into an estimate of how often that cell empties.

saying these in an interview costs you the question

  • Believes reclamation hits individual machines independently at random
  • Counts a fleet as spread because it is large, not because it is varied
  • Assumes zone spread alone covers a shape-wide reclamation wave
  • Presents shape diversity as free, ignoring validation and uneven throughput
  • Keeps a synchronous job on a mixed fleet without making it elastic