TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Auth0 Has been down for almost 4 hours now

195 点作者 inssein大约 4 年前
Seems I can't link to the incident (gets marked as a deadlink), but here it is: https://status.auth0.com/incidents/zvjzyc7912g5?u=3qykby4vypfp

16 条评论

UglyToad大约 4 年前
So I&#x27;ve been mulling this stupid thought for a while (and disclaimer that it&#x27;s extremely useful for these outage stories to make it to the front-page to help everyone who is getting paged with p1s out).<p>But, does it really matter?<p>I read people reacting strongly to these outages, suggesting that due dilligence wasn&#x27;t done to use a 3rd party for this or that. Or that a system engineered to reach anything less than 100% uptime is professional negligence.<p>However from the top of my head we&#x27;ve had AWS outages, Gmail outages, Azure outages, DNS outages, GitHub outages, whatever else. All these hugely profitable companies are messing this stuff up constantly. Why are any of us going to do any better and why does a few hours of downtime ultimately matter?<p>I think it&#x27;s partly living somewhere where a volcano the next island over can shut down connections to the outside world for almost a week. Life doesn&#x27;t have an SLA, systems should aim for reasonable uptime but at the end of the day the systems come back online at some point and we all move on. Just catch up on emails or something. I dislike the culture of demanding hyper perfection and that we should be prepared to do unhealthy shift patterns to avoid a moment of downtime in UTC - 11 or something.<p>My view is increasingly these outages are healthy since they force us to confront the fallibility of the systems we build and accept the chaos wins out in the end, even if just for a few hours.
评论 #26882376 未加载
评论 #26882248 未加载
评论 #26882114 未加载
评论 #26882504 未加载
评论 #26882510 未加载
评论 #26882537 未加载
评论 #26882387 未加载
评论 #26882357 未加载
评论 #26882559 未加载
评论 #26882964 未加载
评论 #26882316 未加载
评论 #26882618 未加载
评论 #26883110 未加载
评论 #26884205 未加载
评论 #26882517 未加载
评论 #26882489 未加载
评论 #26886249 未加载
评论 #26882582 未加载
评论 #26882112 未加载
评论 #26882144 未加载
评论 #26884434 未加载
slackerIII大约 4 年前
Huh, that&#x27;s interesting timing. I co-host a podcast that walks through notable outages, and just yesterday we released an episode about Auth0&#x27;s 2018 outage: <a href="https:&#x2F;&#x2F;downtimeproject.com&#x2F;podcast&#x2F;auth0-silently-loses-some-indexes&#x2F;" rel="nofollow">https:&#x2F;&#x2F;downtimeproject.com&#x2F;podcast&#x2F;auth0-silently-loses-som...</a><p>Last time was due to several factors, but initially because of silently losing some indexes during a migration. I&#x27;m very curious what happened this time -- we&#x27;ll definitely do a followup episode if they publish a postmortem.
评论 #26881636 未加载
评论 #26881507 未加载
评论 #26884347 未加载
ryandvm大约 4 年前
Not going to lie, of all the things to farm out to a 3rd party, auth&#x2F;users always struck me as the dumbest.
评论 #26881710 未加载
评论 #26882133 未加载
评论 #26881556 未加载
评论 #26898926 未加载
评论 #26882154 未加载
评论 #26882806 未加载
romanhotsiy大约 4 年前
Previous discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26876287" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26876287</a>
评论 #26881216 未加载
gjsman-1000大约 4 年前
I literally, today, had a demo of SSO for my organization and was panicking over what went wrong when it wasn&#x27;t working, so I had to skip it.
评论 #26882919 未加载
评论 #26949065 未加载
Jack000大约 4 年前
Auth0&#x27;s pricing has always seemed really strange - 7000 active users for free but only 1000 on the lowest paid tier ($23&#x2F;month). This means if you don&#x27;t care about the extra features, once you exceed 7k you need to jump up to the $228&#x2F;month plan.
okhuman大约 4 年前
wrote <a href="https:&#x2F;&#x2F;github.com&#x2F;pmprosociety&#x2F;authcompanion" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;pmprosociety&#x2F;authcompanion</a> to try and bring auth back on-prem.
trog大约 4 年前
My first Auth0 experience was a couple weeks ago when I had a quick crack at testing it out to see if it would be a suitable candidate to migrate a bunch of WordPress sites (currently all with their own separate, individual user accounts) onto.<p>I didn&#x27;t spend a lot of time on it but initially figured it would be easy because they had what seemed to be a well-written and comprehensive blog post[1] on the topic, as well as a native plugin.<p>But I found a few small discrepancies with the blog post and the current state of the plugin (perhaps not too surprising; the blog post is 2 years old now and no doubt the plugin has gone through several updates).<p>I found the auth0 control panel overwhelming at a glance and didn&#x27;t want to spend the time to figure it all out - basically laziness won here, but I feel like they missed an opportunity to get a customer if they&#x27;d managed to make this much more low effort.<p>I moved on to something else (had much better luck with OneLogin out of the box!), but then got six separate emails over the next couple weeks from a sales rep asking if I had any questions.<p>I&#x27;m sure it&#x27;s a neat piece of kit in the right hands or with a little more elbow grease but I was a bit disappointed with how much effort it was to get up and running for [what I thought was] a pretty basic use case.<p>1. <a href="https:&#x2F;&#x2F;auth0.com&#x2F;blog&#x2F;wordpress-sso-with-auth0&#x2F;" rel="nofollow">https:&#x2F;&#x2F;auth0.com&#x2F;blog&#x2F;wordpress-sso-with-auth0&#x2F;</a>
aleyan大约 4 年前
Is it worthwhile to do authentication via SaaS instead of a local library?<p>For password use case, it seems nice that you don&#x27;t have to store client secrets (eg encrypted salted passwords) on your own infra. However now instead of authentication happening between your own servers and the users browser, there is an additional hop to the SaaS and now you need to learn about JWT etc. At my previous company, moving a Django monolith to do authentication via auth0 was a multi month project and a multi thousand line increase in code&#x2F;complexity. And we weren&#x27;t storing passwords to begin with because we were using onetime login emails links.<p>Maybe SaaS platforms are worth it for social login? I haven&#x27;t tried that, but I am not convinced that auth0 or some one else can help me connect with facebook&#x2F;twitter&#x2F;google better than a library can.
评论 #26882438 未加载
评论 #26882991 未加载
keithnz大约 4 年前
Out of interest, what are peoples experience like with self hosted identity management options? I&#x27;ve been evaluating keycloak recently, and it seems pretty good.
评论 #26882714 未加载
评论 #26882702 未加载
评论 #26889374 未加载
pdx6大约 4 年前
The Auth0 team is probably distracted by their Okta onboarding. When I was onboarding at Okta after they bought the startup I was working at, I had to support both systems to bring myself up to speed fast -- and that caused some outages from double on call.
评论 #26882876 未加载
评论 #26883832 未加载
inssein大约 4 年前
Link: <a href="https:&#x2F;&#x2F;status.auth0.com&#x2F;incidents&#x2F;zvjzyc7912g5?u=3qykby4vypfp" rel="nofollow">https:&#x2F;&#x2F;status.auth0.com&#x2F;incidents&#x2F;zvjzyc7912g5?u=3qykby4vyp...</a>
coopreme大约 4 年前
How does Auth0 compare to keycloak? Is it similar?
twistedpair大约 4 年前
Final RCA: <a href="https:&#x2F;&#x2F;cdn.auth0.com&#x2F;blog&#x2F;Detailed_Root_Cause_Analysis_(RCA)_4-2021.pdf" rel="nofollow">https:&#x2F;&#x2F;cdn.auth0.com&#x2F;blog&#x2F;Detailed_Root_Cause_Analysis_(RCA...</a><p>TL;DR feature flag service was to blame
mattbnr32大约 4 年前
just successfully authenticated a few times
f430大约 4 年前
isn&#x27;t the whole purpose of using Auth0 so that this stuff never happens?
评论 #26882365 未加载