Reliability

Built for the night everything else breaks.

A pager is only worth anything when your own systems are failing. So Transmit keeps its timers in the database, runs somewhere your apps probably don’t, and is watched from outside its own cloud.

Postgres decides. Jobs only act.

Every escalation step and every page is a job written in the same database transaction as the change that caused it. If the alert is stored, its first page is stored with it. Nothing waits only in memory, so a crash or a deploy loses nothing.

  1. An alert arrives.One transaction opens the incident and queues step 1.
  2. Step 1 runs.It locks the incident and re-reads it. Already acknowledged? It does nothing.
  3. It pages and schedules step 2,in one transaction, so there is never a page without the next step, or the reverse.
  4. Someone acknowledges.Nothing is cancelled anywhere: pending jobs see the new status and stop.

More of how it holds up

A page goes out once

The database refuses a second copy of the same page to the same person for the same step. A job that runs twice finds the page already queued and moves on.

Due now means now

A step that is due runs immediately rather than waiting for a scheduler pass; a test fails the build if that ever changes.

Always on

The worker that fires escalation timers runs on an instance that is never scaled down, so a step due at 3:02 pages at 3:02, not whenever the next request wakes something up.

An outside watchdog

A small program on a different provider from Transmit itself checks the API, the worker and the dashboard every minute and emails the team if any is down. Transmit watches the watchdog back with one of its own heartbeats. Uptime checks also run from four regions.

Tested where pagers usually break.

Anything that does arithmetic on time (rotations, restrictions, daylight-saving changes, escalation offsets, heartbeat deadlines) is checked with property tests at ten thousand cases each, before every deploy. Everything between an alert and the email provider runs for real against Postgres in tests.

What we do not have yet

  • A second region. Transmit runs in one region today.
  • A public status page.
  • SMS and voice calls, so a page that has to wake someone depends on email for now.

We would rather say so here than have you find out at 3am.

Move before the deadline, not on it.

Transmit is in early access. Tell us about your on-call setup, and we will help you import it and check it against Opsgenie before you switch.