Lune

SOSP2026Top-tier venue

RPCS hield : Defending Microservices Against Cascading Failures

Milind Chabbi, Sonal Mahajan, Ivan Beschastnikh, René Just, Yuxin Wang, Yufan Xu, Elton Pinto, Seemanta Saha, Manu Sridharan, Abhishek Jha, Sandeep Koushik Sheshadri, Mayank Bansal

2026Year

Abstract

Microservice-based systems are tightly interdependent. A failure in one service can propagate to a dependent service, potentially bringing down critical, user-facing functionality. We have developed and deployed RPCShield, a suite of program analyses for Go and Java that detects such cascading-failure risks. RPCShield uses static program analysis to track error and exception propagation through service code. Two insights make this practical. First, error propagation needs to be only checked per service, so the analysis is intra-service and avoids inter-service analysis entirely. Second, deciding the property counterfactually, by asking whether an endpoint could have succeeded had a given call succeeded, attributes the failure to the specific responsible dependency rather than to every dependency whose error reaches the caller. We have deployed RPCShield at Uber, across a fleet of over 6K microservices. Since deployment, it has detected over 3,800 cascading failure risks, of which service owners have already remediated more than 1,300. Manual review indicates that RPCShield has a false positive rate of around 5%.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get c0c9c27c-406b-490e-8ee9-ddfb153d73a9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines