Scenario
You are operating a production observability platform. The following symptoms appear:
- Logs from different services have wrong ordering
Available evidence:
- Trace spans appear out of order
Your task
Determine the cause, recover, document, and validate.
Investigation
The investigation follows the discipline taught in Part XCVIII:
- Form hypothesis, find evidence, test, validate.
- Use the available evidence above to bound the search.
- Reach one of the likely root causes.
Recovery procedure
(Do not reveal until you have reasoned through the problem.)
- Identify the failing component.
- Apply the remediation pathway.
- Validate with the verification step.
- Document the incident.
Remediation
- Verify NTP. 2. Force a chrony step. 3. Validate.
Verification
Clocks are in sync; spans order correctly.
Rollback
Revert
Prevention
chrony / systemd-timesyncd alerts on NTP offset