CAP Theorem Partition Choice Lab (Interactive)
Cut the transatlantic link and choose: reject writes like CP, or serve stale reads like AP. Two geo-replicated nodes, one partition switch. Measure rejected writes, stale reads, and merged versions to see why C, A, and P are a pick-two under failure.
CAP Partition Trade-off Lab
Cut the fiber between US-East (2 nodes) and EU-West (1 node), then force writes and reads. P is mandatory — you only choose CP or AP.
With the split active, EU-West cannot reach the 2/3 quorum, so it returns errors instead of touching data it cannot verify. Zero stale reads, zero uptime on the minority side — Spanner, ZooKeeper, and etcd all behave this way.
- → Cluster healthy. All replicas hold cart-v0 (version 0).
How It Works Under the Hood
CAP says a replicated system can guarantee consistency and availability only while the network cooperates; when a partition splits the datacenters, every subsequent request forces a choice — refuse service to protect a single history (CP), or answer from local state and let replicas diverge (AP). This lab makes that moment concrete: writes against a minority zone either 503 or commit locally, reads either error or return stale versions, and healing triggers a merge you must resolve. It also exposes the everyday truth: partitions are rare, so your chosen letter defines normal-operation behavior too.
Core Architectural Principles
- Partition toggle forces every request through the CP-or-AP decision point.
- CP mode counts 503 rejections and frozen reads; AP mode counts stale reads served.
- Healing the link surfaces divergent versions that must be merged or LWW-resolved.
State plainly that under partition you choose CP or AP, but note you do not abandon consistency when healthy: “we pick AP for the feed but still converge via CRDTs.” Mention Gilbert–Lynch’s formal definitions and avoid the wrong claim that CAP means dropping either letter on a good day.
CP buys one truth at the price of minority-side downtime; AP buys uptime at the price of conflicts you must resolve later.