内核 多活生存性 —— 丢一个 region 业务不中断
- 一句话
- 默认可串行化 + 按 range 的 Raft 复制 + geo-partitioning——region 级故障下业务零中断,数据可按法规钉在指定地域;Netflix 380+ 集群在跑,是本批最硬的生产证据之一。Serializable-by-default + per-range Raft replication + geo-partitioning — the business survives a region-level outage with zero interruption, and data can be pinned to jurisdictions for compliance; Netflix runs 380+ clusters on it, the hardest production evidence in this batch.
- 窄场景
- 全球化在线业务(设备管理、支付、SaaS 控制面),要求"任何一个云 region 整体挂掉,服务不降级";有数据主权合规要求(欧盟数据不出欧盟)。Global online businesses (device management, payments, SaaS control planes) demanding "any cloud region going down entirely must not degrade service"; data-sovereignty compliance requirements (EU data stays in the EU).
- 机制
- 数据按 key range 切分,每个 range 经 Raft 在多地域多副本同步复制;默认隔离级别就是可串行化(serializable),不需要用户显式选择;geo-partitioning 允许行级指定数据归属地域(如欧盟用户行只落在欧盟节点),在"全球复制求生"与"合规钉住数据"之间按表/行精细调配。代价是写要跨地域走 Raft 共识(见[避坑]卡)。Data is split into ranges by key, each range synchronously replicated across regions via Raft; the default isolation level is serializable — no user opt-in needed; geo-partitioning pins data to regions at row granularity (EU user rows land only on EU nodes), finely balancing "replicate globally to survive" against "pin data for compliance". The price is cross-region Raft consensus on writes (see the [Pitfall] card).
- 生产验证
- Netflix(厂商案例集):380+ 集群、160+ 生产集群、60+ 多 region 集群;设备管理平台(数百种设备的接入与事件处理)在其上运行;最大单集群 60 节点、26.5TB;Netflix 数据平台团队有持续公开技术博客佐证(https://cdn.featuredcustomers.com/CustomerCaseStudy.document/CockroachLabs-NETFLIX-Case-Study.pdf)。Storj:2019 年从 PG 迁移,对象存储元数据 51 亿行、5.5TB,3 大洲 9 region 部署(https://cockroachlabs-www-prod.netlify.app/pdf/CockroachLabs-STORJ-Case-Study.pdf)。诚实标注:数字来自厂商发布的案例材料,未独立复现。Netflix (vendor-published case study): 380+ clusters, 160+ production clusters, 60+ multi-region clusters; its device-management platform (onboarding and event processing for hundreds of device types) runs on it; the largest single cluster is 60 nodes and 26.5TB; Netflix's data platform team keeps a public technical blog corroborating usage (https://cdn.featuredcustomers.com/CustomerCaseStudy.document/CockroachLabs-NETFLIX-Case-Study.pdf). Storj: migrated from PG in 2019; object-storage metadata at 5.1 billion rows / 5.5TB, deployed across 9 regions on 3 continents (https://cockroachlabs-www-prod.netlify.app/pdf/CockroachLabs-STORJ-Case-Study.pdf). Honest note: the figures come from vendor-published case materials, not independently reproduced.
- 竞品差距
- TiDB 多 AZ 强一致、跨洲多活语义与 geo-partitioning 精细度弱;YugabyteDB xCluster 异步双活有 RPO;Aurora Global 跨区异步复制 RPO 非零;Spanner 同级但贵一个数量级且 GCP 专属。"开源/多云可部署 + 同步多活 + PG 线路兼容"三者兼得,31 款只有 CockroachDB。TiDB does multi-AZ strong consistency but is weaker on cross-continent multi-active semantics and geo-partitioning granularity; YugabyteDB xCluster is async active-active with non-zero RPO; Aurora Global replicates across regions asynchronously, also with non-zero RPO; Spanner is same-tier but an order of magnitude more expensive and GCP-exclusive. "Open-source/multi-cloud deployable + synchronous multi-active + PG wire compatibility" combined exists only in CockroachDB among the 31.
- 证据等级
- 具名大厂生产(厂商案例集,数字未独立复现)+ 持续公开技术博客(Netflix)Named big-vendor production (vendor case studies; figures not independently reproduced) + ongoing public technical blog (Netflix)
- 最后核验
- 2026-10-012026-10-01