Check settings
Design failover
1
Define health precisely
Probe a path or port that reflects whether the endpoint can serve real traffic, not merely whether a process accepts a socket.
2
Mark primary and backup records
Set per-record backup metadata and use a picker chain that prefers eligible primary values.
3
Choose TTL and timing
Resolver caches can retain a previously healthy answer until its TTL expires. Set TTL, frequency, and timeout from the recovery objective and expected transient failures.
4
Test failure and recovery
Fail a staging endpoint, query multiple times through a resolver, and confirm it leaves and later rejoins the eligible set.