Chaos Engineering Toolkit
Overview
Execute controlled chaos engineering experiments to test system resilience, fault tolerance, and recovery capabilities. Injects failures including network latency, service crashes, resource exhaustion, and dependency outages to verify that systems degrade gracefully and recover automatically.
Prerequisites
- Distributed system or microservice architecture deployed in a staging/test environment
- Monitoring and alerting configured (Grafana, Datadog, CloudWatch, or Prometheus)
- Rollback capability for the target environment (manual or automated)
- Chaos engineering tool installed (toxiproxy, Pumba, Litmus, or Chaos Mesh)
- Explicit approval from the team to run chaos experiments
- Steady-state hypothesis defined (what "healthy" looks like in metrics)
Instructions
- Define the steady-state hypothesis:
- Identify measurable indicators of normal system behavior (e.g., p99 latency < 500ms, error rate < 0.1%, all health checks pass).
- Record baseline metrics before injecting any failures.
- Define the blast radius -- which services and users are affected by the experiment.
- Design chaos experiments by category:
- Network: Inject latency (200-2000ms), packet loss (5-50%), DNS failure, connection timeout.
- Process: Kill a service instance, exhaust CPU or memory, fill disk.
- Dependency: Block access to database, cache, or external API.
- State: Corrupt data, introduce clock skew, simulate split-brain scenarios.
- Start with minimal impact and increase gradually:
- Begin with read-only experiments (network latency on non-critical path).
- Progress to service-level failures (kill one instance of a multi-instance service).
- Only move to data-level chaos after infrastructure chaos is validated.
- Execute each experiment with safeguards:
- Set a maximum experiment duration (5-15 minutes).
- Configure automatic rollback triggers (error rate > 5% triggers abort).
- Monitor system metrics in real-time during the experiment.
- Have a manual kill switch ready (script to remove all injected failures immediately).
- Observe and record system behavior during the experiment:
- Did circuit breakers activate? How quickly?
- Did auto-scaling trigger? How long until new instances were healthy?
- Did retries succeed? Were they idempotent?
- Did fallback mechanisms engage (cached responses, degraded mode)?
- Were alerts triggered? Did on-call receive notification?
- After the experiment, verify full recovery:
- Remove all injected failures.
- Verify steady-state hypothesis holds again within expected recovery time.
- Check for data inconsistencies or orphaned state.
- Document findings and create action items for resilience improvements.
Output
- Chaos experiment definition files (YAML or JSON) with hypothesis, method, and rollback
- Experiment execution log with timeline of injected failures and observed effects
- System behavior report covering circuit breakers, retries, fallbacks, and alerts
- Recovery timeline showing time-to-detection and time-to-recovery
- Action items for resilience improvements (retry policies, circuit breaker tuning, fallback additions)
Error Handling
| Error |
Cause |
Solution |
| Experiment caused production outage |
Blast radius larger than expected or missing safeguards |
Always run in staging first; reduce scope; add automatic abort triggers; require approval |
| System did not recover after experiment |
Auto-healing mechanisms not configured or too slow |
Add health-check-based restarts; configure auto-scaling; implement circuit breaker patterns |
| Monitoring missed the failure |
Alerting thresholds too lenient or wrong metrics monitored |
Tighten alert thresholds; add specific alerts for the failure mode tested; verify alert channels |
| Chaos tool cannot access target |
Network segmentation or security policies blocking the tool |
Deploy chaos agent inside the target network; add security group rules for the chaos controller |
| Data corruption persists after rollback |
Stateful failure injection without transaction protection |
Use read-only chaos first; snapshot databases before stateful experiments; implement compensating transactions |
Examples
toxiproxy network latency injection:
set -euo pipefail
# Create a proxy for the database connection
toxiproxy-cli create postgres_proxy -l 0.0.0.0:15432 -u postgres-host:5432 # 15432: PostgreSQL port
# Inject 500ms latency
toxiproxy-cli toxic add postgres_proxy -t latency -a latency=500 -a jitter=100 # HTTP 500 Internal Server Error
# Run tests while latency is active
npm test -- --grep "handles slow database"
# Remove the toxic
toxiproxy-cli toxic remove postgres_proxy -n latency_downstream
Kubernetes pod kill experiment (Litmus Chaos):
apiVersion: litmuschaos.io/v1alpha1
kind: ChaosEngine
metadata:
name: api-pod-kill
spec:
appinfo:
appns: default
applabel: "app=api-server"
chaosServiceAccount: litmus-admin
experiments:
- name: pod-delete
spec:
components:
env:
- name: TOTAL_CHAOS_DURATION
value: "60"
- name: CHAOS_INTERVAL
value: "10"
- name: FORCE
value: "true"
Custom chaos script (process kill and verify recovery):
#!/bin/bash
set -euo pipefail
echo "=== Chaos Experiment: API server kill ==="
echo "Hypothesis: System recovers within 30 seconds"
# Record baseline
BASELINE=$(curl -s -o /dev/null -w '%{http_code}' http://app.test/health)
echo "Baseline health: $BASELINE"
# Kill one API instance
docker kill api-server-1
# Monitor recovery
for i in $(seq 1 30); do
STATUS=$(curl -s -o /dev/null -w '%{http_code}' --max-time 2 http://app.test/health)
echo "T+${i}s: HTTP $STATUS"
if [ "$STATUS" = "200" ]; then # HTTP 200 OK
echo "RECOVERED at T+${i}s"
break
fi
sleep 1
done
Resources
1---2name: running-chaos-tests3description: Execute chaos engineering experiments to test system resilience. Use when performing specialized testing. Trigger with phrases like "run chaos tests", "test resilience", or "inject failures".4license: MIT5---6# Chaos Engineering Toolkit
7
8## Overview
9
10Execute controlled chaos engineering experiments to test system resilience, fault tolerance, and recovery capabilities. Injects failures including network latency, service crashes, resource exhaustion, and dependency outages to verify that systems degrade gracefully and recover automatically.
11
12## Prerequisites
13
14- Distributed system or microservice architecture deployed in a staging/test environment
15- Monitoring and alerting configured (Grafana, Datadog, CloudWatch, or Prometheus)
16- Rollback capability for the target environment (manual or automated)
17- Chaos engineering tool installed (toxiproxy, Pumba, Litmus, or Chaos Mesh)
18- Explicit approval from the team to run chaos experiments
19- Steady-state hypothesis defined (what "healthy" looks like in metrics)
20
21## Instructions
22
231. Define the steady-state hypothesis:
24 - Identify measurable indicators of normal system behavior (e.g., p99 latency < 500ms, error rate < 0.1%, all health checks pass).
25 - Record baseline metrics before injecting any failures.
26 - Define the blast radius -- which services and users are affected by the experiment.
272. Design chaos experiments by category:
28 - **Network**: Inject latency (200-2000ms), packet loss (5-50%), DNS failure, connection timeout.
29 - **Process**: Kill a service instance, exhaust CPU or memory, fill disk.
30 - **Dependency**: Block access to database, cache, or external API.
31 - **State**: Corrupt data, introduce clock skew, simulate split-brain scenarios.
323. Start with minimal impact and increase gradually:
33 - Begin with read-only experiments (network latency on non-critical path).
34 - Progress to service-level failures (kill one instance of a multi-instance service).
35 - Only move to data-level chaos after infrastructure chaos is validated.
364. Execute each experiment with safeguards:
37 - Set a maximum experiment duration (5-15 minutes).
38 - Configure automatic rollback triggers (error rate > 5% triggers abort).
39 - Monitor system metrics in real-time during the experiment.
40 - Have a manual kill switch ready (script to remove all injected failures immediately).
415. Observe and record system behavior during the experiment:
42 - Did circuit breakers activate? How quickly?
43 - Did auto-scaling trigger? How long until new instances were healthy?
44 - Did retries succeed? Were they idempotent?
45 - Did fallback mechanisms engage (cached responses, degraded mode)?
46 - Were alerts triggered? Did on-call receive notification?
476. After the experiment, verify full recovery:
48 - Remove all injected failures.
49 - Verify steady-state hypothesis holds again within expected recovery time.
50 - Check for data inconsistencies or orphaned state.
517. Document findings and create action items for resilience improvements.
52
53## Output
54
55- Chaos experiment definition files (YAML or JSON) with hypothesis, method, and rollback
56- Experiment execution log with timeline of injected failures and observed effects
57- System behavior report covering circuit breakers, retries, fallbacks, and alerts
58- Recovery timeline showing time-to-detection and time-to-recovery
59- Action items for resilience improvements (retry policies, circuit breaker tuning, fallback additions)
60
61## Error Handling
62
63| Error | Cause | Solution |
64|-------|-------|---------|
65| Experiment caused production outage | Blast radius larger than expected or missing safeguards | Always run in staging first; reduce scope; add automatic abort triggers; require approval |
66| System did not recover after experiment | Auto-healing mechanisms not configured or too slow | Add health-check-based restarts; configure auto-scaling; implement circuit breaker patterns |
67| Monitoring missed the failure | Alerting thresholds too lenient or wrong metrics monitored | Tighten alert thresholds; add specific alerts for the failure mode tested; verify alert channels |
68| Chaos tool cannot access target | Network segmentation or security policies blocking the tool | Deploy chaos agent inside the target network; add security group rules for the chaos controller |
69| Data corruption persists after rollback | Stateful failure injection without transaction protection | Use read-only chaos first; snapshot databases before stateful experiments; implement compensating transactions |
70
71## Examples
72
73**toxiproxy network latency injection:**
74
75```bash
76set -euo pipefail
77# Create a proxy for the database connection
78toxiproxy-cli create postgres_proxy -l 0.0.0.0:15432 -u postgres-host:5432 # 15432: PostgreSQL port
79
80# Inject 500ms latency
81toxiproxy-cli toxic add postgres_proxy -t latency -a latency=500 -a jitter=100 # HTTP 500 Internal Server Error
82
83# Run tests while latency is active
84npm test -- --grep "handles slow database"
85
86# Remove the toxic
87toxiproxy-cli toxic remove postgres_proxy -n latency_downstream
88```
89
90**Kubernetes pod kill experiment (Litmus Chaos):**
91
92```yaml
93apiVersion: litmuschaos.io/v1alpha1
94kind: ChaosEngine
95metadata:
96 name: api-pod-kill
97spec:
98 appinfo:
99 appns: default
100 applabel: "app=api-server"
101 chaosServiceAccount: litmus-admin
102 experiments:
103 - name: pod-delete
104 spec:
105 components:
106 env:
107 - name: TOTAL_CHAOS_DURATION
108 value: "60"
109 - name: CHAOS_INTERVAL
110 value: "10"
111 - name: FORCE
112 value: "true"
113```
114
115**Custom chaos script (process kill and verify recovery):**
116
117```bash
118#!/bin/bash
119set -euo pipefail
120echo "=== Chaos Experiment: API server kill ==="
121echo "Hypothesis: System recovers within 30 seconds"
122
123# Record baseline
124BASELINE=$(curl -s -o /dev/null -w '%{http_code}' http://app.test/health)
125echo "Baseline health: $BASELINE"
126
127# Kill one API instance
128docker kill api-server-1
129
130# Monitor recovery
131for i in $(seq 1 30); do
132 STATUS=$(curl -s -o /dev/null -w '%{http_code}' --max-time 2 http://app.test/health)
133 echo "T+${i}s: HTTP $STATUS"
134 if [ "$STATUS" = "200" ]; then # HTTP 200 OK
135 echo "RECOVERED at T+${i}s"
136 break
137 fi
138 sleep 1
139done
140```
141
142## Resources
143
144- Principles of Chaos Engineering: https://principlesofchaos.org/
145- toxiproxy: https://github.com/Shopify/toxiproxy
146- Litmus Chaos: https://litmuschaos.io/
147- Chaos Mesh (Kubernetes): https://chaos-mesh.org/
148- Pumba (Docker chaos): https://github.com/alexei-led/pumba
149- Netflix Chaos Engineering: