Split-Brain & Conflict Resolution

10.When Both Sides Think They're In Charge

M

In this chapter

We'll name GreenMart's own incident precisely as split-brain, meet last-write-wins as the simple, honest-about-its-cost fallback, and trace a real PN-Counter CRDT through GreenMart's own numbers — correctly converging on "oversold by 5" without losing either region's own real sales, while being honest that a CRDT alone never prevents the underlying oversell.

10–12 min

The Problem in Real Life

Sarah finally has a precise name for GreenMart's actual incident, once she steps back and looks at the whole shape of it: not just two regions disagreeing — two regions each acting as though it alone was fully in charge, with nothing forcing either one to check.

And a real, separate question right behind it: even with the right fix going forward, what should have happened to the two conflicting versions of the truth that already existed the moment the link came back?

S

It wasn't two regions disagreeing. It was two regions each thinking it was the only one that mattered.

Sarah

Two Regions, Each Sure It's In Charge vs. One Real, Reconciled Answer

Split-brain, named precisely

Two parts of a system each genuinely believing it's the sole authority — exactly what GreenMart's two regions did.

Last-write-wins: simple, honestly lossy

The later write overwrites the earlier one — fast, with a real, named cost: the earlier write's information is discarded.

A real CRDT, traced through the actual numbers

A PN-Counter correctly merges both regions' sales into "oversold by 5" — nothing lost, any merge order, same true answer.

Convergence isn't prevention

A CRDT guarantees the final answer is correct — it never stops the oversell from happening in the first place.

Split-Brain & Conflict Resolution

Split-brain is the precise name for GreenMart's actual incident: a network partition that leaves two (or more) parts of a system each genuinely believing it's the sole authority, each making real, independent decisions as if the other side simply didn't exist. This is exactly what happened — neither region deferred to the other, because neither had any real way to know it needed to. The previous chapter's real fix (majority-quorum leader election) prevents this from happening again. This chapter is about the separate, real question of what to do once conflicting writes already exist.

  • Conflict resolution is the honest, reactive fallback: reconciling two genuinely different, already-committed values after the fact. Last-write-wins — the same strategy Act 10's BaaS chapter already used — is the simplest real version: whichever write is chronologically later simply overwrites the other. Simple, fast, and honest about a real cost: the earlier write's own information is genuinely discarded, not merged.
  • Conflict-free approaches — CRDTs (Conflict-free Replicated Data Types) — go further, and are worth walking through concretely rather than just naming. Certain data structures are mathematically designed so that no matter what order or combination independent updates arrive in, every replica converges to the exact same, correct value automatically, with nothing discarded.
Table — A Real CRDT, Traced Through GreenMart's Own Incident
StepUS Region's Own CounterAsia Region's Own CounterMerged, True Total
Starting stock0 sold0 sold3 − 0 = 3 remaining
US sells 4 units (during the partition)4 sold0 sold (unknown to US)not yet merged
Asia sells 4 units (during the partition)4 sold (unknown to Asia)4 soldnot yet merged
Link reconnects — counters merge4 sold4 sold3 − (4 + 4) = −5 → correctly shows oversold by 5

A PN-Counter (a real, well-known CRDT) has each region keep its own separate running total of what it sold, never touching the other region's own count directly. Merging just adds every region's own total together — always the same result, no matter what order the merge happens in, and nothing from either region is ever silently discarded.

This is the honest, important distinction worth being precise about: the CRDT above didn't prevent the oversell — neither region checked with the other before selling, and nothing about a CRDT changes that. What it guarantees is something narrower and still genuinely valuable: the final, merged answer is always mathematically correct and consistent, arrived at the same way regardless of merge order, with zero data silently lost the way last-write-wins would have lost one region's own real sales entirely. "Oversold by 5" is a painful, real business problem — but it's an honestly, correctly computed one, not a corrupted or ambiguous one.

Put together with the previous chapter's real fix: majority-quorum consensus is what should prevent the oversell from happening at all, by refusing a sale the minority side of a partition can't get proper authority for. A CRDT-style counter is what guarantees that if a conflict does still happen — for less critical data, or before the real fix is fully in place — the eventual, reconciled answer is at least honestly, completely correct, not silently wrong or partially lost.

Key Takeaway

Split-brain is what happens when consensus fails silently — two parts of a system each acting as sole authority, with nothing forcing them to check. Conflict-free approaches like CRDTs don't prevent that from happening; they guarantee that whatever conflicting writes did happen still merge into one correct, complete, honestly-computed answer — a real, different, and genuinely complementary guarantee to majority-quorum consensus, not a replacement for it.

Why This Matters

This is the direct, precise name for GreenMart's own incident, and the honest, concrete difference between preventing a conflict (last chapter's consensus) and correctly surviving one that already happened (this chapter's CRDT) — both real, both useful, solving genuinely different halves of the same problem.

GreenMart now has the actual fix for its own incident, by name, plus a real, worked demonstration of how a conflict-free counter would have at least kept the final numbers honest even without that fix. A single write touching more than one machine at once is a related, but genuinely separate problem, and exactly where the next chapter goes.

Next