The site wasn’t down, which was the confusing part. It answered, forty seconds at a time, in waves. The PHP-FPM slow log pointed every stuck request at the same curl_exec(), talking to a travel API that was having a bad afternoon. Our cURL options carried CURLOPT_TIMEOUT set to zero, which doesn’t mean no time — it means no limit. Slow calls held FPM workers until the pool filled, and then pages that never touched that API queued up behind them too. The fix is a total timeout, a connect timeout, and actually handling the error when it fires. Leave it at zero and you’ve handed a stranger the power to freeze your site by being slow.
Read more "The API call that never gave up (and took the site down with it)"
