Last month I decided anycast DNS was "easy" and deployed a /32 across three providers:
- HostHatch: Amsterdam, $3/month
- CloudCone: Los Angeles, $4/month
- RackNerd: Amsterdam, $5/month
All running BIND, same zone, BGP announced to my upstream. What could go wrong?
Everything. CloudCone leaked my /32 to a peer in Los Angeles who preferred it over their own customer route. Los Angeles went unreachable from half of the US West Coast because CloudCone's upstream deaggregated poorly. Amsterdam worked fine, which was the worst part—I kept thinking I understood the problem.
I spent 72 hours in routing tables. Traceroutes that looped. DNS responses from Los Angeles to European users with 340 ms latency because some Tier 1 decided that was "optimal."
Then I checked my metrics. 40% of users had lower latency than my old unicast setup. The chaos found paths I never would have engineered. Los Angeles leak? East Asia saw 15 ms improvement. US West's mess? Southern California got better peering.
I kept it running. I hate it. It works.