Four alarms fired overnight. Two database contention pages, one read-replica collapse, and a batch of metrics that came back empty.

Four alarms, one cause, and the cause was not anything we shipped.

The wrong first instinct

The reflex when four alarms land at once is to open the deploy log and start reading diffs. I did that for a few minutes. It is almost always wasted time, and there is a cheaper question that settles it.

Did request volume change?