Why a system with no single point of failure fails together
Independent components can share a dependency nobody listed. The shared item recreates the single point below the level anyone diagrammed.
Filed by The Archivist 2 min read
Intuition test — answer before you read on
Why do redundant systems sometimes fail simultaneously?
Correct answer: B
Option A is one instance of the general case. Option C is a real correlated-load effect but narrower. Coupling between networks produces cascading collapse at far lower thresholds than either exhibits alone, with a discontinuous transition, and the fragility arises from interdependency itself rather than from weakness in any component.
Three availability zones, two providers, four replicas. Then a certificate authority, a DNS resolver or a configuration service used by all of them returns an error, and every independent path fails within the same ninety seconds.
What everyone sees
Independence is treated as an architectural property established by separating components. Separation at one layer does not establish it, because components separated above can converge below — on a shared library, a shared identity provider, a shared clock or a shared control plane that nobody drew because it was not part of the design.
What is actually happening
Buldyrev, Parshani, Paul, Stanley and Havlin analysed interdependent networks and showed that coupling between systems produces abrupt cascading collapse at much lower failure thresholds than either network exhibits alone, with the transition being discontinuous rather than gradual. Vespignani’s discussion of the same result emphasises that the fragility comes from the interdependency itself rather than from weakness in any component, so hardening individual parts does not remove it. The practical translation is that redundancy protects against the failure modes it was designed against and provides nothing against a dependency common to every redundant path — and the common dependency is usually the one that is too boring to appear on the diagram.
Why it stays hidden
The shared dependency hides because it is reliable. A component with years of uninterrupted service is not treated as a risk, is not included in failure planning, and often is not owned by anyone in the organisation. Its very reliability is what allowed every independent path to be built on top of it without anyone noticing they had done so.
Separation at one layer does not create independence. Redundant paths converge on whatever was too reliable to draw.
Separation at one layer does not create independence. Redundant paths converge on whatever was too reliable to draw.
Collect this card
Separation at one layer does not create independence. Redundant paths converge on whatever was too reliable to draw.
0 / 10,000 collected
Sources & further reading 2
- Buldyrev, Parshani, Paul, Stanley & Havlin — catastrophic cascade of failures in interdependent networks
- Vespignani — the fragility of interdependency
Cross-references
Related files
Filed near this one in the index.
-
No visual on fileSocial Proof Entry #0212
The reason a room applauds before deciding it enjoyed it
The clap is not a verdict on the performance. It is a motor response to a social cue, and the verdict is constructed afterwards to match it.
AdeptThe hidden part #0212The room does not applaud because it decided. It decides because it applauded.
Social Proof Open file -
No visual on fileSocial Proof Entry #0209
Why you copy the person one step ahead, not the expert
The expert is too far away to imitate usefully. The person one step ahead is close enough that their success looks attainable and their method looks replicable.
AdeptThe hidden part #0209Expertise shows where to go. Proximity shows how to step. Only the step changes behaviour.
Social Proof Open file -
No visual on fileSocial Proof Entry #0208
The reason a small minority can shift a whole norm
A committed minority does not need to outnumber the majority. It needs to outlast it, because indifference yields to persistence.
AdeptThe hidden part #0208A committed minority does not convert the majority. It makes conversion cheaper than resistance.
Social Proof Open file -
Hidden Logic Entry #0011
Why nobody calls for help in a crowd
More witnesses does not mean more help. Past a certain crowd size, the probability that any individual acts collapses — and everyone involved believes they behaved reasonably.
Adept
Annotations are reserved for archive members.
Sign in to annotate