Service Fault Isolation and Graceful Degradation
archimatev1/01 Views
/02 About
Define work admission, bulkheads, circuit protection, deadlines, safe degraded operation and capacity-verified recovery.
Purpose: prevent cascading dependency and overload failures from defeating customer-facing services. Model finite workload admission, resource isolation, dependency circuit opening, request deadlines, approved safe fallback, degraded state disclosure, controlled probing and progressive restoration without prescribing implementation technologies. Safety discipline: degraded operation is permitted only for explicitly approved reduced-scope functions. Missing identity, authorization, integrity or safety-critical prerequisites must never be bypassed by fallback; otherwise the operation fails explicitly. Retry decisions stay bounded and cannot amplify an overloaded dependency. Operating contract: define workload budgets, overload responses, cancellation/deadline behavior, failure thresholds, recovery probes, customer-visible degraded status and acceptance gates for restoring normal traffic. Security and correctness remain enforced throughout. Limitations: this is a logical architecture reference, not an executable circuit breaker, automatic resilience guarantee or permission to bypass safety or legal requirements. State and trigger links are conditional design relationships rather than executable state machines; fault injection and organization-specific acceptance evidence remain necessary.
Curated · operations · CC-BY-4.0 · Published by Lattix · 46 elements · 71 relationships · validated on publish
/03 Contents
- Business Actor
- Business service beneficiary
- Role
- Service reliability accountable owner
- Application
- Logical resilient service application
- Application Service
- Critical business application service, External downstream dependency
- Application Component
- Request admission boundary, Bulkhead isolation component, Dependency circuit protection, End-to-end deadline enforcement, Dependency interaction adapter, Approved degraded-service adapter, Dependency health evaluator, Overload and service health observer
- State
- Normal authorized service, Declared restricted capability, Circuit open to dependency, Recovery probe permitted, Controlled service recovery, Protected service unavailable
- Business Event
- Service capacity saturation signaled, Downstream dependency failure observed, Recovery eligibility signal observed
- Behaviour
- Validate and admit eligible work, Reserve isolated execution capacity, Invoke bounded dependency operation, Open faulty dependency circuit, Choose preapproved degraded behavior, Reject excess demand with reason, Run controlled dependency recovery probe, Ramp service to verified normal operation, Measure service health and saturation
- Message/Event Schema
- Bounded failure response contract
- Resource
- Finite concurrency and queue budget
- Constraint
- Bounded queue and concurrency limits, Propagated request deadline and retry budget, No security bypass through fallback
- Policy
- Approved graceful degradation conditions, Controlled reopening and restoration policy
- Control
- Security and service correctness safeguard
- Risk
- Cascading failure and resource exhaustion risk, Unsafe degraded-response risk
- Data Store
- Service operating condition record
- Measure
- Availability latency and rejection indicators
- Outcome
- Safely bounded business service result
- Requirement
- Verified containment and continuity requirement
- Capability
- Contain service faults and degrade safely