Fault Tree — Regional Cloud API Outage
A month of a three-zone regional service, where one shared datastore sits inside all three availability-zone branches: the exact evaluation shows the two-of-three vote buys far less than the architecture diagram promises.
Make it your own.
title "Regional API unavailability — multi-AZ service"
mission 720h # one calendar month
top "Public API unavailable in the region" = OR(entry_lost, capacity_lost, control_plane)
gate entry_lost "Traffic cannot reach the service" = OR(dns_fault, edge_lb, tls_expiry)
gate capacity_lost "Serving capacity insufficient" = KOFN(2, az_a, az_b, az_c)
gate az_a "Availability zone A unavailable" = OR(az_a_infra, shared_store)
gate az_b "Availability zone B unavailable" = OR(az_b_infra, shared_store)
gate az_c "Availability zone C unavailable" = OR(az_c_infra, shared_store)
gate control_plane "Control plane blocks recovery" = INHIBIT(deploy_regression, condition: no_rollback)
event az_a_infra "Zone A infrastructure event" p=0.004
event az_b_infra "Zone B infrastructure event" p=0.004
event az_c_infra "Zone C infrastructure event" p=0.004
event shared_store "Shared regional datastore degraded" p=0.0025
event dns_fault "Authoritative DNS misconfiguration" p=0.0012
event edge_lb "Edge load balancer fleet failure" rate=3.0e-6
event tls_expiry "Certificate expiry not renewed" p=0.0004
event deploy_regression "Bad deployment reaches the region" p=0.02
condition no_rollback "Automated rollback disabled for the change" p=0.06