← Back to context

Comment by bestouff

2 hours ago

I said elsewhere this doesn't survive a power loss.

While it’s important to make this explicit, at what point do we just assume a high-reliability UPS is table stakes?

Of course, if you need SIL2 type reliability then you need to assume any given hardware component can spontaneously combust and become a total loss, at which point the data loss caused by a power cut is a rounding error.

  • > While it’s important to make this explicit, at what point do we just assume a high-reliability UPS is table stakes?

    Several years after they become commercially available?

    My experience with small UPSes is they tend to cook the batteries and you don't find out until they switch the load and the battery doesn't hold up.

    Large facility UPSes tend to do better, but automatic transfer switches have a tendancy to fail ocassionally. If you're hosted in many locations, it's not unusual to have a couple ATS failures per decade.

    All that said, unexpected power loss is certainly one reason that writes may be lost, but OSes crash too. Plenty of applications don't need or want to pay the cost for full commit to disk, but calling something durable when it's not committed to disk is inaccurate.

    And that's before we get into the whole thing where the OS and the disk like to return success when things haven't quite finished.

  • What's got this to do with a UPS? Not having a UPS is an external threat on the reliability of the power grid.

    Doing a hard shutdown or tripping over power cords seem much likelier local scenarios than any spontaneous combustion of hardware components.