SkillByAIOpen interactive version →

Lesson 6 / 25

Availability Maths

Nines, chains and redundancy.

Series multiply, redundancy compounds

Availability is often quoted in nines: 99.9% allows about 8.8 hours of downtime per year, 99.99% about 53 minutes. Components in series multiply, so a chain is less available than its weakest link. Redundant independent replicas raise availability because all must fail at once. Real failures are often correlated (same region, same bad deploy), so the formulas give an upper bound.

Downtime budgets and redundancy, run

I ran this with Python 3.12.3 using only the standard library; inputs are fixed or seeded, so the output is reproducible. Three components in series give 99.79%; duplicating the app and database tiers raises the total to about 99.99%, now limited by the single load balancer.

# Availability: nines, serial chains and redundancy
MIN_PER_YEAR = 365 * 24 * 60
for a in (0.99, 0.999, 0.9999, 0.99999):
    print(f"{a:.3%} -> {MIN_PER_YEAR * (1 - a):8.1f} min/year downtime")

lb, app, db = 0.9999, 0.999, 0.999
serial = lb * app * db
print(f"LB -> app -> DB in series: {serial:.4%}")

def parallel(a, n):              # n independent replicas, any one is enough
    return 1 - (1 - a) ** n

print(f"two app replicas         : {parallel(app, 2):.6%}")
print(f"with 2 apps + 2 DBs      : {lb * parallel(app, 2) * parallel(db, 2):.4%}")

Output:

99.000% ->   5256.0 min/year downtime
99.900% ->    525.6 min/year downtime
99.990% ->     52.6 min/year downtime
99.999% ->      5.3 min/year downtime
LB -> app -> DB in series: 99.7901%
two app replicas         : 99.999900%
with 2 apps + 2 DBs      : 99.9898%

Find the single points of failure

After drawing the design, point at each box and ask "what happens if this dies?"

Quick check: What happens to availability when components are chained in series?

  • It becomes 100%
  • It increases
  • It stays equal to the best component
  • It decreases, because availabilities multiply
Answer

It decreases, because availabilities multiply — Each extra dependency is another way to fail.