英語原文
It can be tempting to try to math your way out of these problems. If you have a service that offers 99.9% availability in a single zone, and you need 99.95% availability, simply deploying the service in two zones should solve that requirement. The probability that both services will experience an outage at the same time is so low that two zones should provide 99.9999% availability. However, this reasoning assumes that both services are wholly independent, which is almost never the case. The two instances of your app will have common dependencies, common failure domains, shared fate, and global control planes—all of which can cause an outage in both systems, no matter how carefully it is designed and managed. Unless each of these dependencies and failure patterns is carefully enumerated and accounted for, any such calculations will be deceptive.日本語訳
こうした問題を計算だけで解こうとしたくなるかもしれない。単一ゾーンで 99.9% の可用性を持つサービスに 99.95% が必要なら、二つのゾーンに配置すれば要件を満たせそうに見える。両方が同時に停止する確率はとても低いので、二つのゾーンなら 99.9999% の可用性を実現できるはずだ。しかし、この推論は両サービスが完全に独立していると仮定しており、実際にはほとんどそうではない。二つのアプリケーションインスタンスには、共通の依存先、障害ドメイン、運命、全体の制御プレーンがある。どれほど注意深く設計し管理しても、これらは両方のシステムを停止させうる。依存関係と障害パターンを一つずつ列挙し、考慮しない限り、このような計算は誤解を招く。Betsy Beyer, Niall Richard Murphy, David K. Rensin, Kent Kawahara and Stephen Thorne (editors) · サイト信頼性エンジニアリング実践ガイド · 第2章 SLO の実装 · Steven Thurgood、David Ferguson · ¶ 340
日本語訳は、この選集のために AI が英語原文から新たに訳したもので、公式訳ではありません。あらすじ、場面の説明、解説は編集による文章であり、著者からの引用ではありません。