4 ms·
The SLA excludes force majeure.
by beejiu 18d ago
The SLA excludes force majeure.
- LastTrain 18d agoThis
- the8472 18d agoMaking a probabilistic claim while excluding a factor that dominates those statistics is... is quite creative accounting.
- mpyne 18d agoAre you saying that most data loss happens because your data center gets blown up in a shooting war? Like, AWS is the first digital service provider to lose data in decades?
- the8472 18d agoI'm saying that if you have eliminated more mundane failures like dying harddrives, cosmic rays and so on from your systems and your calculation ends up with 11 nines then actually those "force majeure" events are probable enough that they dominate whatever other residuals are supposedly hiding in those last 0.0000000001%. The region has seen a bunch of wars in the last 100 years, so the annual war-rate is > 1%. Even if we generously add the assumption that only 1 in 100 wars affects a datacenter you can see that wars become a major source of correlated hardware failures that they need to solve to actually deliver that kind of reliability.
- mpyne 18d agoCosmic rays and dying hard drives are not force majeure though.
- ployable7 18d agoYou don’t want to blend probabilities like this, because the tactics you use as a consumer vary between the two. If you consider 11 9s like “object AFR”, you might build systems that are resilient to very occasional single object loss. And it’s useful to know at what rate that might occur. Whereas with these force majeure events you’d want a complete DR setup, and it’s typically an async recovery. Here it is useful to understand the fault domain (single server or single building or multi-building) so you can plan. Blending the two numbers doesn’t help you build better against the systems. And the force majeure events are rare enough that they won’t happen … until they do. I’m not sure that knowing the precise probability that Iran would attack a gulf nation would change the fact that if they do, you need to have a DR story.
- the8472 17d agoSeems like begging the question to me. You can't blend the numbers because amazon didn't blend the numbers. If they did and miraculously still arrived at 11 9s then that would also cover things such as wars and natural catastrophes, e.g. because they do offsite backups internally.
- ployable7 17d agoI’m not saying you can’t blend the numbers, I’m saying you shouldn’t blend the numbers. Because one number doesn’t communicate what you actually need to know to build. You want to know how reliable the service is in steady state. For example it’s useful to know that S3 is effectively lossless in steady state whereas EBS volumes have an AFR of about 0.1%. You build your apps very differently between S3 and EBS knowing this. You can build highly resilient applications on each, but you code them differently, informed by these design goals. You separately want to understand the failure modes that will require you to fully recover from backup. For example knowing that cloud storage is resilient to everything but region failure would inform you that your backups should be out of the region, not just a bucket in the same region. You don’t get that perspective from just a 9s number.
- mjr00 18d agoForce majeure carveouts are really common in every type of contract. You should check your home insurance contract, for instance... It likely would not cover an ICBM strike.
- sire-vc 18d agoSomehow I feel like the biggest post-apocalyptic problem will be the loss of home equity due to uninsured damage causing a collapse of financial markets.
- eli 18d agoI think it's what most people comparing provider SLAs would expect
- unethical_ban 18d agoAre you suggesting that their technical documents have separate availability numbers to predict geopolitical events and war?
- throwawaythekey 18d agoThe sales pitch should change from "probabilistically we will NEVER lose your data" to "you are most likely to lose your data due to wars, terrorists, software bugs, someone losing the master encryption key, the government forcing us to...". Offsite backups are sadly rare these days, and aws sales is the main reason why.
- mitxela 18d agoCreative accounting works and is good because it works. If your customers give you more money because you lied to them, but it's legal, then it's good.
- oatmeal1 17d agoExcluding war as force majeure in the Middle East is the same as excluding high tide as force majeure building a sandcastle at low tide.
- Y-bar 17d agoThis is very on point. While I am not legally trained in US law, and especially not in any Middle Eastern law, I have a enough knowledge on the law in my country here where I live… Invoking force majeure requires the entity to prove all three following to be true: A. That the event was unexpected and therefore unavoidable. B. That the event was outside the control of the entity. C. That the event made it impossible for the company to resolve the issue. War in the region is as you say rather common unfortunately. The fact that AWS is used by the IDF (https://www.972mag.com/cloud-israeli-army-gaza-amazon-google-microsoft/ https://www.972mag.com/cloud-israeli-army-gaza-amazon-google...) should be considered a factor whether or not their data centre became a more likely target or not. What remains is the ability or not for AWS to do multi-location reduncancy.
- roryirvine 17d agoAs someone who ran a tech company in Northern Ireland at a time when violence was much more common than it is today, I can tell you that our force majeure clauses always disclaimed liability for "riot, violent disorder, civil commotion, and acts of unlawful civil unrest and terrorism". How could it be otherwise - do you expect AWS to have its own army and missile defence system?
- oatmeal1 17d agoThe difference between you and Amazon is hundreds of millions of dollars in political donations and lobbying. Amazon certainly has the political connections to make defense of its datacenters a national security priority of the strongest military on earth if it made it a priority.