concept

Static Stability

also called Stability Under Failure

A system that keeps working correctly in its current state when its control plane or dependencies become unavailable, rather than needing them to stay running.

resiliencecontrol-planedegradation

The principle separates the data plane — the path that serves user requests — from the control plane — the path that changes configuration, scales capacity, registers instances and issues credentials. Control planes are more complex and less reliable than data planes, and a data plane that depends on its control plane inherits that lower reliability.

Statically stable design means that when the control plane fails, the data plane continues with the configuration it already has. Nothing new can be provisioned or changed, and everything currently running keeps running.

The concrete practices this implies are worth listing because each is a common failure. Cache configuration and credentials locally with a long fallback rather than fetching per request. Pre-provision capacity for the failure case rather than depending on autoscaling to react during an event, since scaling depends on the control plane that may be the thing that failed. Keep DNS and service discovery results usable when the registry is unreachable. Ensure a failover target is already running and warm rather than requiring creation.

The pattern that violates it most often, and most invisibly: a service that fetches a secret or a feature flag on every request and has no cached fallback. It has quietly made a management system a hard dependency of the request path, and that will be discovered during the management system's next incident.