Health Check & Service Discovery  ·  View 15 of 21  ·  Runtime

Eligibility Decision Path

Four kinds of evidence, five verdicts, and two of the verdicts keep the instance in rotation.

Editable source SVG draw.io All views
Evidence No signal all classes quiet Dependency degraded self-reported Failure rate rising probe or passive Hard failure refused, process gone First test Corroborated by a second class? Dependency declared shared? Decaying score vs threshold Fast path, skip decay Damping Transitions > 4 in 10 min? Veto Would this breach 50%? Verdict Unknown kept in rotation Degraded weight reduced Quarantined backoff, owner notified Ineligible removed from views Health disregarded full set, declared weight only crossed yes no yes Eligibility — Every Path From Signal To Verdict Application we own Decision point Interface / broker Risk / gap synchronous failure / alternate Two of five verdicts keep the instance in rotation: silence that nothing corroborates stays Unknown, and a shared dependency only reduces weight. A removal that would take the last eligible instance in a region raises an incident instead. v 1.0 · owner Reliability Architecture

The asymmetry, stated as a graph

  • Silence that nothing corroborates becomes Unknown, not Ineligible — the single most important edge in the set (ADR-05).
  • A degraded shared dependency reduces weight and may not set unreadiness, which is what stops a database wobble becoming a total outage (ADR-06).
  • A hard failure skips the decay entirely; damping protects against noise, not against a closed port (ADR-07).

Assumptions

  • Quarantine after more than 4 eligibility changes in 10 minutes; damping adds no more than 5 s to p99 detection.
  • Fraction guard floor 50% per service per zone.

Deliberate omission

  • The 'last eligible instance in a region' branch is in the note rather than on the canvas: it is the same asymmetry one step further on.