Reliability, capacity, time, monitoring, and operations
LI reliability is unusual: availability must coexist with lawful stop, confidentiality, integrity, completeness, and non-disclosure of case existence. Operations need privacy-safe indicators and rehearsed recovery.
Safety boundary: this chapter teaches lawful, governed system design from public standards. It does not provide operational targeting, activation, decryption, surveillance-evasion, or covert collection instructions.
The mental model
| Concept | Plain meaning | Control that must travel with it |
|---|---|---|
| Service objective | A measurable target for lifecycle and delivery behavior | Do not optimize uptime while violating scope |
| Capacity model | Sizes IRI bursts, CC bandwidth, queues, and recovery | Use tail and catch-up demand |
| Failure domain | A component group that can fail together | Replicas need independent power, network, keys, and control |
| Protected time | Reliable clocks support authorization and evidence | Monitor drift and holdover |
| Privacy-safe telemetry | Shows health without target or payload data | Opaque IDs and aggregation are still sensitive |
| Runbook/game day | Practiced response for failure and compromise | Use synthetic cases and dual control |
Apply it as a controlled workflow
- Model normal, peak, receiver outage, catch-up, and disaster-recovery workloads.
- Set objectives for provisioning, de-provisioning, gap detection, delivery delay, and recovery.
- Design independent capacity and queues for administration, IRI, CC, and audit.
- Monitor clocks, certificates, versions, backlog, rejection, gap, duplicate, and expiry state.
- Exercise loss, corruption, control outage, receiver outage, and regional failure.
- Reconcile after every exercise or incident and update architecture.
Evidence to demand
- Dashboards reveal actionable health without case details.
- Receiver outage cannot cause unbounded storage or unlawful post-expiry collection.
- Recovery tests include key access and audit continuity.
- On-call access is just-in-time and every sensitive action is reviewed.
Failure to reason about
A receiver is unavailable for twelve hours. A queue sized for one hour fills. The system needs an agreed policy for admission, protected storage, notification, recovery priority, and lawful timing—not an improvised deletion or hidden drop.
Feynman check
Reliable means the right permitted parcel arrives safely and on time, and the machine stops when permission ends. It does not mean collecting forever.