# Error Handling / Resilience

> Every principle in this category is listed as a record.

Page: Ontology · Principles
Canonical: https://banes-lab.com/ontology#architecture-category-error-handling-resilience

Listed in [Ontology · Principles](https://banes-lab.com/api/pages/ontology/principles.md), after [Event / Messaging / Asynchronous Architecture](https://banes-lab.com/ontology/principles/architecture-category-event-messaging-asynchronous-architecture.md) and before [Architecture Review / Evolution / Governance Artifacts](https://banes-lab.com/ontology/principles/architecture-category-architecture-review-evolution-governance-artifacts.md).

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram

The relations inside this category.

```mermaid
flowchart LR
n_defensive_programming["Defensive Programming"]
n_fail_fast["Fail Fast"]
n_fail_safe["Fail Safe"]
n_fail_secure["Fail Secure"]
n_graceful_degradation["Graceful Degradation"]
n_fault_tolerance["Fault Tolerance"]
n_resilience["Resilience"]
n_robustness_principle["Robustness Principle"]
n_error_handling["Error Handling"]
n_error_boundaries["Error Boundaries"]
n_fallback_pattern["Fallback Pattern"]
n_retry_pattern["Retry Pattern"]
n_timeout_pattern["Timeout Pattern"]
n_circuit_breaker_pattern["Circuit Breaker Pattern"]
n_bulkhead_pattern["Bulkhead Pattern"]
n_backpressure["Backpressure"]
n_defensive_programming --> n_error_handling
n_defensive_programming --> n_fail_fast
n_fail_fast -.-> n_graceful_degradation
n_fail_safe --> n_resilience
n_graceful_degradation --> n_fault_tolerance
n_fault_tolerance --> n_error_handling
n_fault_tolerance --> n_resilience
n_resilience --> n_fault_tolerance
n_error_handling --> n_resilience
n_error_boundaries --> n_resilience
n_fallback_pattern --> n_graceful_degradation
n_retry_pattern --> n_fault_tolerance
n_circuit_breaker_pattern --> n_fault_tolerance
n_circuit_breaker_pattern --> n_backpressure
n_backpressure --> n_resilience
```

### Defensive Programming

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: function, module, boundary
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that code checks its inputs and assumptions before acting on them, and reports a violation as an explicit error.

Requires
[Input Validation](https://banes-lab.com/records/architecture/input-validation.md), [Error Handling](https://banes-lab.com/records/architecture/error-handling.md)

Reinforces
[Robustness](https://banes-lab.com/records/lexicon/robustness.md), [Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md)

Enables
[Safe Failure](https://banes-lab.com/records/lexicon/safe-failure.md)

In tension with
[Verbosity](https://banes-lab.com/records/lexicon/verbosity.md)

Conflicts with
[Trusting Invalid Inputs](https://banes-lab.com/records/lexicon/trusting-invalid-inputs.md)

Tensions
[Defensive Programming / Verbosity](https://banes-lab.com/records/tension/defensive-programming-verbosity.md)

Distinct from
[Error Handling](https://banes-lab.com/records/architecture/error-handling.md): Defensive programming checks inputs and assumptions before acting, while error handling decides what happens to an error once raised.

Violated by
unchecked assumptions

Detected by
null/empty/range unsafe access

Measured by
guard coverage, runtime exception rate

Refactored by
Add Guards, Validate Inputs

Enforced by
linting, [tests](https://banes-lab.com/records/lexicon/tests.md)

Before

```typescript
function renameFoo(foo: Foo, name: string) {
foo.name = name.trim();
}
```

After

```typescript
function renameFoo(foo: Foo | undefined, name: unknown) {
if (!foo) throw new Error("Foo required");
if (typeof name !== "string" || name.trim().length === 0) throw new Error("valid name required");
return { ...foo, name: name.trim() };
}
```

How it is checked

Checked by
linting, tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Input Validation](https://banes-lab.com/records/architecture/input-validation.md), [Error Handling](https://banes-lab.com/records/architecture/error-handling.md), [Robustness](https://banes-lab.com/records/lexicon/robustness.md), [Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md), [Safe Failure](https://banes-lab.com/records/lexicon/safe-failure.md)

Shape it refuses
[Trusting Invalid Inputs](https://banes-lab.com/records/lexicon/trusting-invalid-inputs.md)

### Fail Fast

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: input, startup, invariant boundary
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that invalid input or state stops the operation at the point it is detected, with an explicit error.

Requires
[Preconditions](https://banes-lab.com/records/architecture/preconditions.md), [Validation](https://banes-lab.com/records/architecture/validation.md)

Reinforces
[Correctness](https://banes-lab.com/records/architecture/correctness.md), [Observability](https://banes-lab.com/records/architecture/observability.md)

Enables
[Early Defect Detection](https://banes-lab.com/records/lexicon/early-defect-detection.md)

In tension with
[Graceful Degradation](https://banes-lab.com/records/architecture/graceful-degradation.md)

Conflicts with
[Silent Failure](https://banes-lab.com/records/lexicon/silent-failure.md), [Silent Data Corruption](https://banes-lab.com/records/architecture/silent-data-corruption.md)

Referenced by
[Preconditions](https://banes-lab.com/records/architecture/preconditions.md), [Defensive Programming](https://banes-lab.com/records/architecture/defensive-programming.md), [Schema Validation](https://banes-lab.com/records/architecture/schema-validation.md), [Input Validation](https://banes-lab.com/records/architecture/input-validation.md)

Contracts
[Correctness Core](https://banes-lab.com/records/algorithms/correctness-core.md)

Tensions
[Fail Fast / Graceful Degradation](https://banes-lab.com/records/tension/fail-fast-graceful-degradation.md)

Distinct from
[Defensive Programming](https://banes-lab.com/records/architecture/defensive-programming.md): Fail fast stops the operation where invalid state is found, while defensive programming is the checking that finds it.

Distinct from
[Design by Contract](https://banes-lab.com/records/architecture/design-by-contract.md): Fail fast is how a violation is handled, by stopping, while design by contract is where the conditions are stated.

Distinct from
[Graceful Degradation](https://banes-lab.com/records/architecture/graceful-degradation.md): Fail fast stops on invalid state, while graceful degradation keeps the rest running when an optional dependency fails.

Violated by
swallowing invalid state

Detected by
ignored exceptions, default fallbacks masking errors

Measured by
late failure rate

Refactored by
Add Guard Clause, Throw Explicit Error

Enforced by
validation tests

Refused by rules
fail-fast

Before

```typescript
const fooUrl = process.env.FOO_URL ?? "http://localhost:3000";
startFooApp(fooUrl);
```

After

```typescript
const fooUrl = process.env.FOO_URL;
if (!fooUrl) throw new Error("FOO_URL is required");
startFooApp(new URL(fooUrl));
```

How it is checked

Checked by
validation tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Preconditions](https://banes-lab.com/records/architecture/preconditions.md), [Validation](https://banes-lab.com/records/architecture/validation.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Observability](https://banes-lab.com/records/architecture/observability.md), [Early Defect Detection](https://banes-lab.com/records/lexicon/early-defect-detection.md)

Shape it refuses
[Silent Failure](https://banes-lab.com/records/lexicon/silent-failure.md), [Silent Data Corruption](https://banes-lab.com/records/architecture/silent-data-corruption.md)

### Fail Safe

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: runtime, operation, security
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that a failing operation leaves the system in the state that causes the least harm.

Requires
[Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md)

Reinforces
[Resilience](https://banes-lab.com/records/architecture/resilience.md)

Enables
[Damage Limitation](https://banes-lab.com/records/lexicon/damage-limitation.md)

In tension with
[Availability](https://banes-lab.com/records/lexicon/availability.md)

Conflicts with
[Unsafe Default Continuation](https://banes-lab.com/records/lexicon/unsafe-default-continuation.md)

Tensions
[Fail Safe / Availability](https://banes-lab.com/records/tension/availability-fail-safe.md)

Violated by
continuing in unsafe state

Detected by
fallback to unsafe behavior

Measured by
unsafe failure modes

Refactored by
Add Safe Fallback, Stop Unsafe Operation

Enforced by
failure-mode tests

Before

```typescript
try {
await openFooGate();
} catch {
fooGate.unlock();
}
```

After

```typescript
try {
await openFooGate();
} catch {
fooGate.lock();
throw new Error("Foo gate remains locked");
}
```

How it is checked

Checked by
failure-mode tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Damage Limitation](https://banes-lab.com/records/lexicon/damage-limitation.md)

Shape it refuses
[Unsafe Default Continuation](https://banes-lab.com/records/lexicon/unsafe-default-continuation.md)

### Fail Secure

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: auth, access, infrastructure
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that an authentication or policy failure denies access.

Requires
[Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md)

Reinforces
[Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)

Enables
[Deny-by-Default Behavior](https://banes-lab.com/records/lexicon/deny-by-default-behavior.md)

In tension with
[Availability](https://banes-lab.com/records/lexicon/availability.md)

Conflicts with
[Fail Open](https://banes-lab.com/records/lexicon/fail-open.md)

Referenced by
[Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md)

Tensions
[Fail Secure / Availability](https://banes-lab.com/records/tension/availability-fail-secure.md)

Violated by
allowing access after auth/policy failure

Detected by
fail-open branches

Measured by
fail-open count

Refactored by
Default Deny, Add Explicit Allow

Enforced by
security tests, policy checks

Before

```typescript
function authorizeFoo(token?: string) {
if (!token) return { role: "admin" };
return decodeToken(token);
}
```

After

```typescript
function authorizeFoo(token?: string): FooIdentity {
if (!token) throw new UnauthorizedError();
const identity = verifyToken(token);
if (!identity) throw new UnauthorizedError();
return identity;
}
```

How it is checked

Checked by
security tests, policy checks

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Deny-by-Default Behavior](https://banes-lab.com/records/lexicon/deny-by-default-behavior.md)

Shape it refuses
[Fail Open](https://banes-lab.com/records/lexicon/fail-open.md)

### Graceful Degradation

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: service, UX, system
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that the failure of an optional dependency removes only the feature it serves, and the rest of the system keeps working.

Requires
[Fallback](https://banes-lab.com/records/lexicon/fallback.md), [Feature Isolation](https://banes-lab.com/records/lexicon/feature-isolation.md)

Reinforces
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)

Enables
[Partial Availability](https://banes-lab.com/records/lexicon/partial-availability.md)

In tension with
[Consistency / Feature Completeness](https://banes-lab.com/records/lexicon/consistency-feature-completeness.md)

Conflicts with
[All-Or-Nothing Failure](https://banes-lab.com/records/lexicon/all-or-nothing-failure.md)

Referenced by
[Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md), [Fallback Pattern](https://banes-lab.com/records/architecture/fallback-pattern.md)

Tensions
[Graceful Degradation / Consistency / Feature Completeness](https://banes-lab.com/records/tension/consistency-feature-completeness-graceful-degradation.md)

Violated by
total outage from noncritical dependency failure

Detected by
critical path dependency on optional service

Measured by
partial availability under failure

Refactored by
Add Fallback, Isolate Optional Dependency

Enforced by
chaos tests

Before

```typescript
async function renderFooPage() {
const foo = await fooService.get();
const bar = await barRecommendations.get();
return render(foo, bar);
}
```

After

```typescript
async function renderFooPage() {
const foo = await fooService.get();
const bar = await barRecommendations.get().catch(() => [] as Bar[]);
return render(foo, bar);
}
```

How it is checked

Checked by
chaos tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Fallback](https://banes-lab.com/records/lexicon/fallback.md), [Feature Isolation](https://banes-lab.com/records/lexicon/feature-isolation.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Partial Availability](https://banes-lab.com/records/lexicon/partial-availability.md)

Shape it refuses
[All-Or-Nothing Failure](https://banes-lab.com/records/lexicon/all-or-nothing-failure.md)

### Fault Tolerance

- Kind: [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: service, system, infrastructure
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
The degree to which a system keeps operating correctly when some of its components fail.

Requires
[Redundancy](https://banes-lab.com/records/architecture/redundancy.md), [Error Handling](https://banes-lab.com/records/architecture/error-handling.md)

Reinforces
[Resilience](https://banes-lab.com/records/architecture/resilience.md)

Enables
[Continued Operation Under Failure](https://banes-lab.com/records/lexicon/continued-operation-under-failure.md)

In tension with
[Cost](https://banes-lab.com/records/lexicon/cost.md)

Conflicts with
[Single Point of Failure](https://banes-lab.com/records/lexicon/single-point-of-failure.md)

Referenced by
[Leader Election](https://banes-lab.com/records/architecture/leader-election.md), [Consensus](https://banes-lab.com/records/architecture/consensus.md), [Graceful Degradation](https://banes-lab.com/records/architecture/graceful-degradation.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Retry Pattern](https://banes-lab.com/records/architecture/retry-pattern.md), [Circuit Breaker Pattern](https://banes-lab.com/records/architecture/circuit-breaker-pattern.md), [Redundancy](https://banes-lab.com/records/architecture/redundancy.md), [Chaos Engineering](https://banes-lab.com/records/architecture/chaos-engineering.md), [RAID Redundancy](https://banes-lab.com/records/architecture/raid-redundancy.md)

Tensions
[Fault Tolerance / Cost](https://banes-lab.com/records/tension/cost-fault-tolerance.md)

Violated by
unrecoverable dependency failure

Detected by
no retry/failover/fallback for critical path

Measured by
failure recovery rate, [availability](https://banes-lab.com/records/lexicon/availability.md)

Refactored by
Add Retry, [Failover](https://banes-lab.com/records/architecture/failover.md), [Redundancy](https://banes-lab.com/records/architecture/redundancy.md)

Enforced by
resilience tests

Before

```typescript
const foo = await fooReplicaA.read(id);
```

After

```typescript
const foo = await firstSuccessful([
() => fooReplicaA.read(id),
() => fooReplicaB.read(id),
() => fooReplicaC.read(id),
]);
```

How it is checked

Checked by
resilience tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Redundancy](https://banes-lab.com/records/architecture/redundancy.md), [Error Handling](https://banes-lab.com/records/architecture/error-handling.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Continued Operation Under Failure](https://banes-lab.com/records/lexicon/continued-operation-under-failure.md)

Shape it refuses
[Single Point of Failure](https://banes-lab.com/records/lexicon/single-point-of-failure.md)

### Resilience

- Kind: [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: production systems
- Scope: service, system, infrastructure
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
The degree to which a system contains failures, stays stable under stress and recovers.

Requires
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Observability](https://banes-lab.com/records/architecture/observability.md)

Reinforces
[Self-Healing Architecture](https://banes-lab.com/records/architecture/self-healing-architecture.md), [Recovery](https://banes-lab.com/records/lexicon/recovery.md)

Enables
[Stability Under Stress](https://banes-lab.com/records/lexicon/stability-under-stress.md)

In tension with
[Complexity](https://banes-lab.com/records/lexicon/complexity.md)

Conflicts with
[Brittle Architecture](https://banes-lab.com/records/lexicon/brittle-architecture.md)

Referenced by
[Service Discovery](https://banes-lab.com/records/architecture/service-discovery.md), [Decentralization](https://banes-lab.com/records/architecture/decentralization.md), [Autonomy](https://banes-lab.com/records/architecture/autonomy.md), [Message Queue](https://banes-lab.com/records/architecture/message-queue.md), [Asynchronous Communication](https://banes-lab.com/records/architecture/asynchronous-communication.md), [Compensating Transaction](https://banes-lab.com/records/architecture/compensating-transaction.md), [Fail Safe](https://banes-lab.com/records/architecture/fail-safe.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Error Handling](https://banes-lab.com/records/architecture/error-handling.md), [Error Boundaries](https://banes-lab.com/records/architecture/error-boundaries.md), [Backpressure](https://banes-lab.com/records/architecture/backpressure.md), [Observability](https://banes-lab.com/records/architecture/observability.md), [Statelessness](https://banes-lab.com/records/architecture/statelessness.md), [Self-Healing Architecture](https://banes-lab.com/records/architecture/self-healing-architecture.md), [Rollback](https://banes-lab.com/records/architecture/rollback.md)

Tensions
[Resilience / Complexity](https://banes-lab.com/records/tension/complexity-resilience.md)

Distinct from
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md): Resilience contains failures and recovers from them, while fault tolerance keeps operating correctly while components are failing.

Distinct from
[Low Coupling](https://banes-lab.com/records/architecture/low-coupling.md): Resilience is surviving failure, while low coupling is surviving change.

Distinct from
[Observability](https://banes-lab.com/records/architecture/observability.md): Resilience is containing and recovering from failure, while observability is seeing what the system does.

Distinct from
[Complexity](https://banes-lab.com/records/lexicon/complexity.md): Resilience is surviving failure, while complexity is the intricacy that its mechanisms add.

Distinct from
[Debuggability](https://banes-lab.com/records/lexicon/debuggability.md): Resilience is recovering without help, while debuggability is how easily the developer can locate a fault.

Distinct from
[Stability](https://banes-lab.com/records/lexicon/stability.md): Resilience includes recovery after failure, while stability is steady operation under load without collapse.

Violated by
cascading failures

Detected by
[failure propagation](https://banes-lab.com/records/lexicon/failure-propagation.md), lack of isolation

Measured by
MTTR, error budget, [availability](https://banes-lab.com/records/lexicon/availability.md)

Refactored by
Add Circuit Breaker, Bulkhead, [Retry](https://banes-lab.com/records/lexicon/retry.md), [Timeout](https://banes-lab.com/records/lexicon/timeout.md)

Enforced by
[chaos testing](https://banes-lab.com/records/reasoning/technique-chaos-testing.md), SLO gates

Before

```typescript
async function loadFoo(id: FooId) { return remoteFoo.get(id); }
```

After

```typescript
async function loadFoo(id: FooId) {
return circuitBreaker.execute(() => retry.withBackoff(() => remoteFoo.get(id), { attempts: 3 }));
}
```

How it is checked

Checked by
chaos testing, SLO gates

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Observability](https://banes-lab.com/records/architecture/observability.md), [Self-Healing Architecture](https://banes-lab.com/records/architecture/self-healing-architecture.md), [Recovery](https://banes-lab.com/records/lexicon/recovery.md), [Stability Under Stress](https://banes-lab.com/records/lexicon/stability-under-stress.md)

Shape it refuses
[Brittle Architecture](https://banes-lab.com/records/lexicon/brittle-architecture.md)

### Robustness Principle

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: protocol, API, input processing
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that a component is strict in what it sends and tolerant of harmless variation in what it receives.

Requires
[Strict Output](https://banes-lab.com/records/lexicon/strict-output.md), [Tolerant Input](https://banes-lab.com/records/lexicon/tolerant-input.md)

Reinforces
[Compatibility](https://banes-lab.com/records/lexicon/compatibility.md)

Enables
[Interoperability](https://banes-lab.com/records/architecture/interoperability.md)

In tension with
[Strict Validation](https://banes-lab.com/records/lexicon/strict-validation.md)

Conflicts with
[Fragile Parsing](https://banes-lab.com/records/lexicon/fragile-parsing.md)

Tensions
[Robustness Principle / Strict Validation](https://banes-lab.com/records/tension/robustness-principle-strict-validation.md)

Violated by
rejecting harmless compatible input variations

Detected by
parser brittleness

Measured by
compatibility failure rate

Refactored by
Normalize Input, Validate Semantics

Enforced by
compatibility test suite

Before

```typescript
function readFoo(message: any) { return { id: message.id, name: message.name }; }
function writeFoo(foo: Foo) { return { ...foo, debug: globalThis }; }
```

After

```typescript
function readFoo(message: unknown) {
const value = FooEnvelopeSchema.parse(message);
return { id: value.id, name: value.name };
}
function writeFoo(foo: Foo): FooEnvelopeV1 { return { version: 1, id: foo.id, name: foo.name }; }
```

How it is checked

Checked by
compatibility test suite

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Strict Output](https://banes-lab.com/records/lexicon/strict-output.md), [Tolerant Input](https://banes-lab.com/records/lexicon/tolerant-input.md), [Compatibility](https://banes-lab.com/records/lexicon/compatibility.md), [Interoperability](https://banes-lab.com/records/architecture/interoperability.md)

Shape it refuses
[Fragile Parsing](https://banes-lab.com/records/lexicon/fragile-parsing.md)

### Error Handling

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: function, module, service
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design rule that every error is either handled with its context kept, or propagated as a typed error the caller must handle.

Requires
[Error Model](https://banes-lab.com/records/lexicon/error-model.md), [Observability](https://banes-lab.com/records/architecture/observability.md)

Reinforces
[Resilience](https://banes-lab.com/records/architecture/resilience.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[Controlled Failure](https://banes-lab.com/records/lexicon/controlled-failure.md)

In tension with
[Simplicity](https://banes-lab.com/records/lexicon/simplicity.md)

Conflicts with
[Exception Swallowing](https://banes-lab.com/records/lexicon/exception-swallowing.md), [Exception Control Flow](https://banes-lab.com/records/architecture/exception-control-flow.md)

Referenced by
[Defensive Programming](https://banes-lab.com/records/architecture/defensive-programming.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)

Tensions
[Error Handling / Simplicity](https://banes-lab.com/records/tension/error-handling-simplicity.md)

Violated by
ignored errors, generic catches, lost context

Detected by
empty catch blocks, unchecked result errors

Measured by
unhandled error count

Refactored by
Add Error Type, Propagate Context, Handle Explicitly

Enforced by
linting, [tests](https://banes-lab.com/records/lexicon/tests.md)

Refused by rules
error-handling

Before

```typescript
async function loadFoo(id: FooId) {
try { return await fooStore.find(id); } catch { return null; }
}
```

After

```typescript
type LoadFooResult =
| { ok: true; value: Foo }
| { ok: false; error: "NOT_FOUND" | "STORE_UNAVAILABLE" };
async function loadFoo(id: FooId): Promise<LoadFooResult> {
return fooStore.findResult(id);
}
```

How it is checked

Checked by
linting, tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Error Model](https://banes-lab.com/records/lexicon/error-model.md), [Observability](https://banes-lab.com/records/architecture/observability.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Controlled Failure](https://banes-lab.com/records/lexicon/controlled-failure.md)

Shape it refuses
[Exception Swallowing](https://banes-lab.com/records/lexicon/exception-swallowing.md), [Exception Control Flow](https://banes-lab.com/records/architecture/exception-control-flow.md)

### Error Boundaries

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: component, UI, service boundary
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design pattern that catches failures at a component boundary, so a failing part renders or returns an error while the rest keeps running.

Requires
[Failure Isolation](https://banes-lab.com/records/lexicon/failure-isolation.md)

Reinforces
[Resilience](https://banes-lab.com/records/architecture/resilience.md)

Enables
[Localized Recovery](https://banes-lab.com/records/lexicon/localized-recovery.md)

In tension with
[Hidden Errors](https://banes-lab.com/records/lexicon/hidden-errors.md)

Conflicts with
[Failure Propagation](https://banes-lab.com/records/lexicon/failure-propagation.md)

Tensions
[Error Boundaries / Hidden Errors](https://banes-lab.com/records/tension/error-boundaries-hidden-errors.md)

Violated by
uncontained failures crashing whole system

Detected by
uncaught exceptions crossing boundary

Measured by
blast radius

Refactored by
Add Boundary Handler, Isolate Component

Enforced by
failure tests

Before

```typescript
function renderApp() { return renderFooPanel(loadFoo()); }
```

After

```typescript
function FooBoundary({ render }: { render(): View }) {
try { return render(); }
catch (error) { return renderFooError(toFooError(error)); }
}
const app = FooBoundary({ render: () => renderFooPanel(loadFoo()) });
```

How it is checked

Checked by
failure tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Failure Isolation](https://banes-lab.com/records/lexicon/failure-isolation.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Localized Recovery](https://banes-lab.com/records/lexicon/localized-recovery.md)

Shape it refuses
[Failure Propagation](https://banes-lab.com/records/lexicon/failure-propagation.md)

### Fallback Pattern

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: service, dependency call
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design pattern that routes a failed call to an alternate provider or response declared in advance.

Requires
[Alternate Behavior](https://banes-lab.com/records/lexicon/alternate-behavior.md)

Reinforces
[Graceful Degradation](https://banes-lab.com/records/architecture/graceful-degradation.md)

Enables
[Partial Availability](https://banes-lab.com/records/lexicon/partial-availability.md)

In tension with
[Stale/Reduced Results](https://banes-lab.com/records/lexicon/stale-reduced-results.md)

Conflicts with
[Single Behavior Path](https://banes-lab.com/records/lexicon/single-behavior-path.md)

Tensions
[Fallback Pattern / Stale/Reduced Results](https://banes-lab.com/records/tension/fallback-pattern-stale-reduced-results.md)

Violated by
no alternate path for noncritical dependency

Detected by
hard dependency in optional path

Measured by
fallback coverage

Refactored by
Add Fallback Response/Provider

Enforced by
failure injection tests

Before

```typescript
const foo = await primaryFooStore.find(id);
```

After

```typescript
const foo = await primaryFooStore.find(id).catch(() => replicaFooStore.find(id));
if (!foo) throw new FooUnavailableError(id);
```

How it is checked

Checked by
failure injection tests

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Alternate Behavior](https://banes-lab.com/records/lexicon/alternate-behavior.md), [Graceful Degradation](https://banes-lab.com/records/architecture/graceful-degradation.md), [Partial Availability](https://banes-lab.com/records/lexicon/partial-availability.md)

Shape it refuses
[Single Behavior Path](https://banes-lab.com/records/lexicon/single-behavior-path.md)

### Retry Pattern

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: network, IO, message handling
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design pattern that repeats an idempotent call after a transient failure, a bounded number of times with backoff.

Requires
[Idempotency](https://banes-lab.com/records/architecture/idempotency.md), [Timeout](https://banes-lab.com/records/lexicon/timeout.md), [Backoff](https://banes-lab.com/records/lexicon/backoff.md)

Reinforces
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)

Enables
[Transient Failure Recovery](https://banes-lab.com/records/lexicon/transient-failure-recovery.md)

In tension with
[Load Amplification](https://banes-lab.com/records/lexicon/load-amplification.md)

Conflicts with
[Non-Idempotent Operation](https://banes-lab.com/records/lexicon/non-idempotent-operation.md)

Tensions
[Retry Pattern / Load Amplification](https://banes-lab.com/records/tension/load-amplification-retry-pattern.md)

Violated by
blind retry without backoff/idempotency

Detected by
retry loops without timeout/backoff

Measured by
retry success rate, retry storm rate

Refactored by
Add Exponential Backoff, Idempotency Key

Enforced by
resilience libraries, policy checks

Before

```typescript
await remoteFoo.save(foo);
```

After

```typescript
await retry.withBackoff(
() => remoteFoo.save(foo),
{ attempts: 3, retryIf: isTransientError, jitter: true },
);
```

How it is checked

Checked by
resilience libraries, policy checks

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Idempotency](https://banes-lab.com/records/architecture/idempotency.md), [Timeout](https://banes-lab.com/records/lexicon/timeout.md), [Backoff](https://banes-lab.com/records/lexicon/backoff.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Transient Failure Recovery](https://banes-lab.com/records/lexicon/transient-failure-recovery.md)

Shape it refuses
[Non-Idempotent Operation](https://banes-lab.com/records/lexicon/non-idempotent-operation.md)

### Timeout Pattern

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: network, IO, dependency call
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design pattern that gives every external call a time budget and fails the call when the budget runs out.

Requires
[Time Budget](https://banes-lab.com/records/lexicon/time-budget.md)

Reinforces
[Fault Isolation](https://banes-lab.com/records/lexicon/fault-isolation.md)

Enables
[Bounded Waiting](https://banes-lab.com/records/lexicon/bounded-waiting.md)

In tension with
[Slow Operation Tolerance](https://banes-lab.com/records/lexicon/slow-operation-tolerance.md)

Conflicts with
[Timeout Omission](https://banes-lab.com/records/architecture/timeout-omission.md)

Tensions
[Timeout Pattern / Slow Operation Tolerance](https://banes-lab.com/records/tension/slow-operation-tolerance-timeout-pattern.md)

Violated by
external calls without timeout

Detected by
missing timeout config

Measured by
timeout coverage, latency tail

Refactored by
Add Timeout, Propagate Deadline

Enforced by
lint/config checks

Before

```typescript
const foo = await remoteFoo.find(id);
```

After

```typescript
const foo = await withTimeout(remoteFoo.find(id), 500, () => new FooTimeoutError(id));
```

How it is checked

Checked by
lint/config checks

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Time Budget](https://banes-lab.com/records/lexicon/time-budget.md), [Fault Isolation](https://banes-lab.com/records/lexicon/fault-isolation.md), [Bounded Waiting](https://banes-lab.com/records/lexicon/bounded-waiting.md)

Shape it refuses
[Timeout Omission](https://banes-lab.com/records/architecture/timeout-omission.md), [Timeout Omission](https://banes-lab.com/records/architecture/timeout-omission.md)

### Circuit Breaker Pattern

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: dependency call, service
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design pattern that stops calling a dependency after repeated failures and probes it again after a wait.

Requires
[Failure Threshold](https://banes-lab.com/records/lexicon/failure-threshold.md), [Fallback](https://banes-lab.com/records/lexicon/fallback.md)

Reinforces
[Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Backpressure](https://banes-lab.com/records/architecture/backpressure.md)

Enables
[Cascading Failure Prevention](https://banes-lab.com/records/lexicon/cascading-failure-prevention.md)

In tension with
[Availability of Degraded Dependency](https://banes-lab.com/records/lexicon/availability-of-degraded-dependency.md)

Conflicts with
[Unbounded Retry](https://banes-lab.com/records/lexicon/unbounded-retry.md), [Retry Storm](https://banes-lab.com/records/architecture/retry-storm.md)

Tensions
[Circuit Breaker Pattern / Availability of Degraded Dependency](https://banes-lab.com/records/tension/availability-of-degraded-dependency-circuit-breaker-pattern.md)

Violated by
continuing calls to failing dependency

Detected by
high failure dependency calls without breaker

Measured by
breaker trip rate, downstream error rate

Refactored by
Add Circuit Breaker

Enforced by
[resilience policy](https://banes-lab.com/records/algorithms/resilience-policy.md)

Before

```typescript
async function loadFoo(id: FooId) { return remoteFoo.find(id); }
```

After

```typescript
const fooBreaker = new CircuitBreaker({ failureThreshold: 5, resetAfterMs: 30_000 });
async function loadFoo(id: FooId) {
return fooBreaker.execute(() => remoteFoo.find(id));
}
```

How it is checked

Checked by
resilience policy

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Failure Threshold](https://banes-lab.com/records/lexicon/failure-threshold.md), [Fallback](https://banes-lab.com/records/lexicon/fallback.md), [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md), [Backpressure](https://banes-lab.com/records/architecture/backpressure.md), [Cascading Failure Prevention](https://banes-lab.com/records/lexicon/cascading-failure-prevention.md)

Shape it refuses
[Unbounded Retry](https://banes-lab.com/records/lexicon/unbounded-retry.md), [Retry Storm](https://banes-lab.com/records/architecture/retry-storm.md)

### Bulkhead Pattern

- Kind: [pattern](https://banes-lab.com/records/kind/pattern.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: resource pool, service, runtime
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A design pattern that gives each workload its own pool of threads or connections, so one workload cannot exhaust the others.

Requires
[Resource Isolation](https://banes-lab.com/records/lexicon/resource-isolation.md)

Reinforces
[Fault Isolation](https://banes-lab.com/records/lexicon/fault-isolation.md)

Enables
[Blast-Radius Reduction](https://banes-lab.com/records/lexicon/blast-radius-reduction.md)

In tension with
[Resource Utilization](https://banes-lab.com/records/architecture/resource-utilization.md)

Conflicts with
[Shared Resource Pool](https://banes-lab.com/records/lexicon/shared-resource-pool.md)

Tensions
[Bulkhead Pattern / Resource Utilization](https://banes-lab.com/records/tension/bulkhead-pattern-resource-utilization.md)

Violated by
one dependency consuming all threads/connections

Detected by
shared pools across critical/noncritical workloads

Measured by
resource saturation isolation

Refactored by
Split Resource Pools, Add Isolation

Enforced by
resource policy

Before

```typescript
const pool = new WorkerPool(100);
pool.submit(fooTask);
pool.submit(barTask);
```

After

```typescript
const fooPool = new WorkerPool(20);
const barPool = new WorkerPool(20);
fooPool.submit(fooTask);
barPool.submit(barTask);
```

How it is checked

Checked by
resource policy

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Resource Isolation](https://banes-lab.com/records/lexicon/resource-isolation.md), [Fault Isolation](https://banes-lab.com/records/lexicon/fault-isolation.md), [Blast-Radius Reduction](https://banes-lab.com/records/lexicon/blast-radius-reduction.md)

Shape it refuses
[Shared Resource Pool](https://banes-lab.com/records/lexicon/shared-resource-pool.md)

### Backpressure

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Error Handling / Resilience](https://banes-lab.com/ontology/principles/architecture-category-error-handling-resilience.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: high-load systems
- Scope: stream, queue, service
- Layer: [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)

Details

Definition
A mechanism that lets a consumer signal its capacity, so a producer slows down when the consumer falls behind.

Requires
[Capacity Signaling](https://banes-lab.com/records/lexicon/capacity-signaling.md)

Reinforces
[Resilience](https://banes-lab.com/records/architecture/resilience.md), [Stability](https://banes-lab.com/records/lexicon/stability.md)

Enables
[Overload Protection](https://banes-lab.com/records/lexicon/overload-protection.md)

In tension with
[Throughput](https://banes-lab.com/records/architecture/throughput.md)

Conflicts with
[Missing Backpressure](https://banes-lab.com/records/architecture/missing-backpressure.md)

Referenced by
[Message Queue](https://banes-lab.com/records/architecture/message-queue.md), [Circuit Breaker Pattern](https://banes-lab.com/records/architecture/circuit-breaker-pattern.md), [Rate Limiting](https://banes-lab.com/records/architecture/rate-limiting.md), [Streaming Architecture](https://banes-lab.com/records/architecture/streaming-architecture.md)

Tensions
[Backpressure / Throughput](https://banes-lab.com/records/tension/backpressure-throughput.md)

Distinct from
[Event Stream](https://banes-lab.com/records/architecture/event-stream.md): Backpressure is a consumer slowing its producer, while an event stream is the replayable log consumers read from their own offset.

Distinct from
[Message Queue](https://banes-lab.com/records/architecture/message-queue.md): Backpressure signals capacity back to the producer, while a message queue holds messages until a consumer takes them.

Distinct from
[Rate Limiting](https://banes-lab.com/records/architecture/rate-limiting.md): Backpressure slows a producer by the consumer's live capacity, while rate limiting caps a caller at a fixed rate and rejects the excess.

Violated by
unbounded queues, uncontrolled producers

Detected by
queue growth without throttling

Measured by
queue depth, rejection/throttle rate

Refactored by
Add Rate Limit, Bounded Queue, Demand Signal

Enforced by
load tests, runtime policies

Before

```typescript
stream.on("data", foo => processFoo(foo));
```

After

```typescript
for await (const foo of stream) {
await capacity.acquire();
void processFoo(foo).finally(() => capacity.release());
}
```

How it is checked

Checked by
load tests, runtime policies

Population
Every failure path: catch blocks, dependency calls, input boundaries and fallbacks

Freshness
A verdict stands until a dependency, a failure path or the resilience policy changes

Refusal
The lint rule, failure-injection test or policy check fails the change that leaves a failure path unhandled or unsafe

Observation
Catch blocks and dependency calls read from source, plus outcomes recorded by failure-injection runs

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The resilience policy, which every failure path conforms to

Depends on
[Capacity Signaling](https://banes-lab.com/records/lexicon/capacity-signaling.md), [Resilience](https://banes-lab.com/records/architecture/resilience.md), [Stability](https://banes-lab.com/records/lexicon/stability.md), [Overload Protection](https://banes-lab.com/records/lexicon/overload-protection.md)

Shape it refuses
[Missing Backpressure](https://banes-lab.com/records/architecture/missing-backpressure.md), [Missing Backpressure](https://banes-lab.com/records/architecture/missing-backpressure.md)

## Links to

- [principle](https://banes-lab.com/records/kind/principle.md)
- [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- [Correctness Core](https://banes-lab.com/records/layer/correctness-core.md)
- [Input Validation](https://banes-lab.com/records/architecture/input-validation.md)
- [Error Handling](https://banes-lab.com/records/architecture/error-handling.md)
- [Robustness](https://banes-lab.com/records/lexicon/robustness.md)
- [Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md)
- [Safe Failure](https://banes-lab.com/records/lexicon/safe-failure.md)
- [Verbosity](https://banes-lab.com/records/lexicon/verbosity.md)
- [Trusting Invalid Inputs](https://banes-lab.com/records/lexicon/trusting-invalid-inputs.md)
- [Defensive Programming / Verbosity](https://banes-lab.com/records/tension/defensive-programming-verbosity.md)
- [Tests](https://banes-lab.com/records/lexicon/tests.md)
- [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- [Preconditions](https://banes-lab.com/records/architecture/preconditions.md)
- [Validation](https://banes-lab.com/records/architecture/validation.md)
- [Correctness](https://banes-lab.com/records/architecture/correctness.md)
- [Observability](https://banes-lab.com/records/architecture/observability.md)
- [Early Defect Detection](https://banes-lab.com/records/lexicon/early-defect-detection.md)
- [Graceful Degradation](https://banes-lab.com/records/architecture/graceful-degradation.md)
- [Silent Failure](https://banes-lab.com/records/lexicon/silent-failure.md)
- [Silent Data Corruption](https://banes-lab.com/records/architecture/silent-data-corruption.md)
- [Defensive Programming](https://banes-lab.com/records/architecture/defensive-programming.md)
- [Schema Validation](https://banes-lab.com/records/architecture/schema-validation.md)
- [Correctness Core](https://banes-lab.com/records/algorithms/correctness-core.md)
- [Fail Fast / Graceful Degradation](https://banes-lab.com/records/tension/fail-fast-graceful-degradation.md)
- [Design by Contract](https://banes-lab.com/records/architecture/design-by-contract.md)
- [Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md)
- [Resilience](https://banes-lab.com/records/architecture/resilience.md)
- [Damage Limitation](https://banes-lab.com/records/lexicon/damage-limitation.md)
- [Availability](https://banes-lab.com/records/lexicon/availability.md)
- [Unsafe Default Continuation](https://banes-lab.com/records/lexicon/unsafe-default-continuation.md)
- [Fail Safe / Availability](https://banes-lab.com/records/tension/availability-fail-safe.md)
- [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md)
- [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)
- [Deny-by-Default Behavior](https://banes-lab.com/records/lexicon/deny-by-default-behavior.md)
- [Fail Open](https://banes-lab.com/records/lexicon/fail-open.md)
- [Fail Secure / Availability](https://banes-lab.com/records/tension/availability-fail-secure.md)
- [Fallback](https://banes-lab.com/records/lexicon/fallback.md)
- [Feature Isolation](https://banes-lab.com/records/lexicon/feature-isolation.md)
- [Fault Tolerance](https://banes-lab.com/records/architecture/fault-tolerance.md)
- [Partial Availability](https://banes-lab.com/records/lexicon/partial-availability.md)
- [Consistency / Feature Completeness](https://banes-lab.com/records/lexicon/consistency-feature-completeness.md)
- [All-Or-Nothing Failure](https://banes-lab.com/records/lexicon/all-or-nothing-failure.md)
- [Fallback Pattern](https://banes-lab.com/records/architecture/fallback-pattern.md)
- [Graceful Degradation / Consistency / Feature Completeness](https://banes-lab.com/records/tension/consistency-feature-completeness-graceful-degradation.md)
- [quality-attribute](https://banes-lab.com/records/kind/quality-attribute.md)
- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- [Redundancy](https://banes-lab.com/records/architecture/redundancy.md)
- [Continued Operation Under Failure](https://banes-lab.com/records/lexicon/continued-operation-under-failure.md)
- [Cost](https://banes-lab.com/records/lexicon/cost.md)
- [Single Point of Failure](https://banes-lab.com/records/lexicon/single-point-of-failure.md)
- [Leader Election](https://banes-lab.com/records/architecture/leader-election.md)
- [Consensus](https://banes-lab.com/records/architecture/consensus.md)
- [Retry Pattern](https://banes-lab.com/records/architecture/retry-pattern.md)
- [Circuit Breaker Pattern](https://banes-lab.com/records/architecture/circuit-breaker-pattern.md)
- [Chaos Engineering](https://banes-lab.com/records/architecture/chaos-engineering.md)
- [RAID Redundancy](https://banes-lab.com/records/architecture/raid-redundancy.md)
- [Fault Tolerance / Cost](https://banes-lab.com/records/tension/cost-fault-tolerance.md)
- [Failover](https://banes-lab.com/records/architecture/failover.md)
- [Self-Healing Architecture](https://banes-lab.com/records/architecture/self-healing-architecture.md)
- [Recovery](https://banes-lab.com/records/lexicon/recovery.md)
- [Stability Under Stress](https://banes-lab.com/records/lexicon/stability-under-stress.md)
- [Complexity](https://banes-lab.com/records/lexicon/complexity.md)
- [Brittle Architecture](https://banes-lab.com/records/lexicon/brittle-architecture.md)
- [Service Discovery](https://banes-lab.com/records/architecture/service-discovery.md)
- [Decentralization](https://banes-lab.com/records/architecture/decentralization.md)
- [Autonomy](https://banes-lab.com/records/architecture/autonomy.md)
- [Message Queue](https://banes-lab.com/records/architecture/message-queue.md)
- [Asynchronous Communication](https://banes-lab.com/records/architecture/asynchronous-communication.md)
- [Compensating Transaction](https://banes-lab.com/records/architecture/compensating-transaction.md)
- [Fail Safe](https://banes-lab.com/records/architecture/fail-safe.md)
- [Error Boundaries](https://banes-lab.com/records/architecture/error-boundaries.md)
- [Backpressure](https://banes-lab.com/records/architecture/backpressure.md)
- [Statelessness](https://banes-lab.com/records/architecture/statelessness.md)
- [Rollback](https://banes-lab.com/records/architecture/rollback.md)
- [Resilience / Complexity](https://banes-lab.com/records/tension/complexity-resilience.md)
- [Low Coupling](https://banes-lab.com/records/architecture/low-coupling.md)
- [Debuggability](https://banes-lab.com/records/lexicon/debuggability.md)
- [Stability](https://banes-lab.com/records/lexicon/stability.md)
- [Failure Propagation](https://banes-lab.com/records/lexicon/failure-propagation.md)
- [Retry](https://banes-lab.com/records/lexicon/retry.md)
- [Timeout](https://banes-lab.com/records/lexicon/timeout.md)
- [Chaos Testing](https://banes-lab.com/records/reasoning/technique-chaos-testing.md)
- [Strict Output](https://banes-lab.com/records/lexicon/strict-output.md)
- [Tolerant Input](https://banes-lab.com/records/lexicon/tolerant-input.md)
- [Compatibility](https://banes-lab.com/records/lexicon/compatibility.md)
- [Interoperability](https://banes-lab.com/records/architecture/interoperability.md)
- [Strict Validation](https://banes-lab.com/records/lexicon/strict-validation.md)
- [Fragile Parsing](https://banes-lab.com/records/lexicon/fragile-parsing.md)
- [Robustness Principle / Strict Validation](https://banes-lab.com/records/tension/robustness-principle-strict-validation.md)
- [Error Model](https://banes-lab.com/records/lexicon/error-model.md)
- [Controlled Failure](https://banes-lab.com/records/lexicon/controlled-failure.md)
- [Simplicity](https://banes-lab.com/records/lexicon/simplicity.md)
- [Exception Swallowing](https://banes-lab.com/records/lexicon/exception-swallowing.md)
- [Exception Control Flow](https://banes-lab.com/records/architecture/exception-control-flow.md)
- [Error Handling / Simplicity](https://banes-lab.com/records/tension/error-handling-simplicity.md)
- [pattern](https://banes-lab.com/records/kind/pattern.md)
- [Failure Isolation](https://banes-lab.com/records/lexicon/failure-isolation.md)
- [Localized Recovery](https://banes-lab.com/records/lexicon/localized-recovery.md)
- [Hidden Errors](https://banes-lab.com/records/lexicon/hidden-errors.md)
- [Error Boundaries / Hidden Errors](https://banes-lab.com/records/tension/error-boundaries-hidden-errors.md)
- [Alternate Behavior](https://banes-lab.com/records/lexicon/alternate-behavior.md)
- [Stale/Reduced Results](https://banes-lab.com/records/lexicon/stale-reduced-results.md)
- [Single Behavior Path](https://banes-lab.com/records/lexicon/single-behavior-path.md)
- [Fallback Pattern / Stale/Reduced Results](https://banes-lab.com/records/tension/fallback-pattern-stale-reduced-results.md)
- [Idempotency](https://banes-lab.com/records/architecture/idempotency.md)
- [Backoff](https://banes-lab.com/records/lexicon/backoff.md)
- [Transient Failure Recovery](https://banes-lab.com/records/lexicon/transient-failure-recovery.md)
- [Load Amplification](https://banes-lab.com/records/lexicon/load-amplification.md)
- [Non-Idempotent Operation](https://banes-lab.com/records/lexicon/non-idempotent-operation.md)
- [Retry Pattern / Load Amplification](https://banes-lab.com/records/tension/load-amplification-retry-pattern.md)
- [Time Budget](https://banes-lab.com/records/lexicon/time-budget.md)
- [Fault Isolation](https://banes-lab.com/records/lexicon/fault-isolation.md)
- [Bounded Waiting](https://banes-lab.com/records/lexicon/bounded-waiting.md)
- [Slow Operation Tolerance](https://banes-lab.com/records/lexicon/slow-operation-tolerance.md)
- [Timeout Omission](https://banes-lab.com/records/architecture/timeout-omission.md)
- [Timeout Pattern / Slow Operation Tolerance](https://banes-lab.com/records/tension/slow-operation-tolerance-timeout-pattern.md)
- [Failure Threshold](https://banes-lab.com/records/lexicon/failure-threshold.md)
- [Cascading Failure Prevention](https://banes-lab.com/records/lexicon/cascading-failure-prevention.md)
- [Availability of Degraded Dependency](https://banes-lab.com/records/lexicon/availability-of-degraded-dependency.md)
- [Unbounded Retry](https://banes-lab.com/records/lexicon/unbounded-retry.md)
- [Retry Storm](https://banes-lab.com/records/architecture/retry-storm.md)
- [Circuit Breaker Pattern / Availability of Degraded Dependency](https://banes-lab.com/records/tension/availability-of-degraded-dependency-circuit-breaker-pattern.md)
- [Resilience Policy](https://banes-lab.com/records/algorithms/resilience-policy.md)
- [Resource Isolation](https://banes-lab.com/records/lexicon/resource-isolation.md)
- [Blast-Radius Reduction](https://banes-lab.com/records/lexicon/blast-radius-reduction.md)
- [Resource Utilization](https://banes-lab.com/records/architecture/resource-utilization.md)
- [Shared Resource Pool](https://banes-lab.com/records/lexicon/shared-resource-pool.md)
- [Bulkhead Pattern / Resource Utilization](https://banes-lab.com/records/tension/bulkhead-pattern-resource-utilization.md)
- [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- [Capacity Signaling](https://banes-lab.com/records/lexicon/capacity-signaling.md)
- [Overload Protection](https://banes-lab.com/records/lexicon/overload-protection.md)
- [Throughput](https://banes-lab.com/records/architecture/throughput.md)
- [Missing Backpressure](https://banes-lab.com/records/architecture/missing-backpressure.md)
- [Rate Limiting](https://banes-lab.com/records/architecture/rate-limiting.md)
- [Streaming Architecture](https://banes-lab.com/records/architecture/streaming-architecture.md)
- [Backpressure / Throughput](https://banes-lab.com/records/tension/backpressure-throughput.md)
- [Event Stream](https://banes-lab.com/records/architecture/event-stream.md)

## Linked from

- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
- [The membership](https://banes-lab.com/ontology/schema/the-membership.md)
