Bulkheads contain failure
Ships survive holes because compartments stop water spreading. Systems work the same way.
Separating things so that the failure of one cannot consume the resources of the others, a connection pool, a thread pool, a shared database, is what stops a single slow dependency taking down everything that touches it. It is the same idea as segmentation applied to failure rather than to attackers.
More on Architecture patterns
- A jump host concentrates administrative entryOne plank, every crossing
- A bastion should not become a general-purpose workstationIt only has the one job
- Out-of-band management survives primary-path failureWhen the bridge is out
- A choke point makes control observableEverything through one gap
- A broker can separate clients from powerful credentialsChained to the bench
- A one-way gateway changes the threat modelWater does not fall upwards
