Database copies can end up on the same server, defeating the point of having copies
What we found
The main database platform runs several copies of each database so that losing one server does not take the service down. The rule meant to keep those copies on separate servers refers to a grouping this platform does not use, so in practice it does nothing.
Copies have generally landed on different servers anyway, but by luck rather than by design — nothing prevents two or three copies of the same database from sharing one server.
Impact
No outage has been caused by this. The risk is that the protection people believe is in place is not actually in place: if copies did share a server, losing it would take the whole database down rather than one copy of it.
Fix
Change the rule to refer to the individual server, and make it a requirement rather than a preference, so two copies of the same database can never share one.
0 Comments
Sign in to comment
No comments yet. Be the first to share your thoughts!
