Systems that survive disconnection.
WHAT TO ASSUME
Connectivity is intermittent, not exceptional.
WHAT THAT REQUIRES
Local operation continuing without the central system Local storage of what cannot be transmitted Queuing of actions and measurements Reconciliation on reconnection
WHAT TO DECIDE
What decisions can be made locally, and which require the centre.
WHY THAT MATTERS
Anything safety-critical must not depend on a connection.
WHAT BUFFERING REQUIRES
Enough local storage for the expected outage duration A policy for what to discard when full
WHAT TO DISCARD FIRST
Detail, keeping summaries.
WHAT RECONCILIATION MUST HANDLE
Data arriving out of order Duplicates from retries Conflicting changes made in both places
WHAT TO DEFINE
Which side wins, per data type.
WHAT TO TIMESTAMP
Everything, at the source, with the source's clock state recorded.
WHY
Clock skew at the edge is common and must be accounted for.
WHAT TO MONITOR
Which locations are connected, and how far behind each is.
WHAT TO ALERT ON
A location silent longer than expected.