Journal

· guides

Fail-open classifiers can fail closed downstream

A classifier fallback preserved requests at one boundary, but the gateway still refused a tier with no admitted deployment.

A mechanical classifier sends one route toward an empty deployment socket and a verdigris fallback route toward an admitted deployment.

A component that fails open can still feed a system that fails closed. Our prompt classifier preserved requests under several faults. The gateway then turned one valid classification into a refusal.

The classifier protected its own boundary

Each request reaches the classifier behind a 100-millisecond timeout. A timeout, transport error, or unrecognized class selects the configured default tier. Each fallback increments a counter.

That behavior keeps classifier trouble from blocking the request. It also leaves a record of how often the service substitutes the default tier.

The service handles a missing or unreadable model artifact without entering a restart loop. Its container starts, and the liveness probe stays green.

The classify endpoint answers 503 while the model remains unavailable. A gauge reports the unloaded model. From the artifact’s head file, the service reads its served class list.

These choices make failure visible while keeping the service available for recovery. They prove that the classifier degrades at its own boundary.

The next query closed the route

The gateway treated the classified tier as a filter on its deployment query. That filter could select no admitted model.

An empty result left the gateway with nothing to call. The classifier had returned successfully, yet the caller received a refusal.

This defect sat between two reasonable local decisions. The classifier returned a permitted tier. In turn, the gateway respected that tier too literally.

Fail-open behavior therefore needs an end-to-end question: can every fallback value still select a usable downstream path?

The default tier now gets a second chance

The gateway now retries at the default tier when the classified tier selects no admitted deployment. If that retry finds a deployment, the request continues.

The gateway also counts the substitution. Operators can distinguish a direct tier match from a request rescued by the default tier.

This counter matters because successful recovery can hide a broken routing assumption. A fallback without a record turns a defect into quiet traffic drift.

The classifier still owns its timeout and error fallbacks. Now the gateway owns the empty deployment result that only its query can see.

The evidence stops at the control flow

This evidence comes from our Muniment Cloud note pinned to commit 04df7a7f19aea8696c6985cbffb9a226135549d8. It records the shipped design, the gateway defect, and the correction.

No benchmark ran. This note proves nothing about classifier accuracy, latency under load, or cost saving.

The result is narrower and more useful. A local fail-open contract needs a downstream path for every value it can emit.

Continue reading

All publications

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.