The recognition that N+1 or 2N redundancy engineered within a single building offers no protection against an event, fire, flood, disaster, that affects the whole site.
The limits of intra-site redundancy refer to the recognition that a redundant architecture, N+1 or dual-chain 2N power, duplicated cooling, multiple generators, however robust, only protects against the failure of a single component within one building, not against an event that affects the entire site: fire, flood, natural disaster or total loss of external power. An operator can therefore display a high Tier certification, a mark of resilience to component failures, while remaining exposed to a total loss if the entire building is compromised by a peril that does not distinguish between primary and backup systems co-located in the same place. This distinction, often poorly understood outside a circle of specialized engineers, explains why a site rated very highly on its everyday operational availability can nonetheless suffer a total loss in a major disaster. For insurers, it means separately assessing resilience to routine failures, well captured by Tier classification, and resilience to catastrophic losses, which depends entirely on whether a recovery architecture exists on a geographically distinct site.
OVHcloud's Strasbourg site had standard internal redundancies, but the March 2021 fire showed these offer no protection against a loss affecting the entire building, unlike an architecture spread across several distant sites.
intra-site redundancy limits, redondance même site, single site risk