Glossary · Automation software engineering and architecture
Graceful degradation
Also known as: Soft degradation
German: Kontrollierte Leistungsreduzierung
In systems and software engineering, graceful degradation is the ability of a system to keep providing its most important functions, possibly with reduced performance or features, when some of its components fail or resources become unavailable, instead of failing completely.
- Software engineering
In one sentence
Graceful degradation keeps a system's most important functions running with reduced performance when components fail.
Example
When the connection to the MES is lost, the line continues producing with the last downloaded orders and buffers production data locally until the connection returns.
How it applies
- Engineering: Graceful degradation requires deciding which functions are essential and which can be dropped, and designing components so failures stay contained. Techniques include Fallback values, local buffering, redundancy and reduced operating modes.
- Operation: Operators must know when the system is degraded and what that means. A silently degraded system can hide faults until a second failure causes a larger outage.
- Documentation: Operating documentation should describe each degraded state: how it is indicated, which functions are limited, how long the system can run that way and how to return to normal. These descriptions are often missing and are valuable for operators and service staff.
Graceful degradation vs. fail-safe behavior
Graceful degradation aims to keep functions available; Fail-safe behavior aims to reach a state without hazard, which may mean stopping. For safety functions, reaching a safe state takes priority over availability; continued operation in a Degraded mode must be justified in the risk assessment.