Control Packs · REL-001 · v1.1.0

External Dependency Partial Failure

Define timeout, retry, reconciliation, degraded-mode, and rollback behavior when an external dependency is unavailable or ambiguous.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Make dependency failure states explicit and recoverable through bounded retries, idempotency, reconciliation, and operator-visible escalation.

  • Ambiguous partial failureThe local system cannot determine whether an external operation completed, leading to unsafe retries, duplicate actions, or silent divergence.
Versioned applicability rule
{
  "characteristic": "EXTERNAL_DEPENDENCY",
  "equals": true
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • What is the safe behavior when the dependency result is unknown?An unknown result must not be silently treated as success or safe to repeat.REL-001-Q1 · choice

Requirements for the coding agent

  • REL-001-R1Bound retries, preserve idempotency keys, record ambiguous outcomes, reconcile with the dependency, and expose unresolved operations for review.

Implementation recipe

Represent external operations as explicit state transitions so timeout, duplicate, unknown, retry-exhausted, reconciled, and terminal outcomes cannot be confused.

  1. Assign a stable idempotency key and local operation record before the external call.
  2. Set explicit connect, response, and total deadlines and a bounded retry budget.
  3. Treat timeout or ambiguous response as unknown, not success and not automatically safe to repeat.
  4. Reconcile unknown operations against the dependency before any retry that could duplicate a side effect.
  5. Expose exhausted or unreconciled operations to the confirmed review path and record the dependency outcome.
const operation = await beginOperation(idempotencyKey);
const result = await callWithDeadline(operation);
if (result.unknown) return holdForReconciliation(operation);
if (result.retryable && retryBudget.available) return retry(operation);
return finalize(operation, result);
  • The safe unknown-state behavior and retry limits remain user decisions unless already confirmed.

Tests and evidence to retain

  • PARTIAL_FAILURE_TESTExercise timeout, duplicate, retry exhaustion, ambiguous result, and reconciliation paths.
  • REL-001-V1 · Ambiguous dependency resultThe operation enters an explicit unknown state and is not blindly repeated.Evidence: Unknown-state record; No duplicate side effect; DEPENDENCY_FAILURE_EVENT record
  • REL-001-V2 · Retry exhaustionRetries stop, the local state remains reviewable, and the configured fail-closed or degraded behavior is used.Evidence: Attempt count; Retry-budget decision; Operator-visible unresolved record
  • REL-001-V3 · Reconciliation after recoveryThe local record converges on the dependency's actual state without duplicating the external action.Evidence: Reconciliation query result; State transition record; Side-effect count
  • implementation_location
  • test_result
  • telemetry_definition
  • operational_procedure

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • CP-10 · System RecoveryNIST_SP_800_53_5_2_0 · partially addressesReconciliation and unresolved-operation handling support recovery from ambiguous dependency outcomes; they do not cover all contingencies.
  • SI-13 · Predictable Failure PreventionNIST_SP_800_53_5_2_0 · partially addressesBounded retries, idempotency, and explicit unknown state reduce predictable failure effects; they do not establish full prevention.
  • SI-17 · Fail-Safe ProceduresNIST_SP_800_53_5_2_0 · partially addressesHolding ambiguous results for reconciliation supports fail-safe behavior; it does not establish complete fail-safe procedures.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review