Failure Museum.Made with ❤️ by Aniruddh Jangid
Submit a case

EXHIBIT 002 · IT & SOFTWARE

Facebook: a network that took itself offline

A backbone configuration change disrupted services and the internal tools needed to restore them.

OrganizationFacebook / Meta
Period2021
LocationGlobal
StatusRecovered
ImpactHigh
EvidenceTechnical postmortem
Compare

Illustrative draft · Source-backed synopsis · Museum analysis marked separately · Updated 5 October 2026

Facebook headquarters at 1 Hacker Way in Menlo Park; contextual company photograph.
Facebook headquarters at 1 Hacker Way in Menlo Park; contextual company photograph.LPS.1 Photograph · Context photograph; not the incident itself. · CC0 · Resized for display.
01 / EXECUTIVE SUMMARY

The outcome is only the beginning.

Facebook’s postmortem attributes the disruption to a backbone configuration change. The outage also affected internal systems and complicated recovery. [1][2]

THE PRINCIPLE TO CARRY FORWARD

Test an out-of-band recovery path with production routing, DNS, and identity services deliberately unavailable.

02 / THE PROMISE

What the system was trying to do.

Keep a global network of applications and data centers continuously reachable.

Museum interpretation

The assumption beneath the promise

recovery tools can appear independent while relying on the infrastructure they are meant to repair.

Success should be assessed against the intended service and its safety, reliability, or integrity constraints. A headline outcome cannot tell us whether those constraints were visible, tested, or owned before the event.

03 / WHAT HAPPENED

A sequence, not a single moment.

Change introduced

A maintenance command disconnected the backbone. [2]

Source-backed synopsis

Failure propagated

DNS and internal tools were affected. [2]

Source-backed synopsis

Services restored

Applications returned to operation. [1]

Source-backed synopsis

Learning published

The detailed postmortem described recovery constraints. [2]

Source-backed synopsis
Timeline of documented milestones. Gaps are not evidence that nothing happened. Sources: [1] [2]
04 / WARNING SIGNS

What could be seen at the time?

Documented in cited record

The detailed postmortem reports that a bug in an auditing tool failed to stop the command responsible for the outage. [2]

Who could see it?

See the cited investigation for named teams and the information they held. The synopsis does not infer awareness by every stakeholder.

Why was it not enough?

Signals need interpretation, authority, and a route to action. This is an analytical question, not proof that a warning was deliberately ignored.

05 / KEY DECISIONS

Choices made within constraints.

A command during backbone maintenance disconnected the data centers; dependent DNS and recovery tools were affected. [2]

Available alternatives

Pause, test, narrow the operating envelope, seek independent review, or build a recovery option. These are proposed analytical alternatives; feasibility at the time is not established.

Information available

The detailed postmortem reports that a bug in an auditing tool failed to stop the command responsible for the outage. [2]

Incentives & constraints

Delivery pressure, cost, authority, and incomplete knowledge may shape a decision. Their specific weight is not established by this synopsis.

Risk accepted

Ask whether the relevant risk was recognized, who had authority to accept it, and whether affected people understood its implications.

06 / SYSTEM MAP

How conditions connected.

Select a node to inspect its evidence. Links show a proposed analytical relationship, not a measured causal effect.

05 / External context04 / Warning signal03 / Decisions02 / Technical conditions01 / Trigger06 / Consequences
Triggering event

Facebook’s postmortem attributes the disruption to a backbone configuration change. The outage also affected internal systems and complicated recovery. [1][2]

Legend: numbered nodes = analytical categories; dashed arrows = proposed influence or propagation. Museum interpretation informed by the sources below. Feedback and omitted influences require further investigation.
07 / CONSEQUENCES

Beyond the immediate event.

People and businesses lost access to services. The company said it had no evidence of compromised user data from the outage. [1]

Customer impactOperational impactTechnical impact

Categories identify documented or relevant consequences. Financial, human, and environmental totals are not estimated here when the source base does not support them.

08 / WHAT THE MODELS EXPLAIN

More than one lens.

Analytical lens

Fault Tree Analysis

Work backward from a defined loss using logical combinations of conditions.

In this case, use the lens to examine coupled dependencies. This application is museum interpretation, not a finding of the original investigation.

Limit: Results depend on the chosen top event and completeness of branches.

Analytical lens

FMEA

Identify failure modes, their effects, and controls before or during system development.

In this case, use the lens to examine coupled dependencies. This application is museum interpretation, not a finding of the original investigation.

Limit: Lists can miss interactions and unanticipated operating conditions; scores are not exact probabilities.

Analytical lens

Systems thinking

Examine relationships, boundaries, feedback, and incentives across a whole system.

In this case, use the lens to examine coupled dependencies. This application is museum interpretation, not a finding of the original investigation.

Limit: A broad lens needs explicit boundaries and evidence to avoid explaining everything after the fact.

09 / COUNTERFACTUALS

What could have changed the outcome?

Counterfactuals are hypotheses. They identify possible intervention points without claiming that a different choice would certainly have prevented the event.

INTERVENTION 2 / During early testing

Test the operating envelope

Exercise realistic boundary conditions and shared dependencies rather than validating components only in isolation.

Cost & feasibility

Requires time and independent review before commitment.

Likely effectiveness

May reduce exposure or consequences. Not quantified; feasibility and effect must be assessed against evidence available at the time.

10 / LESSONS

From hindsight to a usable practice.

FOR FOUNDERS

Test an out-of-band recovery path with production routing, DNS, and identity services deliberately unavailable.

Before accelerating hiring or spending, name the assumptions that remain untested and set evidence thresholds for the next commitment.

11 / AFTERWARD

Recovery is another investigation.

Services were restored; the organization described work to improve infrastructure resilience. [1]

A corrective action is evidence of a response; it is not, by itself, evidence that the wider pattern has disappeared.

12 / SOURCES & EVIDENCE

Follow the record.

Documented claims are linked to sources. Analytical applications, lessons, and intervention proposals are museum interpretation. This draft does not establish motives or a single complete causal explanation.

  1. 1
    Facebook — outage update

    Technical postmortem · Accessed 4 October 2026

  2. 2
    Facebook — detailed postmortem

    Technical postmortem · Accessed 4 October 2026

Editorial history & limits

Version 1 · 4 October 2026 — source-backed illustrative synopsis created. Independent editorial review is pending. No claim of exhaustive investigation. New sources may alter the analysis.