Design for Controlled Decay: When You Can't Prevent Failure, Schedule the Cut
The one-sentence claim
When a failure mode is baked into a structure and can't be engineered away, the choice isn't binary (fix it forever vs. let it fail catastrophically) — there's a third option: schedule a small, monitored, periodic correction and treat the degradation as an operating cost rather than a crisis.
Why this is in the vault
Three Practical Engineering sources give three variants of the same discipline. [[2026-04-20-practical-engineering-sawing-a-dam-in-half]] is the anchor case: TVA's Fontana Dam has alkali-silica reaction baked into its 1944 concrete (nothing removes ASR once it's in the aggregate), so the fix is a half-inch slot cut across the dam roughly every five years, instrumented and monitored, rather than a one-time structural overhaul. [[2026-04-20-practical-engineering-spillway-failed-on-purpose]] gives the engineered-sacrifice variant: fuse-plug spillways are designed to fail in a known, contained way before the main structure is threatened — the "cut" is pre-built into the design rather than scheduled after the fact. [[2026-04-20-practical-engineering-hidden-engineering-floating-bridges]] gives a third variant that generalizes the pattern furthest: Washington's floating bridges close to traffic above a wind threshold, not because anything is structurally wrong, but because the forcing (wind, wave action) can't be engineered out of a floating structure — so the response is operational, not structural. That third case is the one that sharpens the concept: some failure modes aren't engineering problems at all, they're scheduling-and-discipline problems, and conflating the two is how "we'll fix it properly later" becomes "we never fixed it."
Mapping against Ray Data Co
This maps onto vault and tech-debt hygiene directly, and is distinct from [[layered-defense-architecture]] (CA-016 is about defending against a failure that hasn't happened yet; CA-019 is about a failure mode that's already permanent and asks what the periodic maintenance shape should be). The monthly /compile-vault run is the slot-cut: link rot, orphaned docs, and stale indexes are the ASR of a growing markdown vault — they can't be prevented (any active vault accumulates them as a byproduct of normal writing), so the fix is a small scheduled correction rather than a one-time all-hands rewrite. The floating-bridge variant maps to rate-limit-aware scheduling: pausing cron skills during known Anthropic API congestion windows is choosing to close the bridge rather than pretending the wind isn't a structural load. The operational discipline this concept argues for, when scoping any new skill or maintenance loop: name which of the three variants applies (periodic slot-cut, pre-built sacrificial layer, or schedule-around-forcing) before deciding whether the fix belongs in code or in a cron cadence.
Related
- [[2026-04-20-practical-engineering-sawing-a-dam-in-half]] — canonical case, periodic slot-cutting as scheduled small mitigation
- [[2026-04-20-practical-engineering-spillway-failed-on-purpose]] — fuse-plug spillways as the engineered-controlled-failure variant
- [[2026-04-20-practical-engineering-hidden-engineering-floating-bridges]] — wind-threshold closure as the schedule-around-uncontrollable-forcing variant
- [[layered-defense-architecture]] — companion concept; that one is the how you defend, this one is the what you do once prevention has failed
- [[CANDIDATES]] — parent backlog; CA-019 origin trace
Confidence
Three sources, canon-tier promotion bar met, but all three are Practical Engineering — one channel, one voice. The civil-engineering pattern is well attested independently in the literature (bridge maintenance cycles, pipeline pigging schedules) but the vault doesn't have that independent confirming citation yet. The mapping to vault/cron maintenance is this write-up's own interpretation, not sourced — treat it as a working frame, and revisit if a software-engineering source (blue-green deploys, Erlang's let-it-crash supervisor pattern) lands and either confirms or complicates it.