Redundant systems and the failure cascades
Redundancy means you have backup parts, backup power, backup sensors, and backup logic ready to kick in the instant something fails. A space vehicle has multiple computers, multiple oxygen tanks, multiple valves. SpaceX’s Dragon capsule uses four separate parachutes, even though two can land it safely. The space shuttle had three main engines and could lose one and still make orbit, barely. You duplicate critical components so a single failure doesn’t end the mission or the crew. It sounds obvious, but the devil lives in the cascade.
A failure cascade is what happens when one component breaks and takes out everything downstream. Imagine a pressure regulator fails in your oxygen line. That sends unregulated pressure into your tank. The tank bursts, puncturing the hull. The hull breach vents atmosphere, which depressurizes the cabin and exposes electronics to vacuum. Overvoltage from the damaged wiring shorts out your guidance computer. You lose attitude control. The vehicle tumbles. You die. That chain of events started with one regulator, a part that costs less than a hundred dollars. A single point of failure can kill you in seconds.
Engineers spend careers hunting these single points of failure. They use fault tree analysis, looking at every possible way a system can break and tracing the consequences backward. If a failure leads to loss of life and there is no backup, that part gets redesigned or duplicated. The goal is to eliminate any component whose failure automatically means you die. This is why modern spacecraft use triple-redundant computers. The Boeing 787 has three flight control computers voting on every command. If one disagrees, the other two override it. If two disagree, the third decides. The system keeps running even when parts are wrong.
But redundancy has limits. You cannot back up everything. A spacecraft has finite mass and power. Every extra valve, wire, or sensor adds weight and complexity. More parts mean more things that can break. This is the irony of redundancy: you sometimes add failure modes by trying to eliminate them. A backup oxygen tank has its own regulator, its own plumbing, its own valve that can leak. You now have two failure points instead of one. The trick is to make the backup path independent, simple, and more reliable than the primary. Designers use dissimilar redundancy, where the backup works on a different principle. If your electric pump fails, you have a manual hand pump. If your digital controller glitches, you have an analog override. Same job, different physics.
The worst failure cascades happen when the backup system shares a hidden flaw with the primary. During the Apollo 13 mission, an oxygen tank exploded because a heater switch was left on during a test. The heat damaged insulation on the wiring inside the tank. The damage went undetected. When the crew stirred the tank days later, the bare wires sparked and ignited the oxygen. That explosion blew a panel off the service module. It took out two of three fuel cells. The spacecraft lost power, water, and oxygen. The cascade nearly killed three men. The backup oxygen tank in the same bay was also damaged. It was physically redundant but not failure-independent. The same blast wrecked both.
Surviving a cascade requires isolation. You segment systems so a failure in one compartment doesn’t reach the next. The International Space Station has separate electrical buses, separate cooling loops, and separate oxygen generation units distributed across modules. If one module loses pressure, you close the hatches and the rest stays livable. Every critical system has a physical barrier, not just a software switch. You design for containment.
For a guy in his twenties reading this, the lesson applies beyond space. Your car has redundant braking circuits. Your phone has a backup battery shutdown. Your laptop has a surge protector. Those are cheap, simple redundancies designed to stop a cascade before it ruins your day. On a rocket, the stakes are higher. One leak, one corroded wire, one frozen valve, and the cascade is a fireball. Redundant systems buy you time, but only if the backup is truly separate, truly simpler, and truly ready. That is the narrow margin between surviving a failure and not surviving anything at all.
Space News
Latest Articles
New rockets, upcoming launches, and the stories shaping humanity's push off this planet. No astronomy degree required.


