Operational notes Testing

“N+1” in a spec: ITU-T L.1202 calculates it, it does not test it

7 min read

Row of electrical switchgear cabinets with aligned circuit breaker handles, receding in perspective, black and white photograph
Every cubicle repeats the same aligned handle: redundancy shows in the row, it is proven only when someone opens one branch under load.

During a scheduled maintenance job on one power branch, a critical rack in a data centre loses power for a handful of seconds. The design declared “N+1 configuration”: the twin branch was supposed to pick up the load without anyone noticing. The automatic transfer switch exists, it is wired, it was visually inspected at commissioning. It had never been closed under the room’s real load, at the IT power actually installed. “N+1” was written on the design, in the specification, on the commissioning certificate. Nobody had ever put it to the test.

Six configurations, not a label

The only freely downloadable ITU-T Recommendation that describes in full the architecture of an up to 400 VDC power feeding system for data centres and telecommunication centres — ITU-T L.1204 (06/2016), Extended architecture of power feeding systems of up to 400 VDC, which extends the earlier L.1201 (03/2014), itself built on the electrical interface already fixed by L.1200 (05/2012) — we downloaded and read in full. It never contains the label “N+1”, nor “2N”, nor “Tier”: zero occurrences, checked against the complete text. In their place, clause 6.3 lays out six increasingly redundant configurations — a doubled rectifier, then the PDU, then DC distribution, up to the end-to-end redundancy of Figure 8, which the text qualifies without ambiguity: “This system configuration is the most reliable of these system configurations.” The scope stated at the outset is as precise as the list is short: to provide “a reference of power feeding architecture […] with high reliability, safety and manageability”, covering just three chapters — configuration, element requirements, monitoring. No clause on testing.

The backup generator appears, but with a defined role, not a declared response time: “a battery’s main function is to provide power during the starting time of the AC backup generator.” The Recommendation says that gap has to be covered. It does not say how long it lasts, or how it is measured.

The factor of 20 comes from the literature, not from a test bench

How much is end-to-end redundancy actually worth? The same L.1204 states it in the introduction, with a caveat few specifications ever carry over: “Improvements in reliability and availability vary between factors of 2 for a simple architecture to 20 for a full end-to-end redundant architecture” — but the sentence continues: “this is based on many of the papers listed in the bibliography.” The factor of 20 is not an ITU-T measurement: it is a summary of literature, cited as a reference, not a figure drawn from a plant that was actually put through acceptance testing.

Where “N+1” enters, and where it really comes from

The Recommendation that answers “what is this architecture actually worth” is a different one, ITU-T L.1202 (04/2015), Methodologies for evaluating the performance of an up to 400 VDC power feeding system and its environmental impact — also downloaded and read in full. To classify the reliability of the L.1201 configurations, L.1202 uses its own scale, from class {#1} to {#5}. The label “N+1” shows up only elsewhere: in Appendix IV, to compare against external framework classes (BICSI, EMerge Alliance, TGG); and in Appendix VI, comparing against Uptime Institute levels. There, L.1202 writes: “Tier is an industry standard produced by the United States private organization, Uptime Institute” — and reports a table of declared availability by level: Tier 1, 99.67%; Tier 2, 99.75%; Tier 3, 99.98%; Tier 4, 99.99%. We have not read the Uptime Institute’s original document — its official page shows no working download link — only this account, with its own bibliographic source, inside L.1202. “N+1” is never a native ITU-T category: it enters only when the text measures itself against outside standards, each one named as it appears.

Even the model admits it: redundancy needs periodic proof

The most useful part of L.1202, for anyone writing a specification, is not the Tier table: it is an admission buried inside its own calculation method. Discussing how to estimate the mean time to repair (MTTR) of a component whose failure stays silent until someone goes looking for it, the Recommendation writes: “On systems where failure cannot be detected without an active test, it is proposed to replace the MTTR by Test period/2 + MTTR.” The example the standard picks is almost the same as our opening scene: “a battery discharge test is of a 6 month period […] compared to an MTBF = some million hours.” The model that calculates the reliability of a redundant system only works if someone actually tests that redundancy at intervals — otherwise the calculated figure describes a plant nobody can still confirm exists as designed.

What to write into the specification

  • The configuration by element, not by label: which part is doubled — rectifier, PDU, distribution, end-to-end path — with the matching L.1204 figure, not just “N+1” or “2N”.
  • A load test at the declared IT power, not at the plant’s nameplate rating: resistive load banks brought to the operating level expected in service, for a duration fixed before the test.
  • A single-branch failure simulated at full operating load: a controlled opening of the primary feed, not a no-load test, with the standby branch actually required to pick up the load.
  • Transfer time and generator start-up time measured with a calibrated instrumentwith a traceable calibration certificate, not estimated with a stopwatch or read off the manufacturer’s datasheet.
  • IT load continuity checked at the load side, not only at the switchboard: a voltage dip the generator never registers can still reboot equipment downstream.
  • A retest interval written into the contract: calculated reliability is only as good as how often that redundancy is put back to the test, not a one-off certification.

What we could not verify

L.1201 (03/2014), the base Recommendation that L.1204 extends, we downloaded and read as fully as the other two: the same asymmetric AC/DC configuration is already there, in clause 6.3.2.2, but qualified as “transitional solutions, in some regions only”; L.1204 picks it up and formalises it into a hybrid architecture of its own. During this session, ITU’s PDF gateway (dologin_pub.asp) returned repeated 500 errors on these same codes, an infrastructure issue that later resolved itself within the session. The handle.itu.int link, queried without browser headers, triggered ITU’s WAF block (“Request Rejected”, roughly 245 bytes); overcome with full browser headers, but the page returned is a JavaScript application with no static text to read, so we did not use it as a source. The Tier figures quoted here come from L.1202, not from the Uptime Institute’s original document: its official page shows no verifiable download link. We found no ITU-T Recommendation, in this series or elsewhere in the catalogue, dedicated specifically to acceptance-testing a redundant configuration after construction: if one exists, the search carried out in this session did not turn it up.

Two pillars, on declared redundancy

First pillar: the configuration translated into the specifications we check by element — which part is doubled, against which reference figure — together with the load test, the single-branch failure simulation and the times measured with a calibrated instrument. Acceptance testing checks that the built plant matches that description, not that someone remembers choosing “N+1” in a meeting.

Second pillar: that test, repeated at the interval written into the contract — not a one-off at initial commissioning — stops being an isolated event. With CSIDIA, the group’s other company, test records, transfer times measured over time and generator logs come together into a single map for every data centre, on which an AI flags when a measured time drifts from the last test — within the client’s own perimeter, on-premises or dedicated cloud with a data centre in Italy, always with shared management.

Does your specification declare a redundancy class nobody has ever put to the test under real load? Talk to an engineer: the site visit is free, and the difference between “N+1” written down and “N+1” proven shows up in a test, not in a meeting.

Sources