Skip to content

Why I stopped chasing Tier III certification

Datacenter Talk by Buenos 33 replies 8.2K views
#21

This thread is gold

olespete said:
Firewall the IPMI
Pete you always say this and you are right but you are also the only person I know who runs fail2ban on a PDU, that is deeply cursed behaviour The insurance angle is interesting though, I have InterServer for my 8 racks in Lyon and they never asked for Tier anything, just wanted photos of the extinguisher and the cage lock Has anyone actually had an insurer reject a claim over lapsed Tier III specifically, or is this theoretical terror

Vive la résistance... électrique
#22

52 days late but

olespete said:
fail2ban on my PDUs
Made me choke on my coffee

Pete I love you but you are the only person who has ever iptables'd a power strip

Real talk though the insurance angle is interesting — did anyone actually get a claim denied over lapsed Tier III, or is this theoretical? I have heard the same scary story from three different people but never a first-hand denial

My own setup is four racks in a basement that floods maybe once a year, I am not exactly the target market for redundant CRACs

#23

52 days but this one is still relevant

olespete said:
fail2ban on my PDUs

Wait you are actually firewalling individual PDUs or is that a figure of speech

I only ask because I looked at smart PDUs with any real networking once and the price made me go back to basic metered units

The insurance angle is interesting though
Has anyone actually had a claim denied over lapsed Tier III specifically
Not theoretically but actually happened

My guess is insurers care more about the fire suppression inspection date
But I could be wrong

#24

62 days but this one still stings

olespete said:
Firewall the IPMI

Off topic but that is the real advice in this whole thread brother

I let a KnownHost colo cert lapse once and the only thing that changed was the invoice stopped coming

The insurance angle sounds like something the auditor tells you to keep you paying

zfs send | zfs receive. repeat.
#25

75 days late but

olespete said:
Fire marshal sees expired Tier III, assumes negligence
Made me laugh out loud. The fire marshal in my town cannot even find the extinguisher when he visits, he is not googling Uptime Institute dates.

I let our KnownHost colo drop Tier III two years ago and the only person who noticed was the auditor sending sad follow-up emails. Insurance renewal came, broker asked about physical security, I said badge entry and cameras, he checked the box. Never mentioned certification once.

The real risk is the CRAC dying in August though. Pete is right about that part. We run three now because one did exactly that.

#26

Has anyone actually had an insurer ask for Tier III paperwork specifically? I've had them want electrical inspection certs and fire suppression service logs, never the Uptime badge.

olespete said:
Fire marshal sees expired Tier III, assumes negligence

In my experience the fire marshal cares about your egress paths and your panel schedules, not whether you paid a consultant to draw redundant conduit diagrams. But maybe Spain is different.

I run my stuff on Leaseweb and HostHatch colo these days, so this is more curiosity than self-interest. The 99.991 vs 99.979 thing from the OP is the real stat that stuck with me.

#27
cleardmitri said:
Insurance actually checks Tier III dates? Never seen that happen.

They don't check the date until they need a reason not to pay.

Had a client over in Lisbon, small colo, 8 racks. Fire in the building next door, smoke damage, no actual flames on his gear. Insurer sent an adjuster who asked for "all facility certifications." Tier II expired six months prior. Claim went from "we'll cover it" to "under review" for eleven months. He settled for 40 percent.

Not saying they all do this. Saying they can, and when the loss is big enough they will.

Also not just insurance. We had a prospect last year, mid-size SaaS, their security questionnaire asked specifically about current Tier rating. Sales guy had to explain we self-certify to equivalent standards. Deal took four months longer than it should have. They went with InterServer in the end.

Still not worth 18k plus 8k yearly for my setup. But I keep a binder with photos, maintenance logs, test results. Date-stamped, offsite backup. Call it poor man's audit trail.

Fail2ban on the PDUs though. Non-negotiable.

airgapped, encrypted, faraday'd, still worried
#28

105 days but this thread is still relevant.

olespete said:
fail2ban on my PDUs
Pete I need to hear more about this, are you actually seeing brute force attempts on IPMI or is this theoretical? I have mine on a management VLAN with no external route but I never considered layer 2 threats inside the facility.

On the insurance question, my broker at Contabo (https://contabo.com) never asked about Tier anything. They wanted to know about automatic fire suppression, 24/7 staffing, and whether we test our generators monthly. The certificate never came up.

Giorgi

#29
cleardmitri said:
Insurance actually checks Tier III dates? Never seen that happen.

Late to this but same, our broker never asked once and we let ours drop in 2021. They cared way more about the actual PM logs and whether the fire suppression was tagged.

Has anyone here actually had an insurer dig into certification status specifically or is this more theoretical

learning on $5 VPS and prayers
#30

127 days and still no horror story from cleardmitri about an insurer actually caring. Telling.

cleardmitri said:
Insurance actually checks Tier III dates? Never seen that happen.

I checked with my broker last quarter. They wanted the fire suppression inspection, the electrical sign-off, the building occupancy cert. Never asked for Tier anything. The cert is theatre for procurement departments, not underwriters.

That said I still firewall the IPMI. Some paranoia is free.

airgapped, encrypted, faraday'd, still worried

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft