· · 1 min · infrastructure · by the wire desk

The postmortem is the best genre in engineering writing

An editorial in praise of the documents this winter keeps producing, and the tell that separates real ones from theater.

This winter's outage cluster has one upside: the reading. A good incident postmortem is the only genre where large companies publish, voluntarily and in public, precise accounts of their own failures with timestamps attached. No other corporate document comes close. The marketing site describes a company as it wishes to be; the postmortem describes it as it was at 3:47 a.m. It belongs to the same shift the desk noted earlier, where the practitioner notebook beats the press release.

The genre has masters. Cloudflare's post-mortem archive reads like serialized systems education: here is our architecture, here is the assumption it encoded, here is the day the assumption met reality. The recurring winter theme, automated configuration changes with continent-sized blast radii, has taught more network engineering this quarter than most courses manage in a semester.

There is a tell that separates the real article from the theater, and it is worth learning. Real postmortems name mechanisms: this policy, this router, this validation that did not exist. Theater names abstractions: process gaps, learnings, a commitment to excellence. Mechanisms can recur and be checked at the next incident. Learnings cannot fail, which is how you know they do not exist.

The builder's read: your incident review template is a genre choice. Steal from the masters, require mechanisms, ban the word learnings, and publish internally at minimum. The organizations that write well about failure fail more interestingly the next time, which is the whole game.

tags: #postmortems #incidents #writing