Throughput rising with offered load to a knee and then collapsing rather than levelling off, so past the breaking point the system serves far less than it did at the knee

Breaking Point Identification

Back to Performance Tuning and Capacity Planning · Realistic Traffic Modeling · Controlled Environment · Pre-Launch Validation · Service Offerings

Pushing past expected load deliberately, so you know the actual ceiling instead of an assumed one. Most load testing stops at the expected peak and reports a pass. That tells you the system survives what you predicted, and nothing about what happens when you are wrong.

1. Systems Collapse, They Do Not Plateau

The intuition is that a saturated system serves its maximum and queues the rest. Real systems do worse than that, as the illustration above shows: past the knee, throughput falls, and the system under heavy load serves considerably less than it did at its best.

The mechanisms compound each other:

Which is why the practical ceiling is the knee, not the peak measured anywhere beyond it. Operating near the knee means a small surge pushes you over, and over is much further down than it looks.

2. Find What Fails First, and in What Order

The number is the least valuable output. The failure sequence is the useful one, because it tells you what to fix and what will happen next time.

3. Recovery Is the Harder Question

A system that breaks at a known load and recovers in thirty seconds is in decent shape. One that breaks at twice that and then stays broken after the load is removed is not.

4. Degrade Deliberately Instead

If the collapse past the knee is unacceptable — and it usually is — the answer is not more capacity. It is refusing work on purpose, above the knee, so that the system serves what it can rather than failing at everything.

5. Test to Failure, Deliberately and Safely

Finding the real ceiling means going past it, which is why this work belongs in an isolated environment — see controlled environment. The test plan matters:

How We Approach It

  1. Ramp in steps to well beyond the expected peak, holding at each level long enough for queues to settle.
  2. Identify the knee, which is the practical ceiling, rather than the highest number reached.
  3. Record the failure sequence — what saturated, what failed because of it, and what the user saw at each stage.
  4. Remove the load and measure recovery, including whether anything stayed broken.
  5. Recommend admission control where the collapse is steep, since more capacity moves the cliff without removing it.
  6. Re-run after changes against the recorded baseline.

What You Get

The question most capacity plans cannot answer: not what happens at your expected peak, but what happens at twice it — and whether you come back on your own.