== Intra-DC Redundancy ==
We need to guard against the loss of any individual server within a DC. There are separate redundancy schemes for the MySQL servers, and for the for other supporting infrastructureservices.
=== MySQL Redundancy ===
'''TODO:''' Depending on our uptime requirements, we might not need to spend the money on establishing this layer. Cross-DC replication and the acceptance of an occasional lost transaction may be a better tradeoff.
=== Other Service Redundancy ===
Note that this shard-state metadata will be very small and be updated very infrequently, which should make it very friendly to a local zookeeper installation.
== Inter-DC Redundancy ==