A storage quota can fail in two directions when its own machinery breaks, and the choice is a real one with a real cost either way.
Fail closed — if the check cannot run, refuse the write. Safe for the operator, and it turns any bug in the limit into an outage for people doing legitimate work.
Fail open — if the check cannot run, allow the write. Right for a product whose core action must never be interrupted, and it has one severe property that has to be planned for: when it breaks, the symptom is a success. Requests return 200, nobody complains, every automated check stays green, and the limit silently enforces nothing. A fail-closed limit tells you it is broken within minutes. A fail-open one can be broken for a month.
The consequence, which is the actually useful part: choosing fail-open obliges you to verify the limit deliberately and periodically against real data, because nothing else will ever tell you. A test that only ever exercises the allowed path proves that the allowed path works, which is not the thing in doubt.