A grocery-delivery business handling about 220000 orders a day in one country must begin operating a second market as a separate legal entity with its own tax registration and courier contracts, under a rule that the new market's customer data may not leave that market. Today one order service owns the basket, the courier job, the payout and the invoice for everything, with 18 months of history in one Postgres cluster. Sequence the split with no customer-visible downtime, say where data can diverge and name the point of no return.
Show the full answer Hide the answer
The sequence
- Add the entity key everywhere before moving anything. Every row, every event, every API call and every background job carries a market identifier. This is reversible, ships behind no flag, and is the step that makes the rest mechanical. Expect several weeks for 18 months of backfill on a table of roughly 120 million orders.
- Split the contexts along the legal seam, not the technical one. Invoicing and payout become their own context first, because that is where the second entity actually differs — tax registration, courier contracts, settlement accounts. Basket and courier dispatch stay shared until proven otherwise.
- Break cross-entity references. No foreign key, shared sequence or "latest order id" cache may span markets, or the second deployment cannot be moved. This is the step that uncovers the surprises.
- Stand up the second market's ledger and dual-write it, with the original cluster still the source of record. Run both for at least two full month-end closes.
- Cut reads over per report, then move the write path so the new ledger is authoritative for the new market.
- Move the new market's customer data into its own cluster last, when nothing else reads it cross-border.
Where data diverges and how you would know
The two ledgers diverge on anything with a clock or a rounding rule: a payout batch that straddles midnight in two time zones, a refund issued against an invoice the other side has already closed, a currency rounding difference of a penny per line. Reconcile daily in production on three totals per entity — orders accepted, settled value and open refunds — with a tolerance of zero on counts and a documented tolerance on value. A mismatch that appears only at month end has already been filed.
The point of no return
Not the deployment. It is the first tax return filed from the new ledger, because from then on the figures the authority holds can only be reproduced from that system. Before that moment rollback is a configuration change; after it, rollback is a restatement. Put the go or no-go decision one full close before the filing date and name the single person who takes it.
How long it really takes
For a business at this size, 9 to 15 months of elapsed time, of which the entity key and reference-breaking work is typically half, and most of the risk sits in reporting rather than in the request path. The common failure is funding the two months of visible work and discovering the other eight.
When this is the wrong answer
If the second market is a pilot that may close, do not split the context unless a regulator forces it — run it inside the existing entity with the entity key in place and a data-residency exception sought in writing. The entity key alone preserves the option to split later and costs weeks rather than quarters. Choose the full split when a regulator, an auditor or a separate board actually requires separation, not when the business merely expects to expand.