Embedding Pipeline Service · View 08 of 22 · Structure
Decisions
- Extraction runs as its own sandboxed workload with no egress, because it is the least-trusted compute in the system and processes bytes a tenant uploaded.
- The chunk ledger is a relational store with synchronous standby. It is the platform's own system of record, so it is the one data store that must not lose a write.
- Access control is its own boundary inside Serving, holding the ACL filter and the suppression list, so revocation is a property of the read path rather than of indexing.
Build and buy
- Bought as open source and operated: Kafka, PostgreSQL with Patroni, Redis, Qdrant, OpenSearch, MinIO, etcd, Argo Workflows, KubeRay, ClickHouse, Envoy, SPIRE, OpenBao.
- Built: admission and lane assignment, the chunker, the index builder's contract enforcement, the alias resolver, the ACL filter and the quality harness.
- The pattern: buy the storage and the transport, build the semantics. Everything built is something the architecture's correctness depends on.
Deliberately omitted
- The observability stack, secrets distribution and the warehouse export: each has its own view rather than twelve more edges here.
- The re-ranker, which is Phase 2 and would otherwise read as committed.