Embedding Pipeline Service · View 16 of 22 · Runtime
The payoff
- Message 16 is the point of the whole architecture: rollback is one alias write against an index that is still built, still live-fed and still measured.
- Dual-write is enabled before re-embedding starts, so the shadow index is never behind on live edits and "complete" means complete.
- The gate at message 12 is a quality comparison, not a completeness check. An index can be 100% built and still not be allowed to serve.
Cost is accepted before it is spent
- Messages 2 and 3 price the migration — chunks, GPU hours, peak storage, duration at both rates — and a human accepts it. A migration that nobody priced is a migration nobody can stop.
- Progress is reported as the oldest unmigrated chunk rather than a percentage, because a percentage hides a stalled tail.
- The superseded index is retained 21 days, which is the real length of the storage doubling.
Risks
- A per-tenant wave means the estate is split across two contracts for days. Any cross-tenant quality comparison during that window is invalid.
- If the shadow build outruns the retained-text window for old documents, those documents re-enter at the fetch stage and load the source systems.