Feature Store · View 15 of 21 · Operations
Decisions
- Loss of one AZ has no SLO impact; loss of the region is met by rebuilding the online store in the second region from replicated offline state, because the online store is derived and cheap to recreate.
- The second region runs warm at 10% capacity rather than cold or hot — cold cannot meet a 15-minute RTO, hot doubles the most expensive tier in the platform.
- Two EMR Serverless pools: one for scheduled materialisation, one for backfill. Sharing them is how a backfill takes the morning batch wave with it.
Assumptions
- RTO 15 min for serving in the second region; registry RTO 1 h; full online rebuild ≤ 90 min.
- DynamoDB on-demand capacity absorbs the stated 3× burst for 10 minutes without pre-provisioning.
Risks
- A 15-minute RTO that depends on a rebuild is only as good as the last time the rebuild was run in anger.
- Warm-at-10% means the first minutes after a regional failover are served by a tier that is scaling, so the latency SLO is breached before it is met.