File Upload & Scanning Pipeline · View 02 of 21 · Context and scope
Decisions
- Bytes go client-to-store on a path-scoped credential; only control passes through platform compute, on either direction of travel
- Finalisation is an explicit assertion of the chunk set and the whole-object hash — the platform refuses to assemble a mismatch rather than storing a truncated object
- An object is enqueued for scanning exactly once, durably, and cannot reach a terminal state without a verdict recorded against it
The seam
- Bytes exist from stage 2. Access begins at stage 5. Everything between is the platform holding an object it will not let anyone read.
- That gap is why ingest availability (99.99%) and scan availability (99.95%) are separate numbers, and why a scanner outage is a latency incident rather than an availability one
- It is also the cost: a 50 GB object is durable and useless for up to twenty minutes, and the product has to say so honestly
Targets (stated assumptions)
- Initiate p99 ≤ 120 ms; chunk acknowledgement p99 ≤ 400 ms at 16 MB
- Verdict p50 ≤ 2 s and p95 ≤ 8 s under 10 MB on the interactive lane
- 700 initiations/second steady, 3,000/second for a ten-minute burst, 45 GB/s aggregate ingress