File Upload & Scanning Pipeline · View 11 of 21 · Data
Decisions
- Class 1 is the object bytes and the record of why they are where they are: both at RPO 0, synchronously replicated in region and asynchronously across region at ≤ 60 s
- No Class 2 store is authoritative for anything, which makes a corrupt metadata partition a rebuild rather than an incident
- Session chunk state is deliberately Class 3: losing it costs one restarted upload and no data, which is why it is allowed an RPO of 60 seconds
What this buys
- Object metadata, the dedup index and the quarantine queue view are all rebuildable from the transition log and the verdict store
- RTO 15 minutes for the read path in the secondary region, 60 minutes for full scan capacity, with verdicts replicated so a failover does not re-scan 12 PB
- Object durability ≥ 11 nines, and zero tolerated cases of an object reaching a reader without a current clean verdict
Stated assumptions
- 12 PB under management, growing 4 PB/year net of deletion
- Transition log and verdict provenance retained 7 years, immutable
- Quarantine evidence 180 days, then irreversibly destroyed