Flipkart Marketplace Platform · View 19 of 25 · 6 · Operations
Decisions
- Two Indian Azure regions: Central India active, South India read-active at about 30% capacity and warm for failover
- Three availability zones in the primary region with synchronous replication inside the region and asynchronous across regions
- Catalog and media are genuinely multi-region by construction; the transactional tier is not, and pretending otherwise would be the lie in this set
Recovery targets
- In-region zone loss: RPO 0, RTO measured in seconds, handled by the platform
- Region loss: RPO 30 seconds, RTO 20 minutes, a rehearsed runbook with a human decision point
- Failover is rehearsed quarterly and before every major sale event
Risks
- A cross-region failover during a sale hour loses up to 30 seconds of writes — the reconciliation of those orders is a manual playbook
- Kafka mirroring lag is the leading indicator of a bad failover and is alerted separately
- Spot node pools carry batch and stream work only; nothing on the checkout path runs on spot