Health Check & Service Discovery · View 08 of 21 · Structure
Decisions
- Registration is reconciled from orchestrator state for orchestrated workloads; the registration API exists only for the ones it does not own (ADR-03).
- Observed state and desired state are separate stores with different durability classes — one sized for 1.2 M writes/second, one for correctness.
- Target groups at the runtime edge are fed from the same views, so a sidecar-less caller gets the same eligibility semantics.
Assumptions
- Control plane on EKS, 18 replicas per region across 3 AZs; evaluation sharded by service.
- The out-of-band failover signal deliberately has no dependency on the registry it talks about.
Risks
- The xDS tier is stateful and holds 60,000 long-lived connections; its own deploy is the most dangerous routine operation in the platform.