Health Check & Service Discovery  ·  View 08 of 21  ·  Structure

Platform Components

Four planes drawn as two boxes, because the control plane fails as one thing and the data plane survives it.

Editable source SVG draw.io All views
Control plane — advisory, per region Registration and desired state Reconciler orchestrator watch Registration API non-orchestrated Registry store strongly consistent Policy store contracts, topology Observation Prober fleet bounded assignment Signal ingest 1.2 M results/s Observed-state store 7-day, write-sized Evaluation and assembly Evaluator sharded by service View assembler in memory only Transition log append-only Propagation xDS stream tier 60k subscriptions DNS authority Cloud Map / Route 53 Resolution API tooling, admin Data plane — authoritative for routing Per workload Envoy sidecar xDS client Last-known-good cache durable, on disk Client guards ejection, shrink cap Runtime edge NLB / ALB target groups fed by views Thin resolver library sidecar-less callers Workload identity IRSA / SPIFFE Observability platform Readiness + failover signal out-of-band versioned deltas persist view fail static authn transitions Platform Components — Four Planes, One Of Them Optional Application we own Interface / broker Data store Security / platform External / third party synchronous event / async failure / alternate The control plane is one box because it fails as one. Nothing in it is on the request path. v 1.0 · owner Reliability Architecture

Decisions

  • Registration is reconciled from orchestrator state for orchestrated workloads; the registration API exists only for the ones it does not own (ADR-03).
  • Observed state and desired state are separate stores with different durability classes — one sized for 1.2 M writes/second, one for correctness.
  • Target groups at the runtime edge are fed from the same views, so a sidecar-less caller gets the same eligibility semantics.

Assumptions

  • Control plane on EKS, 18 replicas per region across 3 AZs; evaluation sharded by service.
  • The out-of-band failover signal deliberately has no dependency on the registry it talks about.

Risks

  • The xDS tier is stateful and holds 60,000 long-lived connections; its own deploy is the most dangerous routine operation in the platform.