Health Check & Service Discovery  ·  View 10 of 21  ·  Data

Data Flow — Signal To Routing Change

One probe result, one readiness report or one failed request, followed all the way to a changed endpoint set.

Editable source SVG draw.io All views
Produced Probe result pass / fail / timeout Readiness report ready / degraded / unready Request outcome per caller, per endpoint Attributed Identity check self-report only Unattributable dropped never trusted Scored Decaying score per instance, per class Unknown detector silence ≠ unhealthy Decided Eligibility 4 states + weight Fraction guard veto on mass withdrawal Published View version n+1 delta only Transition record cause + evidence Applied Client view monotonic apply Cache written durable next outcomes Data Flow — One Health Signal To One Routing Change Application we own Security / platform Risk / gap Decision point Data store failure / alternate event / async Withdrawal travels this path in 5 s at p99; an addition is deliberately allowed 30 s. v 1.0 · owner Reliability Architecture

Decisions

  • Attribution happens before scoring, and an unattributable signal is discarded rather than down-weighted (ADR-15).
  • The unknown detector sits beside the score and can withhold a removal the score would otherwise make (ADR-05).
  • Every published change writes a transition record carrying its cause and the evidence behind it.

Assumptions

  • Withdrawal completes this path in 5 s at p99; an addition is deliberately allowed 30 s.
  • 1.2 M signal results/second across the three collection paths.

Risks

  • A scoring bug is a fleet-wide event, which is why the fraction guard sits downstream of it rather than inside it.