Health Check & Service Discovery · View 12 of 21 · Data
The two keys that carry the design
- instance_id is never reused, so a restarted process is a new row and a cached endpoint referring to the old one is detectably stale.
- transition.evidence_sample_id points at the actual sample that caused the verdict, which is what makes an explanation auditable rather than narrated.
Deliberately absent
- published_view and subscription are computed state in memory, not registry rows — see view 11.
- The lease is folded into the instance row rather than modelled separately: it is strictly 1:1 and the join bought nothing.
Assumptions
- 450 service rows, 60,000 instance rows, ~2,500 eligibility updates a minute, 90 days of transitions.