Incident Management Platform  ·  View 09 of 34  ·  3 · Structure

Container Architecture — One Paging Cell

Everything that runs in one cell: three dedicated hosts at one site, with no orchestrator, no shared DNS and no registry needed at run time. Cells B and C have the same shape.

Editable source SVG draw.io All views
Paging cell · site A · three dedicated hosts · systemd, no orchestrator Receive HAProxy edge anycast VIP · BFD Ingest gateway ingest.slice · capped State Ingest domain JetStream · site R3 Paging domain JetStream · 3-site R3 Decide and page · paging.slice, reserved CPU Incident engine grouping key CAS Escalation timers shard lease Dispatcher human dedup 60 s Ack receiver signed ack tokens Delivery Asterisk IVR · DTMF Jasmin SMS SMPP · MO replies Push relay APNs · FCM Monitoring sources signed webhooks Cells B and C Raft peers Carrier A SIP trunk · SMPP HTTPS publish CAS · outbox SIP · TLS Raft Container Architecture — One Paging Cell Interface / broker Application we own Queue / topic External / third party synchronous event / async Omitted for legibility: the engine consuming the ingest domain, timers and dispatcher reading the paging domain, and every ack path (view 19). v 1.0 · owner Reliability Architecture · date 2026-09

Decisions

  • Paging services run as static Go binaries under systemd on hosts the platform team owns. The estate's Kubernetes clusters are among the things this platform pages for, so the paging path cannot live on them (ADR-02).
  • Ingest and paging share hosts but not CPU. The gateway runs in a systemd slice with a hard CPU quota; the engine, timers and dispatcher run in a slice with reserved CPU. A storm raises ingest lag; it cannot delay a dispatch.
  • Two JetStream domains per cell: a site-local ingest domain replicated across the cell's three hosts, and a paging domain whose replicas sit one per site (ADR-07). Bulk alert traffic never crosses a site link.

Targets

  • Any one host of three may be lost with no effect. A whole cell may be lost and the anycast address moves to another cell within 2 minutes, the paging path RTO. Timer shards owned by the lost cell are taken over within 3 seconds.

Risks

  • A cell is also a place where a bad deploy lands on every service at once. Deploys go one cell at a time, one day apart, with a synthetic page acknowledged between them (view 27).