Incident Management Platform  ·  View 26 of 34  ·  6 · Operations

Deployment — Two Estate Sites and an Outpost That Shares Neither

Three paging cells in three locations, the control plane at site A with a warm rebuild at site B, and the duties only the outpost performs.

Editable source SVG draw.io All views
Three locations, three power feeds, two upstream carriers Site A · data centre Paging cell A · 3 hosts NATS JetStream ingest R3 · paging voter Paging services engine · timers · dispatch Asterisk · Jasmin carrier A Control plane · platform Kubernetes Control services incident · schedule · review PostgreSQL primary CloudNativePG Site B · data centre Paging cell B · 3 hosts NATS JetStream ingest R3 · paging voter Paging services active-active with A Asterisk · Jasmin carrier A Warm control plane Argo CD manifests scaled to zero PostgreSQL standby synchronous Site C · colocation outpost Paging cell C · 3 hosts NATS JetStream paging voter Paging services minority-capable Asterisk · Jasmin carrier B · GSM bank Outpost-only duties Synthetic and watchdog dead-man switch Status page nginx · static Deployment — Two Estate Sites and an Outpost That Shares Neither Queue / topic Application we own Interface / broker Data store Security / platform The estate runs in A and B. C runs nothing the estate needs and needs nothing the estate runs: own ISP, own DNS resolvers, own time source. v 1.0 · owner Reliability Architecture · date 2026-09

Decisions

  • The requirement's second region becomes site B, and its out-of-cloud provider becomes site C: a colocation outpost on a different power grid and upstream carrier, running the third paging cell, carrier B, the synthetic probes, the dead-man switch and the static status page (ADR-03).
  • Site C is not a disaster-recovery copy of A. It is a full voter in the paging domain and a full paging cell on its own, which is what lets it page during the event that takes out both estate sites.
  • Each site runs its own DNS resolvers and its own time sources for the cell, and the responder app ships with all three cells' addresses. No shared resolver or NTP server is on the paging path.

Sizing

  • Per cell: three hosts with 16 cores, 64 GB and 2 TB NVMe. Control plane: three control-plane nodes and three workers. The load is small; the hosts are sized for the storm and for losing one of three.

Stated premium

  • Site C costs about USD 55,000 a year before staff time: colocation space and power, a second ISP, three servers amortised over four years, the carrier B trunk and SMPP account minimums, and a GSM modem bank. A planning estimate, stated so it can be argued with (ADR-32).