Distributed Job Scheduler  ·  View 09 of 20  ·  Data

Data Flow — Definition to Evidence

Seven states of one instant, of which only two are authoritative.

Editable source SVG draw.io All views
Declared Trigger definition versioned Policies missed, overlap Projected Next instant recomputed Due index row Claimed Instant claim conditional write Committed Fire record idempotency key Queued Lane queue entry Attempted Attempt row n of budget Minted token attempt-scoped Accounted History row Bigtable Archive 13 months Lateness facts BigQuery state changes recompute each tick outcome Data Flow — Definition to Evidence Data store Application we own Queue / topic Security / platform event / async batch Only the first and fourth columns are authoritative. Everything between them is recomputable from the definition. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • The definition and the fire record are truth. The next instant, the due index row, the lane entry and every evidence row are recomputable from them (ADR-11).
  • The next instant is recomputed each tick rather than materialised, so a tzdata change or an amendment is picked up without an invalidation sweep (ADR-05).
  • The original scheduled instant travels with the fire, separate from the dispatch instant, because the work reads a window derived from the former (ADR-08).

Assumptions

  • Fire history 90 days hot and 13 months archived; a single-trigger 30-day query at p95 ≤ 500 ms. All assumed.

Risks

  • Recomputing instants for 20 million triggers every tick is the main scan-cost risk, and the reason Question 7 in the ask is still open.