Distributed Job Scheduler  ·  View 10 of 20  ·  Data

Storage Zones

Backed up, rebuildable, or cold — and why that is the only classification that matters here.

Editable source SVG draw.io All views
Systems of record — backed up, never rebuilt Trigger registry Definitions versioned, immutable Policies and quotas tzdata version pin Fire ledger Fire records PK = idempotency key Attempts Audit Privileged acts 7 years, immutable Rebuildable projections — dropped and recomputed, not restored Due index Next instants per partition Partition leases short TTL Serving caches Next-fires cache Quota counters Evidence stores Fire history 90 d hot Lateness facts derived Cold — retained, not queried Archive History archive 13 months, Cloud Storage Billing counts non-identifying recompute project tier at 90 d load Storage Zones — What Is Truth, What Is Rebuildable Data store batch event / async Tenant payloads live only in the registry and the ledger, encrypted under a per-tenant key, and are never copied into the evidence stores. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • Only the registry, the ledger and the audit store are backed up. The due index, the caches and the evidence stores are rebuilt, not restored (ADR-11).
  • Tenant payloads exist in exactly two places, encrypted under a per-tenant key, and are never copied into evidence or reporting (ADR-16).
  • Audit is a separate store with a separate retention and immutability guarantee, because the acts it records are the ones that multiply work.

Assumptions

  • Registry and ledger RPO 0 in-region, cross-region RPO ≤ 15 s. Audit retained 7 years. Payload ≤ 64 KB with a p99 of 2 KB. All assumed.
  • Tenancy termination deletes definitions, payloads and history within 30 days while retaining non-identifying fire counts for billing.

Risks

  • A rebuild that is never exercised is a restore procedure with better marketing. View 07's shadow rebuilder exists because of this risk, and it only mitigates it.