Distributed Job Scheduler  ·  View 15 of 20  ·  Operations

Deployment Architecture

One write region across three zones, and a standby that deliberately holds no leases.

Editable source SVG draw.io All views
Primary region — europe-west4 Zone a Control plane Cloud Run Timing plane partitions 0-85 Dispatch plane Zone b Control plane Timing plane partitions 86-170 Dispatch plane Zone c Control plane Timing plane partitions 171-255 Dispatch plane Regional state — synchronous across all three zones Spanner regional registry, due index, ledger Bigtable fire history Cloud Tasks lane queues Standby region — europe-west1 (read replica, promoted by declaration) Cold tiers Control plane scaled to zero Timing plane no leases held Replicated state Spanner replica RPO ≤ 15 s History archive dual-region Time authority Tenant targets lease + claim lane queues async replicate attempts bounded ε Deployment — Region, Zones and the Standby Application we own Data store Queue / topic Security / platform External / third party synchronous event / async One write region. The standby holds no leases, because two regions deciding the same instant is a merge problem the fire key only partly solves. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • One write region. Two regions deciding the same instant is a merge-semantics problem that the fire key only partly solves — the key dedupes the fire, not the overlap decision that produced it (ADR-02).
  • Partitions are spread across zones and reassignment is exercised routinely in production, so the takeover path is the common path rather than the emergency one (ADR-11).
  • Region promotion is a declared operation against a stated RPO, not an automatic failover.

Assumptions

  • 256 partitions over three zones; cross-region RPO ≤ 15 s; RTO 5 minutes for dispatch and 30 minutes for the control plane; partition reassignment within 15 s p99. All assumed.

Risks

  • Fifteen seconds of RPO is up to fifteen seconds of fire decisions that the promoted region cannot see. The ledger establishes which fires were already dispatched; the ones in flight at the moment of divergence are the residual.