Leaderboard & Counting Service  ·  View 02 of 21  ·  Context and scope

High-Level Architecture

Six stages, with the caller's acknowledgement at the end of the second one.

Editable source SVG draw.io All views
Admit Counting API Cloud Run Admission idempotency, quota Log Event log Pub/Sub, 31 d Event archive GCS, 90 d replay Aggregate Aggregation job Dataflow, event time Bucket store Bigtable Project Projection builder versioned views Ranked store top-N + histogram Serve Rank cache Memorystore Query API staleness tagged Close Season closer Workflows Control plane Spanner replay own-write overlay Leaderboard & Counting Service — High-Level Architecture Interface / broker Application we own Queue / topic Data store Decision point Security / platform batch event / async Six stages, and the acknowledgement happens at the end of the second. Everything after Log is a rebuildable projection; the replay edge is the recovery path and the routine one. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • The write is acknowledged when the event is durable in the log, not when it has been counted. Everything after Log is allowed to be behind.
  • Aggregate, Project and Serve are three separate stages because they fail separately: a stalled pipeline widens staleness, a bad projection build is rolled back by version, a lost cache is a latency event.
  • Close is a stage, not a scheduled script. A season that can be silently rewritten was never a result.

Why the replay edge is drawn

  • Replay from the archive is the recovery path and the routine one — exercised on a schedule, not discovered during an incident.
  • Because it exists, a corrupt partition, a wrong tie-break rule and a late-discovered fraud campaign have the same remedy: rebuild.

Risks

  • Staleness is now a product property. A screen that implies live truth will be wrong, so every response carries its as-of and the product must show it.
  • The log must be retained long enough and replay fast enough to rebuild the largest leaderboard inside the RTO. That is a throughput commitment, not a backup.