Leaderboard & Counting Service · View 11 of 21 · Data
Decisions
- The high-volume counters and the exact transactional state never share a store. One needs cheap splittable rows at 3.5 billion keys; the other needs strong consistency at a few million rows, and a store that is good at both is good at neither at this ratio.
- The cache carries no RPO. Losing it entirely is a latency event by definition, which is what makes it safe to treat as capacity rather than as state.
- Closed standings are a separate store from ranked views, because the thing a reward is paid against must not be reachable by a projection build.
Retention (assumptions)
- Log 90 days hot plus 13 months archive; bucket aggregates 400 days; closed standings and audit 5 years.
- RPO 5 s for accepted events, RPO 0 for standings and configuration; RTO 10 min read path, 30 min full rebuild.
Risks
- A rebuild reads the archive at ≥ 10× real time, which is a large, bursty read against the same storage the ingest path is writing.
- 400 days of hourly buckets for 3.5 billion counters is the dominant storage line; the tiering rule is what keeps it affordable and it is easy to get wrong.