Leaderboard & Counting Service · View 13 of 21 · Runtime
Decisions
- Message 6 — the 202 after the log commits — is the platform's only synchronous promise. Every later message is allowed to be seconds behind, and the design is only defensible because of that.
- Deduplication happens before the publish, not in the pipeline, so a client retry storm costs a lookup rather than a pipeline reprocess.
- The projection publish and the cache warm are one step. A version that is readable before its top-N is warm turns a publish into a latency cliff.
Numbers (assumptions)
- Accept p99 ≤ 25 ms single event, ≤ 80 ms for a 500-event batch.
- Global staleness ≤ 5 s at p95, ≤ 30 s at p99; up to 120 s during a declared burst, flagged in the response.
- Own value and rank band within 1 s.
Risks
- The error message at the end is the honest one: when the pipeline stalls, the read path keeps answering with an ageing as-of. A product that does not render the as-of turns a declared degradation into a wrong number.
- At-least-once delivery means the pipeline must stay idempotent across restarts, not only across duplicate publishes.