Leaderboard & Counting Service  ·  View 13 of 21  ·  Runtime

From One Event to a Rank

Seventeen messages, exactly one of which the caller waits on.

Editable source SVG draw.io All views
Product client Counting API Event log Aggregation Bucket store Projection builder Query API Rank cache 1. POST /events (+ idempotency key) 2. verify token, signature, bounds 3. dedup lookup, 24 h horizon 4. publish, wait for durable 5. committed 6. 202 accepted, p99 ≤ 25 ms 7. deliver (at-least-once) 8. event-time window, shard merge 9. merge delta into bucket 10. changed keys 11. build ranked view v+1 12. publish version, warm top-N 13. GET /rank?member=me 14. read at pinned version 15. top-N, histogram, as-of 16. apply own-write overlay 17. rank + value + as-of + version 18. if pipeline stalls: staleness widens, flagged Critical Flow — From One Event to a Rank the Member Believes The acknowledgement at message 6 is the platform's only synchronous promise. Everything between it and message 17 is allowed to be seconds behind — except the overlay, which is what makes the member's own contribution visible. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • Message 6 — the 202 after the log commits — is the platform's only synchronous promise. Every later message is allowed to be seconds behind, and the design is only defensible because of that.
  • Deduplication happens before the publish, not in the pipeline, so a client retry storm costs a lookup rather than a pipeline reprocess.
  • The projection publish and the cache warm are one step. A version that is readable before its top-N is warm turns a publish into a latency cliff.

Numbers (assumptions)

  • Accept p99 ≤ 25 ms single event, ≤ 80 ms for a 500-event batch.
  • Global staleness ≤ 5 s at p95, ≤ 30 s at p99; up to 120 s during a declared burst, flagged in the response.
  • Own value and rank band within 1 s.

Risks

  • The error message at the end is the honest one: when the pipeline stalls, the read path keeps answering with an ageing as-of. A product that does not render the as-of turns a declared degradation into a wrong number.
  • At-least-once delivery means the pipeline must stay idempotent across restarts, not only across duplicate publishes.