Leaderboard & Counting Service  ·  View 14 of 21  ·  Runtime

Aggregation Pipeline

Six stages, every accumulator commutative and associative.

Editable source SVG draw.io All views
Read Log subscription per tenant Parse & schema Deduplicate Keyed state idempotency key Drop counter dedup hit rate Window Event-time assign hour bucket Lateness gate declared horizon Late bucket visible, not silent Accumulate Exact sum HLL++ sketch uniques Per-shard state hot keys split Write Bucket upsert Bigtable Shard fan-in on read or flush Signal Changed-key stream Lag metric per leaderboard parse failures late ratio Leaderboard & Counting Service — Aggregation Pipeline Queue / topic Application we own Security / platform Decision point Data store failure / alternate event / async Every accumulator is commutative and associative, which is what makes shard fan-in order-independent and a rebuild byte-identical to the original run. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • Every accumulator is commutative and associative, which is what makes shard fan-in order-independent and a rebuild byte-identical to the original run. Any accumulator that is not loses the rebuild guarantee the whole architecture rests on.
  • The lateness gate is an explicit decision point with a declared horizon per counter, and what falls beyond it goes to a visible late bucket. Silent inclusion and silent exclusion are both worse.
  • The parse failure path and the late ratio are emitted as signals from inside the pipeline, because by the time they show up as a wrong number the cause is three stages back.

Why dedup lives here too

  • Admission deduplicates client retries within the 24-hour horizon; the pipeline deduplicates redelivery from the log. They are different failures with the same remedy and the same key.
  • Keeping dedup state keyed on the idempotency key means the pipeline's state size is bounded by the horizon, not by the counter count.

Risks

  • Keyed dedup state at 250,000 events/second over a 24-hour horizon is the pipeline's largest state and its slowest restart.
  • A sketch is mergeable but not retractable: removing a member from a unique-cardinality counter requires rebuilding the sketch for that window from the log.