Leaderboard & Counting Service  ·  View 16 of 21  ·  Operations

Deployment Architecture

Two regions, one write region, and a standby whose cache is rebuilt rather than replicated.

Editable source SVG draw.io All views
Google Cloud — europe-west1 (primary read region) Edge and request services (regional, multi-zone) Global load balancer anycast + Cloud Armor Counting API Cloud Run, 3 zones Query API Cloud Run, 3 zones Config + Ops API Cloud Run Processing (regional) Aggregation job Dataflow streaming Projection builder Dataflow batch Season closer Workflows + Scheduler Regional state Bigtable cluster buckets + ranked views Memorystore rank cache, HA tier Google Cloud — europe-west4 (standby read region) Warm read path Query API scaled to minimum Bigtable replica async replication Memorystore cold, rebuilds on cutover Multi-region services Log and archive Pub/Sub global topic, 31 d Cloud Storage dual-region archive Exact state Spanner multi-region, RPO 0 BigQuery export target Platform services Cloud KMS signing keys Secret Manager Cloud Monitoring + Logging, Trace Product clients Product backends HTTPS / mTLS publish subscribe write buckets replicate Leaderboard & Counting Service — Deployment Architecture Interface / broker Application we own Data store Queue / topic Security / platform External / third party synchronous event / async Two regions, one write region. The standby serves reads at declared staleness; a cutover rebuilds its cache rather than replicating it, which is why RTO is 10 minutes and not seconds. Product backends reach the same edge as clients; the replay path is on view 11. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • One write region. Multi-master counting would require either cross-region coordination on the hot path or a merge rule for conflicting deltas, and the product does not need either to tolerate a 10-minute RTO.
  • The standby serves reads from an asynchronously replicated Bigtable at declared staleness, and rebuilds its cache on cutover. That is the whole reason RTO is 10 minutes rather than seconds, and it is an accepted cost.
  • Spanner is multi-region because the things it holds — definitions, seasons, closed standings, audit — are the only state with RPO 0.

Numbers (assumptions)

  • Ingestion accept ≥ 99.99% monthly; read path ≥ 99.95% monthly.
  • RTO 10 minutes for the read path in the standby region; RPO 5 s for accepted events.
  • 4× burst for 120 s absorbed by the log, with typed backpressure beyond it.

Risks

  • A single write region means a regional failure stops counting, not just ranking. Clients must buffer and retry with the same idempotency keys, which is a contract on the product teams.
  • Cold Memorystore on cutover means the first minutes after a failover run on the ranked store's latency, not the cache's.