Leaderboard & Counting Service · View 18 of 21 · Operations
Decisions
- Rebuild is a step on the normal loop, not an incident path. A projection that is rebuilt only in emergencies is a projection whose rebuild does not work.
- The loop closes on dematerialisation rather than deletion: an idle scope releases its ranked view and keeps its buckets, and rematerialises on the next read.
- Publication is an explicit transition, which is what lets a bad build be withdrawn by pointing readers back at the previous version.
Numbers (assumptions)
- Scheduled rebuild of every tenant's largest board at least monthly, at ≥ 10× real-time replay.
- Dematerialisation after 30 days with no read; rematerialisation on demand within the cache-miss budget.
Risks
- Rematerialising a cold scope on a read is a latency spike at exactly the moment a dormant product surface gets attention again — typically a marketing campaign.
- Versioned projections accumulate storage until retirement, and the retirement rule interacts with session-pinned versions.