Observability Platform  ·  View 12 of 25  ·  Data

Storage Zones

Grouped by recovery obligation rather than by technology: what cannot be lost, what can be rebuilt, what may vanish.

Editable source SVG draw.io All views
NOT DERIVED — losing this loses the platform. RPO ≤ 1 min, RTO ≤ 15 min. Catalogue, budgets, rules Aurora PostgreSQL, Multi-AZ Config as code Git — the second copy Query audit 13 months Cost ledger per team, daily DERIVED — replayable from the buffer while it still holds the window. No RPO. Hot — interactive query Metric ingesters recent window in memory Log hot parts ClickHouse, 7 days Exemplar index DynamoDB, 90 days Warm and cold — object storage is the substrate S3 Standard blocks, parts, traces S3 Glacier IR logs to 400 days S3 Object Lock compliance class, 7 years VOLATILE — its loss is a telemetry gap, shown as a gap and never interpolated Node agent spool bounded, sheds by class Gateway batch in memory Tail sampler hold 45 s of in-flight traces Ingest buffer — MSK, 72 h retention, RPO ≤ 5 min KMS — keys held outside the platform replay replay flush age out crypto-shred Storage Zones — By Who Owns It and Whether It Can Be Rebuilt Data store Security / platform Application we own Queue / topic event / async batch synchronous The zones are drawn by recovery obligation, not by technology: four stores carry a strict RPO, six carry none, and three are allowed to vanish. v 1.0 · owner Reliability Architecture · date 2026-09

Decisions

  • Telemetry is derived and perishable. Only the control plane, the query audit and the cost ledger carry a strict recovery objective; every telemetry store replays from the buffer or is honestly a gap.
  • The buffer's retention window is what makes that claim true. At 72 hours it is the platform's real RPO story, and shortening it to save money quietly shortens every store's recoverability.

Numbers

  • Control plane RPO ≤ 1 min, RTO ≤ 15 min. Ingest buffer RPO ≤ 5 min, RTO ≤ 15 min. Query RTO ≤ 30 min.
  • Subject erasure across every tier including cold: within 30 days of request, which is why the compliance class is separable and crypto-shred exists as a last resort.

Risks

  • Three stores are allowed to vanish — the node spool, the gateway batch and the tail sampler's hold window. Together they are up to 45 seconds of in-flight traces plus whatever the spool held, and that is the loss a gateway restart actually costs.