Search Indexing Service  ·  View 01 of 21  ·  Context and scope

System Context

Who searches, who publishes, which systems of record feed the index, and what the platform declines to own.

Editable source SVG draw.io All views
Systems of record (owned elsewhere) Inventory Service DynamoDB Catalogue Service Aurora PostgreSQL Merchant Service People Consumer 40 M MAU Merchant 180 k active Search Engineer Platform SRE Consuming products Mobile & Web Apps Discovery & Feeds Merchant Console Search Indexing Service Index lifecycle + query Platform dependencies Enrichment Services categorise, geocode, score IAM & KMS Observability CloudWatch, Grafana searches edits listings tunes relevance reindex, rollback stock stream push query API query API own-listing search best-effort identity, keys signals Search Indexing Service — System Context External / third party Person or role Security / platform synchronous event / async failure / alternate Out of scope: the search UI, semantic/embedding retrieval, the systems of record, the analytics warehouse. v 1.0 · owner Data Platform Architecture · date 2026-10

Decisions

  • The platform holds no authoritative copy of any business entity. Sources stay with their owners; the index is a projection.
  • Four source systems, two with native change streams and two pushing changes through a signed API — the push path is the weakest supported case and is labelled as such.
  • Enrichment is a dependency the platform is allowed to lose: the edge is drawn as a failure-tolerant call, not a requirement.
  • Consuming products reach the index only through the query API, and only ever through an alias.

Deliberately out of scope

  • The product's own search UI and ranking surfaces.
  • Semantic retrieval and the embedding pipeline — a separate use case with its own index contract.
  • The systems of record, and the analytics warehouse that also reads them.

Assumptions

  • 40 million monthly active consumers, 180,000 active merchants, 12 product tenants, 80 million live documents.
  • Sources can emit a daily full snapshot to object storage; two of the four cannot emit a change stream at all.