Search Indexing Service  ·  View 09 of 21  ·  Structure

Integration Surface

Four ways in, four ways out, and three different authorisation stories among them.

Editable source SVG draw.io All views
Inbound Source Change Streams CDC + DynamoDB Streams Push Ingest API signed, versioned Daily Snapshot Export S3 Definition API admin plane Search Indexing Service Indexing & Query Platform 40 indices · 12 tenants Outbound Query API alias-scoped Enrichment Calls timeout + fallback Engagement Log Sink Firehose to S3 Audit Sink Object Lock stream HTTPS nightly HTTPS HTTPS best-effort sampled audit Integration Surface — Who Writes In, Who Reads Out External / third party Interface / broker Data store Application we own Security / platform event / async synchronous batch failure / alternate Four inbound surfaces with three different authorisation stories; the alias-swap privilege is not among them. v 1.0 · owner Data Platform Architecture

Decisions

  • Change streams, the push API and the snapshot export are three distinct inbound contracts with different guarantees; the push API is explicitly the weakest because it may arrive without a source version.
  • The definition API is an inbound surface, but moving an alias is not: that privilege is held separately and is not exposed as an integration at all.
  • The engagement log is an outbound surface because relevance cannot be evaluated without it, and it is the one place query text leaves the query path.

Risks

  • A source that silently stops emitting looks identical to a source with nothing to say. The quiet-period alarm on each binding is the only detector.
  • The snapshot export is a dependency on someone else's batch job; a stale snapshot quietly lengthens every rebuild.