Search Indexing Service  ·  View 11 of 21  ·  Data

Storage Zones

Five zones by what recovery means for each, which is the only classification that changes a decision here.

Editable source SVG draw.io All views
Owned elsewhere — never backed up here Catalogue DB Inventory Store Merchant DB Replayable — the platform's own system of record Change log Change Log MSK · 7 d hot Log Archive S3 · 90 d Rebuild base Source Snapshots S3 · daily, 30 d Strongly consistent and precious — backed up, PITR Definition Registry Aurora · PITR Aliases & Promotions Aurora Judgement Sets Aurora Audit Log S3 Object Lock Rebuildable — not backed up, by decision idx_v41 live OpenSearch idx_v40 retained 72 h rollback Assembly State DynamoDB Enrichment Cache DynamoDB Recent Writes TTL 60 s Cold — evidence and evaluation Query & Engagement Log S3 · 400 d Quarantined Payloads S3 · 30 d Retired Index Archive S3 Glacier rebuild catch-up Storage Zones — Owned, Replayable, Rebuildable, Cold External / third party Queue / topic Data store Security / platform Risk / gap batch event / async A search index is deliberately in the rebuildable zone: snapshots of it would be a recovery-time optimisation, never a durability claim. v 1.0 · owner Data Platform Architecture

Decisions

  • The search indices are deliberately in the rebuildable zone and are not backed up. A snapshot of an index would be a recovery-time optimisation, never a durability claim.
  • The registry is the smallest and most precious store: definitions, aliases and promotion history get point-in-time recovery and an RPO of zero.
  • The change log plus the daily snapshot together are the rebuild base. Log retention is therefore a replay-throughput commitment measured against the 4-hour RTO.
  • Quarantined payloads are stored, because a poison change you cannot read later is a bug you cannot fix.

Assumptions

  • Change log 7 days hot and 90 days archived; snapshots daily, 30 days retained; previous index version 72 hours; engagement log 400 days.
  • RPO 5 s for accepted changes, RPO 0 for definitions and aliases; RTO 15 min for queries from another region, 4 h for a full rebuild, 1 min for a rollback.