Search Indexing Service · View 16 of 21 · Operations
Decisions
- One write region. Two regions assembling the same entity produce two documents that no alias reconciles, and nothing in this design makes that reconciliation cheap.
- Read regions serve a follower index with a declared staleness and take no local writes; on failover, indexing resumes from the log rather than from the follower.
- The query tier is provisioned for the dinner-hour peak rather than scaled into it, because autoscaling latency is visible inside a 250 ms p99.
- Reindex orchestration is regional and stateful in the registry, so an interrupted rebuild survives a task replacement.
Assumptions
- Three availability zones, 3× MSK brokers, OpenSearch data nodes per zone with two replicas; RTO 15 min to serve from a read region.
- Cross-region replication lag is a published number on the response, not an internal metric.