SLO and Error Budget Service  ·  View 02 of 21  ·  Context and scope

High-Level Architecture

Seven stages on one spine, from an aggregate the platform did not produce to a document it does not enforce.

Editable source SVG draw.io All views
Declare Definition reconciler Container Apps job Admission checks resolution, cardinality Remember SLO registry Azure SQL Ingest Indicator stream Event Hubs Event-time bucketer 10 min lateness Store SLI aggregates Data Explorer, 13 mo Compute Budget calculator watermarked Snapshot writer at window close Publish Verdict API signed, p99 150 ms Burn-rate evaluator multi-window Act Release gate outside the platform On-call page or ticket SLO and Error Budget Service — High-Level Architecture Application we own Decision point Data store Queue / topic Interface / broker External / third party Seven stages on one spine. The platform begins at an aggregate it did not produce and ends at a document it does not enforce; everything in between is derivation. v 1.0 · owner Reliability Architecture · date 2026-10

Decisions

  • Ingest and computation are separate stages with a durable store between them, so a computation outage is a freshness problem rather than a data-loss one (ADR-07).
  • Publication splits in two: a synchronous verdict for the gate and an asynchronous burn-rate evaluation for on-call. They read the same derived state but have different latency and availability targets (ADR-09).
  • Admission sits before the registry, not after it, so an unmeasurable objective is refused at authoring time rather than published as a meaningless figure (ADR-15).

Targets

  • Budget freshness p95 ≤ 60 s, p99 ≤ 120 s from event timestamp to updated state — assumed.
  • Verdict API p99 ≤ 150 ms in-region at 400 rps steady state, 2,000 rps for 120 s during a coordinated release window — assumed.
  • Fast-burn page dispatched within 5 minutes (p95) of a 14.4× burn beginning — assumed.

Risks

  • The spine has one authoritative input. If the outcome cube's dimensions are wrong, every stage downstream is confidently wrong and no amount of recompute fixes it (ADR-03).
  • Two publication paths reading one projection means a staleness bug degrades a page and a release decision simultaneously.