SLO and Error Budget Service · View 08 of 21 · Structure
Decisions
- Four tiers deploy independently on one container platform. The computation tier can be scaled, drained or rolled back without touching the read path, which is what keeps a backfill off the gate's latency budget (ADR-07).
- The recompute runner is a separate deployment on preemptible capacity rather than a mode of the calculator, so an expensive full-estate rebuild cannot consume the capacity serving verdicts (ADR-16).
- Exactly one component writes the registry and exactly one signs a verdict. Both are named here and traced in view 20 (ADR-12).
Assumptions
- Managed PaaS throughout — no Kubernetes to operate, on the view that a reliability platform should not be the most operationally demanding thing in the estate.
- The budget projection is a cache, so losing the whole of it is a 90-minute recompute rather than an incident with data loss.
Deliberately omitted
- The ingest chain and the definitions path, drawn in full in views 09 and 10.
- The signing call to the HSM, drawn in view 20 where the privilege story makes it legible.