SLO and Error Budget Service  ·  View 12 of 21  ·  Data

Data Model

Twelve entities, and the two keys that make the arithmetic reproducible.

Editable source SVG draw.io All views
service service_id PK name owning_team tier critical_journey journey_id PK name product_owner composite_rule nullable slo slo_id PK journey_id FK service_id FK owning_team current_version FK slo_version version_id PK slo_id FK indicator_type good_predicate valid_predicate objective_pct window_len, alignment effective_from label_dims bounded sli_bucket slo_id PK1 minute_utc PK2 good_count valid_count coverage ok|no-data source_class ingested_at budget_window window_id PK slo_id FK version_id FK kind rolling|calendar opened_at, closes_at watermark_minute budget_snapshot snapshot_id PK window_id FK total, consumed remaining_pct coverage_pct sealed_at immutable exclusion_window exclusion_id PK slo_id FK from_minute, to_minute reason_code approver_1, approver_2 expires_at budget_policy policy_id PK scope slo|service thresholds[] gate_mode auto|advisory unreachable open|closed exempt_classes[] verdict verdict_id PK slo_id FK state healthy|warning| exhausted|insufficient version_id FK computed_at coverage_pct signature, valid_until alert_rule rule_id PK slo_id FK burn_multiple long_window, short_window class page|ticket alert_decision decision_id PK rule_id FK evaluated_at inputs snapshot fired bool suppressed_reason N : M 1 : N 1 : N 1 : N 1 : 1 N : M 1 : N 1 : N N : M 1 : N Data Model — Definition, Bucket, Budget, Verdict Two keys carry the design. (slo_id, minute_utc) makes bucket writes idempotent, so a replayed batch cannot double-count. A sealed budget_snapshot has no update path, so a later exclusion produces a new annotation rather than a new history. budget_window carries version_id as an FK without a drawn relation, to keep the vertical runs legible; the override register and audit ledger appear in views 19 and 20. v 1.0 · owner Reliability Architecture · date 2026-10

Decisions

  • (slo_id, minute_utc) is the bucket's primary key, so a replayed or duplicated batch is a primary-key collision rather than a double-count. Idempotency lives in the data model, not in the consumer's logic (ADR-08).
  • A sealed budget_snapshot has no update path. A later exclusion produces a new annotation and a new current figure; it cannot alter the figure the compliance record already carries (ADR-14).
  • slo_version carries the predicates and the objective, not slo. Every budget figure is therefore attributable to the exact text that produced it (ADR-05).

Assumptions

  • label_dims is bounded at authoring time — the cardinality limit is a column constraint, not a review convention (ADR-15).
  • A verdict carries valid_until because it is a signed document a machine will act on; five minutes is the assumed validity (ADR-12).
  • composite_rule on critical_journey is nullable and unused at MVP; journey-level composition is Phase 3.

Deliberately omitted

  • The override register and audit ledger, which are drawn with their approval flow in views 19 and 20.
  • budget_window's version_id FK is listed on the entity but not drawn as a relation, to keep the vertical runs legible.