SLO and Error Budget Service  ·  View 15 of 21  ·  Runtime

Recompute Lanes

Five reasons a published figure changes, through one engine with five schedules.

Editable source SVG draw.io All views
Trigger Scope Schedule Compute Publish Late data Bucket within horizon One minute Inline, continuous Re-sum the window seconds Projection advances Definition change New version merged One SLO, 28 days On demand Re-project the cube p95 90 s Corrected history Exclusion approved Two approvers An interval Immediate Overlay, no rewrite buckets untouched Both figures kept Full-estate backfill Cube schema change 5,000 SLOs, 13 mo Scheduled window spot capacity Partitioned by SLO ≤ 6 h Read path unaffected Shadow verification Continuous Sampled SLOs Always on Rebuild and compare Divergence alert Recompute Lanes — Five Reasons History Changes Application we own Data store Decision point Security / platform Risk / gap Five reasons a published figure changes, through one engine with five schedules. Only the second and fourth cost real compute, and neither is allowed to touch the read path — which is why the recompute runner is a separate deployment on preemptible capacity rather than a mode of the calculator. v 1.0 · owner Reliability Architecture · date 2026-10

Decisions

  • Only two of the five lanes cost real compute, and neither may touch the read path. That is why the recompute runner is a separate deployment on preemptible capacity (ADR-16).
  • An approved exclusion is an overlay, never a bucket rewrite. The lane exists so the operation is visibly cheap and visibly non-destructive (ADR-11).
  • Shadow verification runs continuously rather than on demand, because a rebuild path exercised only during an incident is a claim rather than a capability.

Targets

  • Single-SLO recompute over a 28-day window ≤ 90 s (p95); full-estate backfill ≤ 6 hours on scheduled spot capacity — assumed.
  • Late-data recompute is inline and continuous, completing in seconds within the 10-minute horizon.
  • Shadow divergence on any sampled SLO raises an alert rather than silently correcting.

Risks

  • Preemptible capacity means a full-estate backfill has no completion guarantee. The 6-hour figure is a target on a best-effort pool, which is acceptable only because nothing reads from a backfill in progress.
  • A definition change recomputes the current window but cannot change a sealed snapshot, so a long-standing definition error leaves a permanent discontinuity in the trend.