Storage Tiering Service · View 01 of 31 · 1 · Context and scope
Decisions
- The tiers are drawn outside the boundary. Ceph and the tape estate belong to the storage team and are consumed as a declared ladder of prices, latencies and durabilities. The service decides placement; it does not run disks.
- Records management owns holds. The service consumes them as constraints it may not violate and never decides what may be deleted.
- Export, eDiscovery and ML pipelines are separate callers because they read in bulk. They are the source of every retrieval storm and every false 'hot' signal, so they get their own interface and their own reader classes.
Assumptions
- About 180,000 tenants, 9.2 billion objects, 41 PB logical, 1.4 million reads a second at peak. Figures are the requirement's own and are revised against real telemetry in the proof phase.
- The requirement targets Google Cloud. This package runs on hardware the organisation owns, so provider class names, retrieval fees and minimum-duration charges become internal transfer prices published by the storage team (view 09).
- Keycloak, SPIRE, OpenBao and the finance chargeback ledger already exist and are operated by other teams.
Out of scope
- Durability of the tiers, deletion and retention policy, encryption choices, and the byte-serving path to end users. Each is consumed as a declared property.