Storage Tiering Service  ·  View 01 of 31  ·  1 · Context and scope

System Context

Who reads through the service, who changes what it does, the storage it places into, and the shared services it depends on without owning.

Editable source SVG draw.io All views
Who reads through it File service web · mobile · sync ML training pipelines non-promoting People and records authority Storage economics lead Legal operations Storage SRE Records management holds · retention Storage and its ledger Ceph object tiers hot · warm · cold Tape archive EOS + CTA · LTO Offsite vault Phase 3 custodian Finance chargeback storage ledger Storage Tiering Service 9.2 B objects · 41 PB Shared services and bulk readers Export and eDiscovery bulk readers Identity and keys Keycloak · SPIRE · OpenBao resolve placement declared reads policy · ladder holds · recalls drift · reversal hold events copy · verify · release archive · stage cartridges net saving recall jobs OIDC · SVIDs · keys Storage Tiering Service — System Context External / third party Person or role Security / platform synchronous event / async batch v 1.0 · owner Storage Platform Architecture · date 2026-09

Decisions

  • The tiers are drawn outside the boundary. Ceph and the tape estate belong to the storage team and are consumed as a declared ladder of prices, latencies and durabilities. The service decides placement; it does not run disks.
  • Records management owns holds. The service consumes them as constraints it may not violate and never decides what may be deleted.
  • Export, eDiscovery and ML pipelines are separate callers because they read in bulk. They are the source of every retrieval storm and every false 'hot' signal, so they get their own interface and their own reader classes.

Assumptions

  • About 180,000 tenants, 9.2 billion objects, 41 PB logical, 1.4 million reads a second at peak. Figures are the requirement's own and are revised against real telemetry in the proof phase.
  • The requirement targets Google Cloud. This package runs on hardware the organisation owns, so provider class names, retrieval fees and minimum-duration charges become internal transfer prices published by the storage team (view 09).
  • Keycloak, SPIRE, OpenBao and the finance chargeback ledger already exist and are operated by other teams.

Out of scope

  • Durability of the tiers, deletion and retention policy, encryption choices, and the byte-serving path to end users. Each is consumed as a declared property.