Streaming Video Encoding & Packaging Pipeline  ·  View 08 of 22  ·  Structure

Platform Components

The container view on Google Cloud, grouped by plane rather than by service type.

Editable source SVG draw.io All views
Google Cloud — encode region Recipe plane Complexity analyser Cloud Run jobs Ladder solver Cloud Run Recipe store GCS + Spanner index Control plane Job API Cloud Run Job & task store Spanner Lane scheduler GKE, deadline-ordered Task dispatch Pub/Sub Quota & spend governor GKE Execution Batch encode workers Spot MIG + gVisor On-demand encoders GKE warm pool Stitcher Cloud Run jobs Assurance Perceptual scorer VMAF on GKE Structural checker Decoder matrix runner device profiles Gate decision service Package, publish and protect Packager Shaka on GKE Key broker Cloud KMS client Manifest publisher Cloud Run Lifecycle controller tiering, eviction Storage Master bucket dual-region archive Rendition bucket regional, addressed Catalogue projection Spanner + Memorystore Score & telemetry BigQuery Audit log append-only Cloud KMS CMEK + content keys DRM licence service 3 systems Media CDN out of scope Rights & windows digest tasks claim renditions gate-passed wrap/unwrap tiering Platform Components (C4 Container View) Application we own Data store Interface / broker Security / platform Queue / topic Decision point External / third party synchronous two-way batch Thirteen of the edges are omitted: every component writes to the audit log and emits to telemetry. v 1.0 · owner Media Platform Architecture

Stack choices worth arguing with

  • Spanner for job and chunk-task state: this is the one place in the system that needs transactional correctness across zones, and the alternative is a lease protocol we would have to write and prove.
  • Spot managed instance groups for the batch fleet, with gVisor around the decoder — reclaimable compute is the economic premise, and an untrusted codec parser is the assumed attack.
  • Shaka Packager rather than a managed packaging service, because common encryption from one elementary-stream set is the requirement and a per-minute managed price answers the cost question for us.

Why the on-demand pool is separate

  • It is the only fleet with a latency SLO, so it is the only one carrying reserved headroom. Mixing the two would either give the batch fleet an availability requirement it does not need, or give a waiting viewer a Spot queue.

Deliberate omission

  • Roughly thirteen edges are left off: every component writes the audit log and emits to BigQuery. Drawing them would obscure the eight that carry the flow.