| Master custody — immutable, retention-locked, dual-region |
Cloud Storage dual-region bucket, Archive class, object retention lock |
Google Cloud |
Single-region with manual replication; a self-managed object store on-premises |
Dual-region gives RPO 0 without a replication job to operate, and retention lock is a storage-level guarantee rather than application logic the pipeline could be talked out of. |
ADR-02 |
| Recipe store — immutable, content-addressed, indexed |
Cloud Storage dual-region for the documents, Spanner for the index |
Google Cloud |
A relational store holding the documents inline; a document database |
The documents are immutable and want object-store durability; only the lookup wants a transactional index. Splitting them keeps the custody artefact out of a schema that will change. |
ADR-03 |
| Job and chunk-task state — transactional, cross-zone |
Cloud Spanner, regional |
Google Cloud |
PostgreSQL with a leader per region; a lease protocol over a key-value store |
This is the one place in the design needing transactional correctness across zones — task claim, lease expiry and lane accounting in one transaction. The alternative is a lease protocol we would have to write and prove. |
ADR-07 |
| Batch encode fleet — reclaimable, per-second billed |
Compute Engine Spot VMs in zonal managed instance groups, gVisor around the decoder |
Google Cloud |
Committed-use reserved instances; a managed transcoding API priced per minute |
Reclaimable capacity is the economic premise of the whole design, and per-second billing is what makes small chunks affordable. A managed per-minute API removes the decision this use case exists to make. |
ADR-05 |
| Encoders and packaging |
Open-source encoders (FFmpeg-family, SVT-AV1) and Shaka Packager on GKE |
Open source |
A managed transcoding and packaging service; a commercial encoder licence |
Owning the encoder is what makes determinism gateable, build pinning enforceable and the ladder solvable per title. Common encryption from one elementary-stream set is a packager requirement, not a service feature. |
ADR-06 |
| On-demand generation — latency-bound, reserved |
GKE regional warm node pool beside a Cloud Run packaging origin |
Google Cloud |
Scale-to-zero serverless; preemption inside the batch fleet; edge compute |
An assumed p95 of 1.5 s to first byte rules out a cold start and rules out queuing behind Spot work. Edge compute is left open in Question 7 rather than chosen. |
ADR-08 |
| Task dispatch — at-least-once, high fan-out |
Pub/Sub, with task claim in Spanner |
Google Cloud |
A broker with exactly-once semantics; direct scheduler-to-worker assignment |
Determinism and idempotent chunks make at-least-once sufficient, so the expensive delivery guarantee buys nothing. The transactional claim lives where the state already is. |
ADR-06 |
| Content keys and encryption at rest |
Cloud KMS for CMEK and content-key generation, keys held in memory for one packaging job |
Google Cloud |
A self-hosted key manager; keys cached in the packaging tier for throughput |
The pipeline must never be a place a content key is stored, and per-rights-holder key separation is a contract requirement for part of the catalogue. Caching keys would trade a contractual exposure for a latency gain nobody asked for. |
ADR-15 |
| Quality, cost and playback analytics |
BigQuery, partitioned by publish date, fed from Pub/Sub |
Google Cloud |
A time-series database; a warehouse in the analytics estate |
Gate decisions, metric scores and playback outcomes are append-only, queried by date and joined against digests — a columnar store is the natural shape, and the post-hoc gate needs to query it directly. |
ADR-10 |
| Rendition residency and eviction |
Cloud Storage regional with lifecycle rules, driven by a demand-tier controller on GKE |
This design |
Pure age-based lifecycle rules; manual tiering; no eviction at all |
The eviction rule is economic rather than temporal — regeneration cost against retention cost over the policy horizon — and an age rule cannot express it. Lifecycle rules execute the decision; the controller makes it. |
ADR-13 |