Consumer Messaging Platform — WhatsApp-Class System  ·  View 21 of 23

Deployment and Multi-Region Topology

What runs where and what survives a failure: anycast edge, two active regions, three availability zones each, accounts pinned to a home region.

Editable source SVG draw.io All views
Global edge — Anycast
Global edge — Anycast
Points of presence, 200+ sites
Points of presence, 200+ sites
Edge Terminator
TLS + Noise
Edge Terminator...
DDoS Scrubbing
DDoS Scrubbing
CDN Cache
Media blobs
CDN Cache...
Global routing
Global routing
BGP Anycast + GeoDNS
BGP Anycast + GeoDNS
Health-based Steering
Drains a bad region
Health-based Steering...
Region A — primary for pinned accounts
Region A — primary for pinned accounts
AZ-1
AZ-1
Gateway Pool
1M sockets
Gateway Pool...
Core Services
Kubernetes
Core Services...
AZ-2
AZ-2
Gateway Pool
1M sockets
Gateway Pool...
Core Services
Kubernetes
Core Services...
AZ-3 — stateful
AZ-3 — stateful
Message Store
RF 3, quorum write
Message Store...
Delivery Queue
Delivery Queue
Account & Group DB
Sharded, semi-sync
Account & Group DB...
Region B — active for its own pinned accounts
Region B — active for its own pinned accounts
AZ-1
AZ-1
Gateway Pool
Gateway Pool
Core Services
Core Services
AZ-2
AZ-2
Gateway Pool
Gateway Pool
Core Services
Core Services
AZ-3 — stateful
AZ-3 — stateful
Message Store
RF 3, quorum write
Message Store...
Delivery Queue
Delivery Queue
Account & Group DB
Account & Group DB
Multi-region Object Store
Multi-region Object Store
TURN Relay Fleet
TURN Relay Fleet
nearest healthy PoP
nearest healthy PoP
registry replication
registry replication
cross-region route
cross-region route
failover drain, 15 min
failover drain, 15 min
Deployment and Multi-Region Topology
Deployment and Multi-Region Topology
Application we own
Application we own
Security / platform
Security / platform
Data store
Data store
Interface / broker
Interface / broker
Queue / topic
Queue / topic
External / third party
External / third party
synchronous
synchronous
event / async
event / async
failure / alternate
failure / alternate
Accounts are pinned to a home region. Both regions serve live traffic; neither is idle standby.
Accounts are pinned to a home region. Both regions serve live traffic; neither is idle standby.
v 1.0 · owner Platform Architecture · date 2026-08
v 1.0 · owner Platform Architecture · date 2026-08
Text is not SVG - cannot display

Failure domains

  • An availability zone loss removes gateway and service capacity, not data — replication factor 3 with quorum writes
  • A region loss drains to the peer region; accounts re-home on reconnect
  • A point-of-presence loss is invisible: anycast re-routes to the next healthy site

Recovery targets

  • RTO 15 minutes for a full regional failover, RPO effectively zero for accepted messages
  • Registry replication under 1 second, so a re-homed device finds its inbox
  • Both regions serve live traffic; neither is an idle standby that has never been exercised

Capacity

  • Gateway pools sized at one million sockets per pool, scaled horizontally
  • Stateful services isolated in a dedicated availability zone per region
  • Media served from CDN edge, so blob egress does not follow regional capacity