Design canvas: defend your durability number
Every S3 decision — replicate-small vs erasure-code-large, placement across failure domains, strong-in-region vs eventual cross-region, lifecycle + incomplete-MPU cleanup — is a workload-driven choice that must survive a correlated-failure objection.
We've built every piece — keyspace, immutability, erasure coding, placement, the two planes, repair, consistency, multipart, lifecycle — so the last move is to assemble them for a real workload and defend the durability number.
Scene 11
Design canvas: defend your durability number
- Watch
- Try it
- Predict
- Capture
Workload A — media/backups. The defensible config is pre-loaded: erasure-code the large blobs, spread fragments across failure domains, strong consistency in-region with async cross-region replication, lifecycle to archive. The verifier walks green and every check names the earlier scene it satisfies; the durability readout shows the projected nines.
Highlighted lines are the ones running in the diagram right now.
def gradeConfig(workload, knobs):for obj_size in workload.object_sizes:# replicate small, erasure-code large (s3-04)if obj_size < knobs.small_object_threshold:require(knobs.scheme == REPLICATE)else:require(knobs.scheme == ERASURE_CODE)# EC on tiny objects amplifies bytes 2.8-3.3xif workload.dominant_size < 1_KB:reject_if(knobs.scheme == ERASURE_CODE, cite='s3-04')require(knobs.placement == SPREAD, cite='s3-04a')
def killRack(fragments, k, m, placement):# group the k+m fragments by failure domainper_domain = group_by(fragments, lambda f: f.domain)worst = max(len(g) for g in per_domain.values())# one domain dies -> all its fragments vanish at onceif worst > m:return DATA_LOST # exceeds the code's tolerance# <= m lost: repair reads k survivors, rebuilds (s3-06)return SURVIVES
def projectNines(failure_rate, mttr, m, placement):# the model ASSUMES failures are independentif placement != SPREAD:return INVALID # co-location voids the premise# P(loss) ~ (failure_rate * mttr) ^ (m+1)p_loss = (failure_rate * mttr) ** (m + 1)return nines_of(1 - p_loss) # repair (mttr) sets the window
Where this sits in Build an S3-style distributed object store
Scene 11 of 12, in the Design canvas act — Assemble it for a workload and defend the durability number.. Assemble code, placement, consistency, and lifecycle for a workload — then survive a correlated-failure objection.
All 12 scenes in Build an S3-style distributed object store · Every curriculum