Design canvas: defend your durability number

Every S3 decision — replicate-small vs erasure-code-large, placement across failure domains, strong-in-region vs eventual cross-region, lifecycle + incomplete-MPU cleanup — is a workload-driven choice that must survive a correlated-failure objection.

Previously

We've built every piece — keyspace, immutability, erasure coding, placement, the two planes, repair, consistency, multipart, lifecycle — so the last move is to assemble them for a real workload and defend the durability number.

Scene 11

Design canvas: defend your durability number

  1. Watch
  2. Try it
  3. Predict
  4. Capture
DESIGN CANVAS · defend your durability numberworkload AKNOBSCODING SCHEMEerasure-code 17+3SMALL-OBJECT THRESHOLDreplicate < 128 KBPLACEMENTspread across domainsCONSISTENCYstrong in-region · CRR asyncLIFECYCLEtransition→archive · MPU cleanupVERSIONINGon · noncurrent expiryWORKLOADAMedia / backupspreset ASALIENT PARAMSobject size10 MB–5 GB blobsaccesswrite once, read rarelycount~10M objectsVERIFIER · cites earlier scenes✓EC-large fits big immutable blobs — overhead ~1.18×nots3-04✓spread placement keeps ≤ m fragments per failuredomains3-04a✓strong read-after-write in-region; CRR stays eventuals3-07✓lifecycle + incomplete-MPU cleanup bound the bills3-09CORRELATED-FAILURE OBJECTIONspread placement holds — losses ≤ m, object reconstructsrack kill: SURVIVESPROJECTED DURABILITYeleven nines (designed)Workload A — defensible end to end; every knob traces to a scene.
What to watch for

Workload A — media/backups. The defensible config is pre-loaded: erasure-code the large blobs, spread fragments across failure domains, strong consistency in-region with async cross-region replication, lifecycle to archive. The verifier walks green and every check names the earlier scene it satisfies; the durability readout shows the projected nines.

Continue unlocks when the animation finishes.
Implementation

Highlighted lines are the ones running in the diagram right now.

Verifier.gradeConfig
grade each knob against the workload; cite the scene
def gradeConfig(workload, knobs):
for obj_size in workload.object_sizes:
# replicate small, erasure-code large (s3-04)
if obj_size < knobs.small_object_threshold:
require(knobs.scheme == REPLICATE)
else:
require(knobs.scheme == ERASURE_CODE)
# EC on tiny objects amplifies bytes 2.8-3.3x
if workload.dominant_size < 1_KB:
reject_if(knobs.scheme == ERASURE_CODE, cite='s3-04')
require(knobs.placement == SPREAD, cite='s3-04a')
Verifier.killRack
the correlated-failure objection against the placement
def killRack(fragments, k, m, placement):
# group the k+m fragments by failure domain
per_domain = group_by(fragments, lambda f: f.domain)
worst = max(len(g) for g in per_domain.values())
# one domain dies -> all its fragments vanish at once
if worst > m:
return DATA_LOST # exceeds the code's tolerance
# <= m lost: repair reads k survivors, rebuilds (s3-06)
return SURVIVES
Durability.projectNines
the rate equation behind the eleven-nines readout
def projectNines(failure_rate, mttr, m, placement):
# the model ASSUMES failures are independent
if placement != SPREAD:
return INVALID # co-location voids the premise
# P(loss) ~ (failure_rate * mttr) ^ (m+1)
p_loss = (failure_rate * mttr) ** (m + 1)
return nines_of(1 - p_loss) # repair (mttr) sets the window

Where this sits in Build an S3-style distributed object store

Scene 11 of 12, in the Design canvas act — Assemble it for a workload and defend the durability number.. Assemble code, placement, consistency, and lifecycle for a workload — then survive a correlated-failure objection.

All 12 scenes in Build an S3-style distributed object store · Every curriculum

Built with Arqly
Every scene in Build an S3-style distributed object store builds on the one before it.All 12 Build an S3-style distributed object store scenes