Architecture review

The order platform holds today. Peak season needs one change.

Current state, the bottleneck we found, three options and the change we propose.

Platform team Architecture board · October

Where we stand

Healthy today, close to the limit at peak

Last 90 days, production.

99.94%

Availability

SLO 99.9% · met

420 ms

p95 checkout latency

Budget 500 ms

2.1×

Peak traffic expected

Black Friday forecast

31

Deploys per week

From 18 last year

Source: monitoring dashboards, 90-day export

Order platform / architecture review02 / 09

How an order flows

Three services, one synchronous chain

Each hop adds latency and a failure mode.

01 / INGEST

API gateway

Authenticates and validates the order.

Owner: edge team

→
02 / PROCESS

Order service

Prices and reserves stock in one call to the inventory database.

Owner: order team

→
03 / FULFIL

Fulfilment

Books the carrier and sends the confirmation.

Owner: logistics team

The takeawayThe order service waits on the inventory database for every order.

Order platform / architecture review03 / 09

Latency budget

The inventory lock takes half the budget

p95 per hop at today's peak, in ms.

The inventory lock takes half the budget
Inventory lock210 ms+160 Added at 2.1× traffic
Pricing85 ms+40 Added at 2.1× traffic
Gateway60 ms+10 Added at 2.1× traffic
Carrier booking45 ms+15 Added at 2.1× traffic
Confirmation20 ms

Added at 2.1× trafficSource: load test LT-48, 2.1× replay

Order platform / architecture review04 / 09

Options

Reserve stock asynchronously for the best balance

Scored with the order and data teams.

Reserve stock asynchronously for the best balance
OptionPeak latencyEffortRiskRun cost
Scale the databaseWeakLowLowHigh
Async reservationGoodMediumMediumLow
Split the inventoryGoodHighHighMedium

RecommendationMove the stock reservation to an event, confirm the order first and compensate the rare failures.

Order platform / architecture review05 / 09

ADR-021

Reserve stock after the order is accepted

Proposed · for approval today

Context

At 2.1× traffic the synchronous inventory lock pushes p95 latency to 560 ms, above the 500 ms budget.

Decision

Publish an order-accepted event and reserve stock asynchronously; cancel and notify when stock is gone.

Consequences

  • p95 latency back under 350 ms at peak
  • The database lock leaves the checkout path
  • About 0.2% of orders cancelled after acceptance
  • A new compensation flow to test and operate
Order platform / architecture review06 / 09

Risks

Three risks, all with an owner

Reviewed with service owners.

Three risks, all with an owner
RiskImpactLikelihoodOwnerMitigation
Oversold stock during flash salesHighMediumOrder teamHold a 2% safety stock on promoted items.
Event backlog at peakMediumMediumPlatform teamAutoscale consumers; alert on lag over 30 s.
Customers confused by late cancellationsMediumLowCustomer careClear email and an instant refund.
Order platform / architecture review07 / 09

Before we build

Four points to confirm with the board

Decision needed today.

Four points to confirm with the board
DoneOwnerDue
Approve ADR-021 and the compensation flowArchitecture boardToday
Agree the 0.2% late-cancellation budgetProduct owner10 Oct
Load test at 2.5× before the code freezePlatform team31 Oct
Update the runbook and on-call trainingSRE lead7 Nov
Order platform / architecture review08 / 09

Sources

  1. 02Healthy today, close to the limit at peakMonitoring dashboards, 90-day export
  2. Peak forecast 2026
  3. 04The inventory lock takes half the budgetLoad test LT-48 report