Design a Video Processing Pipeline, stage 14 of 14: defend it
Defend the design
A staff engineer reviews your design and says:
"This is overbuilt. Use a managed transcoding service: hand it the object key, and it calls our webhook when it's done. Delete the workers, the leases, the reconciler, all of it."
They might be right. Respond as you would in the review.
System so far· 8 parts
Select a component to see what it is responsible for and which state it owns.
- 1Instructor browser → Video API: Create upload, report parts, poll status
- 2Instructor browser → Object storage: Upload parts via presigned URLs
- 3Video API → Object storage: Complete multipart upload, verify object
- 4Video API → Postgres: Video row and job row in one transaction
- 5Transcode workers → Postgres: Claim lease, heartbeat, fenced completion
- 6Transcode workers → Object storage: Read raw upload, write attempt output
- 7Reconciler → Postgres: Find abandoned uploads and orphaned output
- 8CDN → Object storage: Origin fetch on cache miss
- 9Student player → CDN: Manifest and segments
- Request / response
- Bulk data
What you need to know
A managed service (here, a transcoding API) removes the parts it runs for you: workers, scaling, codecs. It doesn't remove guarantees that live at the boundary between it and your system.
When evaluating "just use service X", list each guarantee your design provides and ask: does X provide it, or does it move to the code that talks to X?
Check
The managed service calls your webhook when a transcode finishes. Which guarantee is still yours?Think first
An instructor deletes a video while the managed service is still transcoding it. Its webhook later reports success. What must your handler do?