System Design Notebook / 02
Object Storage
Why a file is not your application's data, and what to do about it
Seven ways the obvious design dies, one at a time, then block, file and object storage compared on what they actually promise. Ends on the trade you are making when you pick one.
- pages
- 86
- sections
- 54
- editions
- Reading, Print, Tablet
Sign in to read it
The whole notebook is free for 7 days. No card, no payment. We ask for an account so the download link belongs to someone.
Sign in with GitHub or GoogleWhat is inside
The full table of contents. Nothing here is hidden: if a section you need is not in this list, the notebook is not the right one and you should not spend a week on it.
- The whole picture on one page
- 1. The requirement, and the intuitive answer
- 2. Failure 1: the file does not fit
- 3. Failure 2: the disk is ephemeral
- 4. Failure 3: horizontal scaling, and the 1-in-N 404
- 5. Failure 4: the disk grows the wrong way
- 6. Failure 5: durability is not availability
- 7. Failure 6: your server is an expensive CDN
- 8. Failure 7: no transaction across two systems
- 9. Block storage
- 10. File storage, and what POSIX costs
- 11. Object storage: the minimum interface
- 12. The trade you are actually making
- 13. Key, value, metadata, bucket
- 14. There are no folders
- 15. Designing the key
- 16. Why LIST is not a lookup
- 17. What happens when you PUT
- 18. The data plane: replication and erasure coding
- 19. Eleven nines, read carefully
- 20. The metadata plane
- 21. Consistency: eventual, then strong
- 22. Conditional writes, the primitive that changed things
- 23. Architecture A: through your server
- 24. Buffering versus streaming
- 25. The limits streaming does not remove
- 26. Architecture B: presigned URLs
- 27. The hole in a presigned PUT
- 28. Presigned POST policies
- 29. The two-phase upload
- 30. Reconciliation: pending, expired, orphaned
- 31. CORS, the last mile
- 32. Why a single PUT stops working
- 33. The multipart protocol
- 34. Choosing the part size
- 35. The ETag trap
- 36. Abandoned uploads: the invisible bill
- 37. The full large-file architecture
- 38. Resuming
- 39. Never relay a download
- 40. Three delivery patterns
- 41. Why a presigned GET destroys your cache
- 42. Range requests
- 43. Segmented streaming, and where object storage stops
- 44. The bill
- 45. The security surface
- 46. Lifecycle, storage classes and versioning
- 47. Untrusted content, and what to watch
- 48. The delivery script
- 49. Whiteboard drawing order
- 50. Follow-up question bank
- Appendix A. Numbers to memorise
- Appendix B. Glossary
- Appendix C. Self-test
How to read it
Read with a pen. Every notebook opens with a question to answer before you start and asks you to redo the answer at the end, and the margin in the Print edition exists so you have somewhere to be wrong first. The Tablet edition is 16:9 with vector text, so note apps draw on it rather than treating it as a photograph.