Skip to main content

YU12-aeron-cluster architecture

BLP high availability as Raft consensus: an odd-quorum Aeron Cluster replicates one committed log into a deterministic ClusteredService hosting the inherited matching/risk core; a gateway tier terminates FIX/REST sessions and follows the leader; a feed adapter sequences price ticks and control updates as ingress; committed outputs feed the unchanged CQRS/read-model side.

  • Inherits architectural baseline from: YU11-aeron-replication (which inherits the full YU02..YU10 LMAX/Kubernetes lineage)
  • Generated from: system/architecture.model.json
  • Canonical flows: architecture.md

Architecture Diagram​

Node Catalog​

NodeKindLabelNotes
counterpartyexternalFIX + REST counterpartiesUnchanged external contracts: FIX 4.4 sessions and REST/UI order entry.
gatewayserviceFIX/REST gateway tierTerminates counterparty sessions, screens admission against control-feed state, and forwards through the cluster client; sessions survive leader changes. Scales out horizontally; each replica is an independent cluster session + owner thread, so N replicas give NΓ— ingress; REST round-robins, FIX pins via sessionAffinity: ClientIP (ADR-047).
cluster_clientserviceAeron Cluster clientSpeaks the cluster ingress/egress protocol and routes to the current leader natively.
feed_adapterserviceFeed adapterConsumes inherited NATS pricing and control subjects, conflates per symbol, and publishes ticks and policy updates as cluster ingress.
consensus_leaderserviceLeader: Consensus Module + logRaft leader sequences ingress into the replicated log and commits on majority acknowledgement.
consensus_followersserviceFollowers: Consensus Module + logRaft followers replicate and acknowledge the log; a partition minority cannot elect a leader.
service_containerserviceClusteredService: MatchingEngine + riskSingle-threaded deterministic apply of committed messages through the inherited matching and two-tier risk core on every member.
snapshot_storestoreCluster snapshots + per-pod log PVConTakeSnapshot state bound to the applied log position: book, ID generators, idempotency, risk, symbols, control versions.
egressqueueCommitted output egressLeader-emitted committed outputs: order lifecycle events, fills, and admission responses.
projectorserviceProjector / read-modelUnchanged CQRS side draining committed outputs to MariaDB and inherited NATS distribution subjects. Realized in YU12 by the leader-side trade-egress bridge (TradeNatsPublisher, ADR-048): every booked trade on the deterministic apply stream is republished to NATS /trades, where trade-processor persists Trade + Position to MariaDB and republishes the /accounts/*/trades + /positions UI feeds. Not the gateway egress (best-effort, one-sided).
natsqueueNATS (pricing, control, distribution)Inherited subjects for pricing, control feeds, and output distribution; no replication or witness role.
dbstoreMariaDB read modelInherited read-model and downstream service storage.