Problem statement
Design an ephemeral "stories" service where a user posts short photo or video clips that are visible to their followers for 24 hours and then automatically stop being served.
Operating context. Hundreds of millions of people open the app daily. Each posts a few stories and watches many. Media clips are a few seconds long, up to about 10 MB, and reads dwarf writes. When a viewer opens the app they see a "tray" of followed authors who currently have fresh, unseen stories, tap in, and watch them in order. The system tracks which viewer saw which story and gives the author an aggregate viewer list. Twenty-four hours after posting, a story must disappear from every tray and no longer be playable.
Out of scope. The video transcoding pipeline internals, DRM, direct-message replies to stories, ad insertion, and recommending whose story to watch. Assume other teams own those.
What to produce. A high-level architecture covering: the upload path and where media bytes vs metadata live, storage and CDN delivery for playback, the read model that assembles a per-viewer tray of authors with unexpired unseen stories, the expiry-and-reclamation mechanism, and how per-viewer "seen" state and author-facing view counts are recorded off the hot path. Sketch the components and the request flow; checkpoints will probe the tray read model and the expiry design.
Functional requirements
- Accept a photo or video story upload and make it viewable by the author's followers within seconds.
- Assemble a per-viewer story tray of followed authors who have unexpired, unseen stories.
- Play an author's stories in posting order and record which viewer saw which story.
- Show the author an aggregate viewer list and total view count for each story.
- Stop serving and reclaim a story automatically 24 hours after it was posted.
Non-functional requirements
- 300M daily active users; 150,000 story uploads/sec at peak; each media object up to 10 MB.
- Story-tray read path p99 under 150 ms while serving 500,000 tray reads/sec.
- Media served from edge with a cache hit ratio above 95%; playback start p99 under 400 ms.
- 99.95% availability for playback and 99.9% for upload.
- Expiry enforced within 60 seconds of the 24-hour mark; no expired media ever served.
- Per-(viewer, story) seen state is durable; view counts converge within 30 seconds.
Topics
- System Design HLD
- Media Storage
- Infra CDN
- Data Ttl-Expiry
- Social Stories