Database failover RPO RTO
Design automatic failover for the primary database of an e-commerce order service with async cross-AZ replicas and one async cross-region replica. The business wants RPO near zero for orders (no lost paid orders) and RTO under 60 seconds, but cannot afford the latency of synchronous cross-region replication on every write. Reconcile these goals: how do you do failover, and what do you tell the business is actually achievable?
What a strong answer looks like
Clarify scale and constraints first. Propose a clean component breakdown, then go deep on the hard parts (data model, bottlenecks, consistency, failure modes) and name the trade-offs you are making.
Clarify5:00 left
Estimate5:00 planned
Design15:00 planned
Deep dive12:00 planned
Failure8:00 planned
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.