systemdrill.
PATTERN LIBRARY / 06

Atomic Blob Publication

Make large bytes immutable and coordinate only their small visible pointer.

On this pageStage, verify, publishGuard concurrent versionsGarbage collection is part of correctness

Stage, verify, publish

An upload session owns uncommitted parts. Verify all required parts and complete the immutable object before committing a visible manifest. Store a finalization identity so a lost response returns the already published version. A failed metadata commit leaves an orphan, which is safer than a visible missing object.

Guard concurrent versions

Publish with the expected base metadata version. If another editor already advanced it, preserve the uploaded content as a conflict version or merge under explicit rules. Do not erase another user’s edit simply because your upload finished later.

Garbage collection is part of correctness

A momentary absence of live references is insufficient if a concurrent publisher can still acquire one. Include active uploads as roots, coordinate final deletion with reference acquisition, and use generations/grace periods with bounded operation lifetimes. A final unprotected existence check still has a race.

Authorization applies to content access even when blobs are deduplicated. A hash identifies bytes; it does not identify who is permitted to read them. Signed URLs have a lifetime and therefore an explicit revocation window unless the delivery path checks revocation separately.

Study File storage and Media streaming.

Source: content/patterns/storage/publication.md · Edit the Markdown to make this book your own.