Design an ETA Service and Location Sharing Between Driver and Rider — System Design Interview Practice
Design a system to calculate ETA and share real-time location between drivers and riders. Work through the requirements, architecture trade-offs, and an interactive design review.
Concepts and architecture decisions to consider
- locationConcept to explore
- etaConcept to explore
- real timeConcept to explore
Interview prompt
Design driver and rider location sharing with map matching, ETA calculation, and privacy so users can publish a location and refresh ETA reliably at scale.
- Define the source of truth for trip consent and final route state and make retries idempotent.
- Use bounded, partitioned state to meet 1M active trips and 1M location updates per second and ETA update p95 <=2s.
- Separate the critical request path from map matching, route recalculation, notifications, and history.
- Explain consistency, failure recovery, authorization, observability, and a degraded mode.
Requirements and scale assumptions
- Support the core workflow to publish a location and refresh ETA.
- Expose status, results, and freshness appropriate to driver and rider location sharing with map matching, ETA calculation, and privacy.
- Support authorization, validation, updates, deletion, and recovery semantics.
- Meet ETA update p95 <=2s under normal load.
- Scale to 1M active trips and 1M location updates per second without a single hot key or unbounded synchronous work.
- Do not lose committed state; make retries and duplicate events safe.
- Degrade safely when downstream workers, caches, or external dependencies fail.
- 1M active trips and 1M location updates per second
- Partition by the primary tenant, user, item, or geographic key and isolate hot partitions.
- Keep serving state bounded; retain raw events or durable records for replay and auditing.
- Peak scale: 1M active trips — Capacity assumption that drives partitioning and backpressure.
- Latency target: ETA update p95 <=2s — User-facing budget for the primary request or read path.
- Durable boundary: Committed before async — The source of truth is trip consent and final route state.
- Async boundary: At-least-once workers — Keep map matching, route recalculation, notifications, and history off the synchronous path.
Key entities
- InteractioninteractionId, actorId, objectId, type, version, occurredAt
Canonical eta location sharing interaction with an idempotency key and ordering version.
- ConnectionSessionsessionId, userId, deviceId, roomKey, lastHeartbeat, status
Ephemeral but observable eta location sharing connection registration used for routing and presence.
- FanoutCursorstreamKey, shard, offset, consumerGroup, updatedAt
Durable progress marker for eta location sharing fan-out and replay.
- DeliveryReceiptinteractionId, recipientId, channel, attempt, status, deliveredAt
Deduplicated eta location sharing delivery state for reconnects, retries, or acknowledgements.
Data flow
- 1. Accept and commit the interactionThe eta location sharing gateway authenticates the actor, validates room or object membership, applies rate limits, and conditionally commits the interaction.
- 2. Publish an ordered eventAn outbox emits the committed eta location sharing transition with an event ID, partition key, sequence, and replay retention.
- 3. Fan out by partitionConsumers route eta location sharing events to connected recipients, durable inboxes, or notification channels without making the origin write wait for every recipient.
- 4. Resume and reconcile connectionsClients reconnect with a cursor; the eta location sharing service replays missed events, deduplicates delivery, and exposes stale or degraded state.
- 5. Measure latency and recoverOperations tracks eta location sharing publish-to-deliver latency, hot partitions, reconnect storms, dropped events, and consumer lag for replay or repair.
Deep dives and trade-offs
- Ordering, idempotency, and hot keysChoose a eta location sharing partition key that preserves required order while distributing high-volume rooms, users, or objects. Use event IDs, inboxes, consumer offsets, and conditional state transitions for at-least-once delivery. Split or isolate hot partitions without changing the client-visible sequence contract.
- Reconnect and replay semanticsIssue resumable eta location sharing cursors with an expiry and a clear snapshot-plus-delta fallback. Bound replay windows and rebuild from durable state when a cursor is too old. Expose version and freshness so a client can distinguish current, catching up, and degraded state.
- Backpressure and presenceKeep connection heartbeats and ephemeral presence separate from durable eta location sharing interactions. Coalesce safe updates, shed low-value work, and protect critical events during reconnect storms. Measure end-to-end delivery, not only broker publish latency.
- Direct fan-out versus pull-based readsUse push for latency-sensitive eta location sharing deltas and pull or replay for reconnect, history, and recovery. A push-only design loses state when clients disconnect and a pull-only design wastes latency and bandwidth.
- Per-recipient queues versus shared streamsUse shared partitioned streams with per-recipient cursors where fan-out is large, and isolate exceptional high-fanout objects. A queue per recipient becomes expensive and hard to inspect at large scale.
- Strong ordering versus availabilityGuarantee ordering only within the scope the product needs, such as a room, object, or conversation. Global ordering introduces a bottleneck and still does not solve duplicate delivery or reconnect recovery.