Scaling a Payments Ledger to 10K TPS
Replacing a legacy ledger with an event-sourced core capable of sustaining mission-critical transaction throughput.
The incumbent system relied on optimistic locking on shared rows and could not sustain bursts above 800 TPS. Reconciliation drift was absorbed by manual operations work, and the audit trail was incomplete for regulators.
An append-only journal forms the source of truth. Commands are validated by domain aggregates with strict invariants, then emitted as events through Kafka. Projection workers materialize balances, statements, and reporting views. All state changes are idempotent and replayable.
┌────────────┐ ┌──────────────┐ ┌──────────────┐
Client ─▶│ API Edge │───▶│ Command Bus │───▶│ Aggregates │
└────────────┘ └──────────────┘ └──────┬───────┘
│ events
┌──────▼───────┐
│ Kafka │
└──┬────┬───┬──┘
│ │ │
┌─────────▼┐ ┌─▼─┐ ▼─────────┐
│ Balances │ │AML│ │ Reports │
│ Project. │ │ │ │ Project.│
└──────────┘ └───┘ └─────────┘- 01
Modelled domain with event storming; identified 6 aggregates and ~40 events.
- 02
Idempotency keys at the command layer; deterministic projections.
- 03
Outbox pattern guarantees exactly-once event publication.
- 04
Chaos drills weekly: broker partition, replica failover, projector lag.
