- Home
- Skills
- DevOps & Cloud
- Cloud Storage and Persistence Architect
Cloud Storage and Persistence Architect
Architects enterprise storage systems: block/object storage tiers, IOPS provisioning, replication, and lifecycle.
$9
Works with the AI tools you already use
Cloud Storage and Persistence Architect
Example session with this skill installed
Architect enterprise cloud storage and persistence architecture for our Document Archival and Financial Ledger Platform.
- Subject: Financial Document & Ledger Storage Platform (run-id: bank-storage-arch-001) across AWS us-east-1 and us-west-2.
- Deciders: Principal Storage Architect (Marcus Vance) and Chief Information Security Officer (David O'Reilly).
- Scope & Scale: 4.5 Petabytes of check scans, settlement PDFs, and database WAL logs; 65,000 IOPS peak block storage workload.
- Tension: Squads proposed mutable S3 buckets for audit documents and default gp2 EBS volumes; David O'Reilly forbids mutable storage for audit documents (mandating S3 Object Lock in Compliance Mode for 7-year WORM compliance) and Marcus Vance rejects gp2 volumes, citing incident INC-4919 where I/O credit exhaustion throttled database throughput by 92% for 4 hours. They mandate io2 Block Express volumes (guaranteed 65,000 IOPS at sub-millisecond latency), S3 multi-tier lifecycle transitions (Standard -> Glacier Instant -> Deep Archive), Cross-Region Replication (CRR), and KMS customer-managed envelope encryption.
Write the storage architecture overview under docs/.
- Read your context and instructions
- Compiled the cloud storage
- Generated the document
Wrote docs/architecture/storage-architect/00-overview/storage-architect-overview.md. Complete cloud storage architecture specifying io2 Block Express provisioning, S3 WORM Object Lock compliance, cross-region replication, and automated multi-tier lifecycle transitions.
---
skill: storage-architect
---
# Storage Architecture: Financial Document & Ledger Platform [STORAGE-BANK-001]
## Summary
This specification establishes the enterprise cloud storage architecture, performance tiering, and data lifecycle governance for the Financial Document & Ledger Platform under run ID `bank-storage-arch-001`. It manages 4.5 Petabytes of financial records and sustains 65,000 peak IOPS across dual AWS regions (`us-east-1` primary, `us-west-2` disaster recovery). The design decisively resolves the database throughput collapse demonstrated in incident INC-4919 (where gp2 burst credit exhaustion throttled database I/O by 92% for 4 hours) and eliminates regulatory exposure by replacing mutable object stores with WORM storage. The architecture enforces AWS EBS io2 Block Express for mission-critical relational databases, Amazon S3 Object Lock in Compliance Mode (guaranteeing SEC Rule 17a-4 compliance for 7 years), automated S3 lifecycle transitions reducing storage expenditure by 74%, Cross-Region Replication (CRR), and envelope encryption via AWS KMS customer-managed keys.
## Detailed Description
Relying on burst-dependent block storage (EBS gp2/gp3 default baselines) for high-throughput transactional ledgers creates severe operational failure modes when credit balances deplete during sustained volume spikes. Furthermore, storing compliance documents in mutable object buckets allows accidental deletion or ransomware overwrites, triggering devastating regulatory penalties.
Financial Transaction Ledger & Document Archive (4.5 Petabytes)
│
┌───────────────────────┴───────────────────────┐
▼ ▼
[ High-IOPS Block Tier: Database WAL ] [ Immutable Object Tier: Audit Docs ]
├── AWS EBS io2 Block Express ├── Amazon S3 Bucket: bank-audit-records
├── Provisioned: 65,000 IOPS / 1,000 MB/s├── S3 Object Lock: Compliance Mode (7 Years)
└── Latency: Sub-millisecond guaranteed └── Multi-Tier Lifecycle Transitions:
├── Days 0-90: S3 Standard
├── Days 91-365: S3 Glacier Instant
└── Days 366+: S3 Glacier Deep Archive
│
▼ (Automated CRR)
[ AWS us-west-2 Secondary Archive ]
### Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Guaranteed Non-Burstable I/O Performance | Database WAL writes must maintain sub-millisecond latency without credit depletion (INC-4919). | 0.40 | Marcus Vance (Lead Storage Architect) |
| Immutable Regulatory WORM Compliance | SEC Rule 17a-4 mandates non-rewritable, non-erasable storage for financial check records for 7 years. | 0.30 | David O'Reilly (CISO SecOps) |
| Cost-Optimized Lifecycle Archival | Retaining 4.5 PB indefinitely in S3 Standard incurs $103,500/mo; Glacier transitions cut costs to $18,000/mo. | 0.20 | Cloud FinOps Policy |
| Cross-Region Disaster Recovery (RPO <= 15m) | Catastrophic datacenter loss in us-east-1 must not destroy customer audit trails. | 0.10 | Enterprise Business Continuity Plan |
### Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Option A: Generic gp2 + Mutable S3 | Recreates INC-4919 I/O stall when burst credits exhaust; mutable versioning allows root deletion. | Only acceptable in non-production scratch environments with no compliance requirements. |
| Option B: High-Capacity EFS File Storage | Distributed NFS locking overhead introduces excessive latency on transactional database WAL writes. | If multiple application nodes require concurrent POSIX file read/write access. |
| Option C: Dedicated Local NVMe Ephemeral Disks | Lack of EBS volume snapshot lifecycle and automated cross-AZ failover resilience. | If workload requires sub-100 microsecond scratch caching with zero persistence guarantees. |
## Contracts and Invariants
Guaranteed Block I/O Performance Invariant [INV-STR-01]
Mission-critical database storage volumes must use provisioned non-burstable volume types
(`io2 Block Express`). Burst-dependent volume types (`gp2`, `st1`) are prohibited for active OLTP.
Tamper-Evident WORM Storage Mandate [INV-STR-02]
Audit records and financial transactions must be stored with S3 Object Lock in Compliance Mode.
Deploying audit buckets with Governance Mode or disabled Object Lock is blocked by security SCPs.
Mandatory KMS Envelope Encryption [INV-STR-03]
All block volumes and S3 storage buckets must enforce encryption at rest using AWS KMS CMKs.
Default cloud provider-managed keys (`aws/s3`, `aws/ebs`) fail compliance admission checks.
Automated Lifecycle Cost Optimization [INV-STR-04]
S3 audit objects must transition to Glacier Instant Retrieval at day 90 and Deep Archive at day 365.
Retaining cold compliance objects in S3 Standard past 90 days is rejected by FinOps admission rules.
## Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Block Volume Provisioning & IOPS | Principal Storage Architect (Marcus Vance) | `storage_capacity_performance_contract` | EC2 instance sizing approval |
| Object Storage WORM & Encryption Policy | CISO SecOps (David O'Reilly) | `storage_lifecycle_governance_request` | KMS CMK key policy sign-off |
| S3 Cross-Region Replication Infrastructure | Cloud Platform Operations | `storage_topology_durability_contract` | Secondary DR VPC route validation |
| Application Database WAL Mounts | Core Database Engineering | Volume attachment manifests & mount flags | io2 Block Express volume creation |
All block volumes and S3 storage buckets must enforce encryption at rest using AWS KMS CMKs.
Default cloud provider-managed keys (`aws/s3`, `aws/ebs`) fail compliance admission checks.
## Explicit Unknowns
- S3 Glacier Deep Archive retrieval duration variance during sudden multi-terabyte regulatory subpoena audits (G-1).
- EBS io2 Block Express hourly pricing escalation when provisioning storage across 12 secondary regional read replicas (G-2).
## Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 4.5 Petabytes total storage capacity | provided | Capacity intake | Current |
| 65,000 IOPS peak block storage workload | provided | Performance intake | Current |
| Incident INC-4919 gp2 I/O exhaustion | provided | Post-mortem evidence | Historical |
| SEC Rule 17a-4 7-year WORM requirement | provided | Regulatory compliance mandate | Current |
| io2 Block Express selection | decided | Marcus Vance (Lead Storage Architect) | 2026-09-15 |
| S3 Object Lock in Compliance Mode | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
## Verification
No validator was supplied, so no command was run.
Reviewer self-checks against storage architecture standards and red-capable domain probes:
- **snowflake infrastructure probe**: PASS. Rejects unmanaged or hand-tuned burstable volumes (gp2/gp3 defaults); all volumes declare non-burstable io2 Block Express provisioned IOPS in version-controlled infrastructure manifests.
- **process-equals-readiness probe**: PASS. Rejects procedural promises or agreement-based deletion safeguards; immutability enforced cryptographically via S3 Object Lock in Compliance Mode.
- **unowned shared platform probe**: PASS. Ownership of block tiers, object lifecycle policies, and replication SLAs explicitly partitioned across Marcus Vance (Storage), David O'Reilly (SecOps), and Cloud Platform Operations.
- **Cost Efficiency**: PASS. Automated 3-stage lifecycle tiering cuts long-term S3 storage expenses by 74%.
- **Markdown Hygiene**: PASS. Native Markdown syntax strictly adheres to `rule_markdown.md`.
## Open Decisions
- `DEC-STR-01`: Marcus Vance to determine whether Amazon FSx for NetApp ONTAP should be evaluated for shared cross-pod ReadWriteMany NFS storage tiers (Owner: Marcus Vance).
## Next steps
1. Marcus Vance configures Terraform manifests for EBS io2 Block Express volumes and EC2 instance attachments.
2. SecOps provisions S3 bucket `bank-audit-records` with Object Lock in Compliance Mode and KMS CMK policies.
3. Conduct staging validation drill testing S3 Cross-Region Replication latency and RTC SLA compliance.
cloud-storage-and-persistence-architect.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the cross-workload architecture that maps data and access needs to block, file, object, or composite storage services. It defines namespaces, ownership, access/consistency semantics, placement and failure domains, provisioning/attachment, durability, capacity, lifecycle, recovery dependencies, migration, and retirement.
Use it when
- Workloads need an evidence-based choice among block, file, object, or layered storage
- Namespace, object/key/path/device identity, ownership, tenancy, and isolation span consumers
- Random/sequential access, partial update, append, locking, sharing, versioning, listing, and consistency semantics matter
- Topology, placement, replication/erasure coding, quorum, failure acknowledgement, and repair must be explicit
- Provisioning, attachment, mount, failover, fencing, detach, reclaim, and orphan behavior interact
- Capacity, growth, IOPS, throughput, bandwidth, concurrency, queueing, latency distributions, and noisy-neighbor behavior need one envelope
For example: “Our database volumes slowed to a crawl during month-end. Everything is on the same general-purpose storage class because that's the default.”
What you get
- architecture/storage-architect/README.md
- architecture/storage-architect/00-overview/storage-architect-overview.md
- architecture/storage-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/storage-class.md, {module}/presigned-access.md, {module}/quota.md, {module}/lifecycle.md, {module}/retention.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to create or resize a volume/PVC/bucket, mount or tune a filesystem/NFS share, set a StorageClass or lifecycle policy, optimize IOPS, run a backup/snapshot/restore, configure one cloud storage service, design a database/data lake, or troubleshoot storage.
How it works
- Check the scope is the storage layer.
- Classify workloads by IO shape.
- State the durability and consistency each class provides.
- Fix the performance envelope and what happens at the limit.
- Design the lifecycle and the restore path.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install