System designby Learnastra

System-design interview · Extended interviews

Design a live video-conferencing service

By Anup Rai

Design how participants join a call, establish a media connection, receive suitable video quality, lose access after removal, reconnect and record with permission.

You will learn to

  • Explain signaling, connectivity discovery, relay, and media forwarding in plain terms.
  • Calculate per-client and server bandwidth for mesh versus SFU delivery.
  • Trace authenticated room join, media setup, network restart, and consented recording.

Practice in this chapter

8 interview questions with model answers and follow-ups.

Go to interview practice

Useful foundations: HTTP APIs and request lifecycle · Real-time communication: polling, long polling, SSE, and WebSocket · Load balancing: definition, algorithms and failover · Production readiness: SLI, SLO, observability, and recovery

Workload and timing examples are interview assumptions.

01Problem and scope

A live conferencing service exchanges interactive audio, video and screen content over changing networks. Low delay and intelligible conversation take precedence over retransmitting expired frames. This design supports rooms of two to twenty-five participants, scoped guests, host removal, screen sharing and optional authorized recording. The database retains room membership and permissions; live packet buffers are temporary and may be lost when a media server fails. Encrypting each network connection does not by itself prevent that server from reading the media.

A media track is one source, such as a microphone, camera or shared screen. Signaling exchanges the control messages needed to establish and manage connections; media packets carry the actual audio and video. A selective forwarding unit (SFU) is a media server that receives encoded tracks and forwards selected ones to participants, giving the service a place to enforce subscriptions.

Clarify room size and media goals

Candidate: “How large are rooms, and are we optimizing conversation or one-to-many broadcast?” Interviewer: “Two to twenty-five participants, normal meetings, optional recording.” Candidate: “I will separate room authorization and connection setup from live media, target good conversation on supported networks, and define what happens during a network change. Recording will be an explicit authorized workflow.” Ask whether guests are allowed, hosts can remove participants, and infrastructure may access media. Here, guests require a scoped invitation, hosts can remove users, and the baseline offers encrypted transport with trusted media infrastructure.

Scope and exclusions

Include room creation/join, role-based publish/subscribe, camera/microphone controls, active-speaker layout, screen share, reconnect and optional recording. Exclude telephone-network integration, million-viewer broadcasts and advanced effects. End-to-end encryption against the infrastructure is a later requirement change with consequences for recording; do not promise it merely because a WebRTC connection is encrypted.

02Functional requirements

  1. Join a room. Only an eligible participant receives room credentials and tracks.
  2. Publish audio or camera. Track belongs to the current authorized participant session.
  3. Subscribe to tracks. Forward only allowed tracks at a quality the receiver can sustain.
  4. Share a screen. Enforce presenter policy; prioritize readable screen content.
  5. Remove a participant. New joins fail immediately; existing forwarding stops within the agreed bound.
  6. Reconnect. Preserve participant identity while replacing broken transport state.
  7. Record a meeting. Authorized request, visible recording state and explicit consent/notice policy.

Membership and media controls

A room ID locates a meeting; it does not authorize entry. Participant P1 authenticates or presents an invitation, joins as an identified participant, and receives permission to publish or subscribe. A viewer may subscribe without publishing. Local mute stops participant P1 sending audio, while host-enforced removal must also stop forwarding at the media server.

Constraints and exclusions

Assume one active device session per participant for this exercise. If participant P1 intentionally joins from another device, replace the previous session under a new participant generation: a version number that identifies the currently authorized device session. Allowing several devices is a valid extension, but the design must distinguish their tracks and prevent duplicate audio playback. Distinguish a participant leaving from a signaling socket temporarily disconnecting: a media path may still be useful during a short control outage.

Joining a room is not proof that audio is audible. The client separately reports first received/decoded media and permission/device failures. This gives the product meaningful states: joining, connected, muted, reconnecting or failed, instead of a single misleading green socket indicator.

03Non-functional requirements

  1. Workload assumption. Ten thousand concurrent six-person rooms at a busy planning point; support individual rooms up to twenty-five participants.
  2. Interactive latency. Join-to-first-media p95 below three seconds; one-way conversational media around 150–250 ms on supported regional networks. Track regional/network cohorts rather than promise arbitrary Internet latency.
  3. Call quality and availability. Target successful media setup for 99.9% of authorized join attempts within the documented room-size, client and network support limits. Separately track audio gaps and freezes: a successful join does not make a frozen call successful.
  4. Control durability. Commit room membership and authority changes durably across one control-store failure domain.
  5. Media recovery. Re-establish transport after an SFU failure, targeting p95 below eight seconds after failover is declared; disclose detector delay separately.
  6. Permission revocation. After removal commits, reject new joins and stop existing forwarding within three seconds under the stated bounded-clock assumption.
  7. Recording policy. Agree on consent/notice, retention and access rules. This exercise uses visible policy acknowledgment, an authorized recorder and illustrative thirty-day retention.

Revocation and isolation invariants

Boundary Required guarantee
Room/tenant No cross-room or cross-tenant access
Publication Only the current authorized participant session publishes
Subscription Forward only authorized tracks
Permission lease Authority-issued validity at most two seconds, plus a one-second safety reserve
Clock uncertainty exceeds the reserve Stop forwarding; never extend a lease locally

Ephemeral media and explicit qualifications

Packets are forwarded without first writing a database. SFU failure can lose buffered packets; recording has its own committed-chunk durability and may have a documented gap. To meet the removal deadline, an SFU stops forwarding when it cannot renew its permission lease, even if participants could otherwise keep exchanging media.

The recording assumptions are a technical interview contract, not a claim that one universal recording policy applies everywhere.

04Capacity estimates

Use six participants each sending one 1.5-Mbps video stream, excluding audio, packet overhead and extra quality layers. A mesh makes each sender transmit to five receivers. A selective forwarding unit, SFU, receives streams and forwards selected encoded packets to subscribers without normally composing a new mixed video.

Quantity Calculation Decision
Mesh upload per client 5 × 1.5 = 7.5 Mbps Already difficult for some home/mobile uplinks
Mesh directed stream copies 6 × 5 = 30 Connections and receiver demand grow with room size
SFU ingress per room 6 × 1.5 = 9 Mbps One baseline upload per participant
SFU full all-to-all egress 6 × 5 × 1.5 = 45 Mbps Forwarding saves client duplication, not server fanout
Ten thousand rooms 45 Mbps × 10,000 = 450 Gbps About 202.5 TB/hour of outbound payload
Twenty-five-person full grid 25 × 24 × 1.5 = 900 Mbps/room Select fewer/lower-quality streams rather than blindly forwarding all

A receiver could instead view one 1.5-Mbps active speaker and four 0.15-Mbps thumbnails: 2.1 Mbps instead of 7.5. For six receivers that is 12.6 Mbps/room, a 72% reduction from 45 Mbps under these assumptions. Simulcast means publishing multiple encoded qualities; a publisher sending 1.5+.4+.15 uses 2.05 Mbps before overhead, so ingress is no longer nine Mbps per room. Measure device encoding load too.

TURN is the relay service used when a suitable direct network path is unavailable. A relayed participant sends or receives through that extra hop, so relay capacity must be counted separately from the SFU’s own forwarding work. The baseline below explains how path discovery, checking and relay selection fit together.

At ten thousand rooms, renewing one room-policy lease per second creates ten thousand control renewals/s. Partition this state by room and batch SFU renewals without extending individual deadlines. A hypothetical twenty-percent TURN use adds relay traffic on those participant paths; budget traffic on both the participant-to-relay and relay-to-SFU connections, including any regional transfer charges, rather than only the SFU network interface. Benchmark CPU, packets/s, retransmission buffers, encryption and egress together before choosing rooms per machine.

05APIs and contracts

Room creation and joining

A room epoch is the version of the room-to-SFU assignment. It distinguishes the current assigned media server from a previous one; participant generation separately identifies the current device session.

POST /rooms with a request key creates R8 and host policy. POST /rooms/R8/join derives participant P1's identity from authentication, checks invitation/role and returns J1, participant generation 12, room epoch 4 and assigned SFU A3. A same-attempt retry recovers the recorded session result; an intentional device replacement is a separate action. J1 is scoped to room, tenant, session, roles, SFU/epoch and a short expiry.

Versioned signaling messages

  • Message identity. Signaling messages carry {room:R8,participant:P1,session:S11,generation:12,negotiation:2,seq:17,type:offer,description:...}.
  • Descriptions and candidate paths. Offers/answers describe media capabilities and transport information; candidate messages describe possible paths.
  • Duplicates and stale negotiation. Define duplicate sequence handling and reject incompatible stale negotiation generations.
  • Authorized relay. The signaling service relays these messages in the correct authorized session; it does not treat client-supplied participant names as authority.

Removal and recording commands

POST /rooms/R8/remove {participant:P2,expectedMembershipVersion:40} is host-authorized, commits membership version 41, and notifies the active SFU. A stale expected version returns a conflict for reread rather than overwriting newer policy. POST /rooms/R8/recordings uses an idempotency key and checks recording policy before creating Rec2. Room status returns current epoch/version and visible recording state.

Control transport and admission errors

Exchanging candidate addresses is only setup. ICE is the connectivity procedure that tests candidate network paths and selects a working one; receiving a signaling response does not establish that those tests succeeded.

Use WebSocket signaling for bidirectional low-volume control, with a snapshot-plus-version protocol on reconnect. Large media bytes use negotiated real-time transports. A 429/admission response protects overloaded regions; a signaling 200 does not claim that ICE succeeded or that a remote microphone has permission to capture.

06Data model and access patterns

Durable room, member and recording entities

Persist Room(roomId,tenantId,hostId,policyVersion,currentEpoch,assignedSFU) and Member(roomId,participantId,role,status,generation), partitioned by room for local membership changes. A primary key on room/participant supports authorization. Session-attempt records recover duplicate joins. Recording(recordingId,roomId,state,policyVersion,startedBy,manifestKey,retentionUntil) and an outbox support auditable recording lifecycle updates.

Authority and lease records

A room authority serializes epoch/assignment updates through a replicated store. “Replicated” here requires a specified quorum or synchronous commit policy and safe promotion; arbitrary lagging replicas cannot issue new authority. Store the last issued lease expiry so failover can choose a non-overlapping activation interval if that is the selected policy. Signed lease contents include room, SFU, epoch, membership version, allowed track roles and absolute validity bounds. A stale controller cannot produce a new valid grant by changing its local clock.

Ephemeral media state

Track IDs such as camera-P1 belong to (R8,P1,generation12). Transport addresses, ICE candidates, packet sequence numbers, jitter buffers and per-receiver bandwidth estimates are ephemeral on the SFU/client. Recover them by negotiation, not by synchronously replicating every packet. Durable metadata says who may publish; it does not contain the decoder's current frame.

Recording manifests and collection guards

Recording bytes live in object storage as immutable numbered chunks, with a manifest listing only verified committed chunks. A chunk metadata row tracks its upload grant, recorder generation, retained-manifest references, playback pins and LIVE/DELETING state. A playback pin records that an active reader still needs the chunk, preventing cleanup from deleting it during playback. Check these conditions in the same recording-metadata transaction. Stable chunk identities identify uploader retries; the published manifest lists playable chunks and any gaps. Searchable meeting history is a derived index, and loss of that index must not admit an unauthorized participant to the live room.

Enforce immutable recording bytes

Recording chunk identity includes recording ID, recorder generation, segment number and immutable attempt identity. Enforce create-only bytes or retain the exact object-store VersionId; verify the digest of that version before publishing it in the manifest. A reusable signed upload URL to a mutable key cannot protect previously verified recording bytes. The metadata transaction compares current recorder generation, chunk identity and digest; a retry returns the existing identical entry, while a conflicting payload or stale recorder is rejected. A newer recorder never overwrites the bytes referenced by an older committed segment.

07Basic working design

Two-party connectivity

Start with two browsers, one authentication/signaling server and a durable room table. Participant P1 and participant P2 join authorized sessions, exchange offers/answers and network candidates, and establish a peer-to-peer media connection if the network allows. STUN (Session Traversal Utilities for NAT) helps discover the address visible outside a network address translator, or NAT, and supports connectivity checks. TURN (Traversal Using Relays around NAT) supplies an authenticated relay when a direct path is unsuitable. ICE (Interactive Connectivity Establishment) gathers possible paths, tests them and selects a working one. These protocol services are needed for practical network traversal even before a group media server exists.

Join and media boundaries

Extend to mesh and define removal limits

For a six-person first prototype, extend this into mesh: every browser maintains connections to the other five. It is a valid working topology, and the signaling server still does not carry every video byte. But control-plane removal in a pure peer topology depends on participant cooperation and bounded connection authorization; it does not give a central forwarding cutoff against an uncooperative peer. Therefore this baseline does not yet satisfy our final host-enforced removal contract, as well as the group bandwidth targets.

architecture · baselineA direct call with signaling and network traversal

The application authorizes and arranges the call. Media uses the selected direct or relayed path; the room database is not a video packet store.

A direct call with signaling and network traversalThe application authorizes and arranges the call. Media uses the selected direct or relayed path; the room database is not a video packet store. alice to signal: 1. Join and exchange descriptions; bob to signal: 1. Join and exchange descriptions; signal to db: 2. Commit authorized sessions; alice to stun: 3. Discover candidate address; alice to bob: 4a. Selected direct media; alice to turn: 4b. Relay path if selected; turn to bob: 5. Relayed media alternative1. Join and exchangedescriptions1. Join and exchangedescriptions2. Commit authorized sessions3. Discover candidate address4a. Selected direct media4b. Relay path if selected5. Relayed media alternativeACTORParticipant P1browserACTORParticipant P2browserSERVICEAuth and signalingSTORERoom and session DBSERVICESTUN discoverySERVICEAuthorized TURNrelaysynccontrolmedia
Read each connection in order
  1. sync1. Join and exchange descriptionsParticipant P1 browser → Auth and signaling
  2. sync1. Join and exchange descriptionsParticipant P2 browser → Auth and signaling
  3. sync2. Commit authorized sessionsAuth and signaling → Room and session DB
  4. control3. Discover candidate addressParticipant P1 browser → STUN discovery
  5. media4a. Selected direct mediaParticipant P1 browser → Participant P2 browser
  6. media4b. Relay path if selectedParticipant P1 browser → Authorized TURN relay
  7. media5. Relayed media alternativeAuthorized TURN relay → Participant P2 browser

08Find the baseline flaws

Failure test What breaks and what must follow
Mesh uplink/decoding cost At six participants, each sender's 7.5-Mbps baseline video upload can exceed a mobile uplink. At twenty-five, it becomes 24 × 1.5 = 36 Mbps per client. Dropping resolution can reduce that load but does not change its growth with participant count. Receiver decoding and connection-management overhead also increase. A faster signaling database cannot solve these media costs because it is not on the packet path.
Removal does not stop media A second flaw appears when participant P2 is removed. The room database commits version 41, but a media path that never consults updated permissions can continue sending. A signed join token valid for an hour is still cryptographically authentic for that hour; signature validation alone does not implement three-second revocation. A server-side mute icon is also insufficient if the packet forwarder keeps participant P2's subscription active.
Network switch and stale signaling A third failure occurs on participant P1's Wi-Fi-to-cellular switch. The signaling WebSocket reconnects successfully, but the selected media path still points at the old address. The UI says connected while audio remains absent. Blindly creating another camera-P1 track can leave two generations forwarding when the old path recovers. We need a separate transport-recovery procedure and explicit session/negotiation identities, not just more signaling replicas.

Three problems need different fixes: browsers send too many copies, permission changes may arrive late, and broken network paths need recovery. An SFU reduces repeated uploads; it still needs permission checks and a recovery protocol.

09Improve the design, step by step

1. Put an SFU in the media path

  • Trigger: Mesh upload growth is the trigger.
  • Mechanism: Each participant publishes to one assigned SFU, which forwards selected streams to authorized receivers. This lowers baseline upload from 7.5 to 1.5 Mbps in the six-person example.
  • Benefit, cost and alternative: It adds server egress, fleet capacity, encryption/session state and a new failure point. A multipoint control unit, MCU, instead decodes/mixes/reencodes a composition: it can simplify a weak receiver's workload but costs media CPU, latency and per-layout flexibility. Keep mesh for very small calls when its permission model and uplinks suffice; choose forwarding for this group's requirements.

A keyframe can establish a decodable picture without depending on earlier frames in that stream. When a receiver changes video quality or recovers from missing state, it may need such a frame before subsequent dependent frames are useful. That is why layer switching adds recovery work as well as saving bandwidth.

2. Adapt subscriptions and quality

  • Trigger: Full-grid 900-Mbps server egress for twenty-five people triggers active-speaker selection, thumbnail layers and screen-share priority.
  • Mechanism: Simulcast or scalable encoding lets an SFU choose a suitable layer; receiver feedback guides bitrate and subscription changes.
  • Benefit, cost and alternative: Benefits are lower egress and fewer decoded high-quality streams. Costs are publisher encoding/uplink and switching/keyframe complexity. The new risk is adaptation oscillation or a receiver stuck on an unusable layer, so use measured feedback and bounded change rates. A single lower-quality stream is simpler when device capacity cannot sustain multiple encodings.

3. Add replicated room authority and bounded media permissions

  • Trigger: An hour-long token cannot meet removal, so SFUs require fresh short leases from the current room authority and enforce roles on the actual forwarding path.
  • Mechanism: Versioned membership changes push fast updates; expiry supplies the bound when a push is lost.
  • Benefit, cost and alternative: This provides a concrete revocation guarantee, at the cost of renewal traffic and cutting media when authority isolation exceeds the lease. Longer disconnected-call continuity is the alternative only if the product accepts a weaker removal bound. This is an explicit product tradeoff, not a hidden implementation detail.

4. Place and recover room allocations

  • Trigger: Capacity and geographic delay motivate a regional allocator using measured SFU CPU, packet rate and egress headroom.
  • Mechanism: Pin a room to an assignment/epoch; scale by assigning new rooms rather than moving every healthy live connection. Draining removes a node from new allocations and lets calls finish or reconnect under a planned policy.
  • Benefit, cost and alternative: Costs include spare capacity, directory ownership and imperfect placement across geographically dispersed users. Cascaded regional SFUs may reduce long-haul duplication for larger distributed rooms, but add inter-SFU coordination; keep one regional SFU per room until measurements justify them.

10Detailed architecture

Regional control plane

The global entry point routes authentication and signaling to a regional gateway. Room authority checks identity, policy and current participant generation. A placement directory maps R8 to A3 at epoch 4; health/capacity information guides new assignments but does not itself authorize packet forwarding. The system must commit assignment and membership consistently: either update them in one room transaction, or use a defined coordination protocol that prevents a newly assigned SFU from forwarding with obsolete membership.

Direct and relayed media

Participant P1 connects to A3 directly if ICE finds a suitable path. Participant P2 may reach A3 through TURN. The relay is on participant P2's network path; it is not a replacement for room authorization or an alternative media mixer. STUN assists discovery/checking, while TURN allocates relay resources. ICE gathers candidate pairs, checks connectivity and selects a usable pair. Exchange candidates through authenticated signaling; an address appearing in a candidate does not prove a connection works.

SFU-local ephemeral state

The SFU owns live transports, authorized track/subscription mappings and bounded media buffers. It validates current leases, participant generations and publish/subscribe rights before forwarding. Congestion feedback adjusts per-receiver layers and sender bitrate. Packets do not pass through the durable room database. In the final diagram, control connections refresh permission, while media connections carry the high-volume traffic estimated earlier.

Authorized recording and telemetry

architecture · finalRoom authority controls an independent media plane

Control grants identify epoch, membership and expiry. The SFU forwards packets only while those grants authorize the sender and receiver. Recording is a separately authorized workflow, not an invisible copy of every room. The selected browser/SFU and browser/TURN/SFU transport legs carry media in both directions; arrows highlight the example flow.

Room authority controls an independent media planeControl grants identify epoch, membership and expiry. The SFU forwards packets only while those grants authorize the sender and receiver. Recording is a separately authorized workflow, not an invisible copy of every room. The selected browser/SFU and browser/TURN/SFU transport legs carry media in both directions; arrows highlight the example flow. alice to signal: 1. Join R8 / negotiate; bob to signal: 1. Join R8 / subscribe; signal to authority: 2. Identity and role checks; authority to db: 3. Commit membership / epoch; allocator to authority: 4. Propose capacity assignment; authority to sfu: 5. Current bounded room lease; alice to stun: 6. Discover candidate address; alice to sfu: 7a. Direct protected media; bob to turn: 7b. Selected relayed path; turn to sfu: 8. Participant P2’s media transport; sfu to alice: 9. Selected received tracks; authority to recordapi: 10. Validate recording policy; recordapi to manifest: 11. Commit Rec2 / visible state; recordapi to recorder: 12. Scoped recorder grant; sfu to recorder: 13. Authorized media tracks; recorder to objects: 14. Create immutable chunk attempt; recorder to manifest: 15. Publish verified chunks1. Join R8 / negotiate1. Join R8 / subscribe2. Identity and role checks3. Commit membership / epoch4. Propose capacity assignment5. Current bounded room lease6. Discover candidate address7a. Direct protected media7b. Selected relayed path8. Participant P2’s mediatransport9. Selected received tracks10. Validate recording policy11. Commit Rec2 / visible state12. Scoped recorder grant13. Authorized media tracks14. Create immutable chunkattempt15. Publish verified chunksACTORParticipant P1browserACTORParticipant P2browserSERVICERegional signalinggatewayG1SERVICERoom authorityG1STOREReplicated roomstoreG1SERVICECapacity / roomallocatorG1SERVICESTUN discoveryG2SERVICETURN relay fleetG2SERVICERegional SFU A3G2SERVICERecordingauthorizationG3WORKERAuthorized recorderG3STOREImmutable recordingchunksG3STORERecording manifest /auditG3controlsyncmediaasyncG1 Room control and durable authorityG2 Live transport and forwardingG3 Authorized recording and retention
Read each connection in order
  1. control1. Join R8 / negotiateParticipant P1 browser → Regional signaling gateway
  2. control1. Join R8 / subscribeParticipant P2 browser → Regional signaling gateway
  3. sync2. Identity and role checksRegional signaling gateway → Room authority
  4. sync3. Commit membership / epochRoom authority → Replicated room store
  5. control4. Propose capacity assignmentCapacity / room allocator → Room authority
  6. control5. Current bounded room leaseRoom authority → Regional SFU A3
  7. control6. Discover candidate addressParticipant P1 browser → STUN discovery
  8. media7a. Direct protected mediaParticipant P1 browser → Regional SFU A3
  9. media7b. Selected relayed pathParticipant P2 browser → TURN relay fleet
  10. media8. Participant P2’s media transportTURN relay fleet → Regional SFU A3
  11. media9. Selected received tracksRegional SFU A3 → Participant P1 browser
  12. sync10. Validate recording policyRoom authority → Recording authorization
  13. sync11. Commit Rec2 / visible stateRecording authorization → Recording manifest / audit
  14. control12. Scoped recorder grantRecording authorization → Authorized recorder
  15. media13. Authorized media tracksRegional SFU A3 → Authorized recorder
  16. async14. Create immutable chunk attemptAuthorized recorder → Immutable recording chunks
  17. async15. Publish verified chunksAuthorized recorder → Recording manifest / audit

11Write path and acknowledgement

The room authority saves joins and role changes. Before forwarding a publisher’s media, the SFU checks the current participant generation and the grant’s expiry, including the stated clock-uncertainty allowance.

Numbered join and publication trace

  1. Authorize and commit the participant session. Participant P1 submits join attempt JAttempt9 for R8. The room authority validates tenant, invite and role; transactionally creates/replays S11 generation 12, checks epoch 4 assignment A3 and commits before returning J1. Participant P2 obtains a separate scoped session, not a copy of participant P1's token.
  2. Exchange versioned signaling. Participant P1 negotiates with A3 through signaling. Offers/answers define supported media and transport parameters. Candidate messages carry the current negotiation generation so delayed candidates from a prior attempt cannot corrupt the new one.
  3. Select a verified connectivity path. ICE checks candidate paths. Participant P1 reaches A3 directly; participant P2 obtains an authenticated TURN allocation and selects its working relay path. A connectivity failure is surfaced independently from the successful join transaction.
  4. Authorize the secured media transport. Secure transport setup protects media on each chosen connection. A3 verifies J1 plus current room lease and generation before accepting camera-P1/audio-P1. Store live track ownership as (R8,P1,12,trackId).
  5. Publish under fresh forwarding authority. Participant P1 encodes and sends timestamped media packets. A3 keeps bounded retransmission/selection state and forwards only according to permitted subscriptions and fresh leases. Publishing a track is not a durable recording acknowledgement.
  6. Commit recording state and immutable chunks. If recording is requested, commit Rec2's authorized state and visible policy notice first. The recorder joins with its own permission, obtains a staged upload grant for its generation, uploads immutable chunk Rec2/0001 idempotently, and verifies it. A metadata transaction checks current recording/recorder authority and the LIVE chunk grant, publishes the manifest entry, and transfers upload protection to a retained-manifest reference. A crash leaves either protected staging or a committed entry, not a falsely complete recording.

Retry, replacement and revocation

A lost join response is recovered by JAttempt9 while its attempt record remains retained. A deliberate second-device join advances participant generation; stale control commands for generation 12 cannot remove or replace generation 13. This is an application session rule, separate from ICE credentials used to change one session's network path.

12Read and delivery path

Subscribers receive selected timely tracks under bounded permission leases. Reconnect rejects stale control, and replacement SFUs wait for old forwarding authority to expire.

Numbered subscription and reconnect flow

  1. Reconcile the permitted room snapshot. Participant P2 receives a room snapshot with membership version 40 and track IDs. It contains only tracks permitted for that session under the room policy. Incremental signaling events carry versions; a gap causes snapshot reconciliation rather than guessing which participant left.
  2. Authorize subscriptions. Participant P2 subscribes to participant P1's camera at a supported layer and to audio. A3 checks participant P2's current session, its room lease and both publication/subscription permissions. A client request for an arbitrary track ID cannot bypass those checks.
  3. Forward and decode selected packets. A3 forwards selected encoded packets over participant P2's negotiated transport, directly or through the selected TURN relay. It normally avoids decoding/reencoding every stream. Participant P2 decodes and schedules playout; receiver feedback reports loss, delay and available bandwidth.
  4. Adapt within playout deadlines. When bandwidth drops, lower camera layers or reduce off-screen streams, preserve audio and screen readability, and request keyframes only as needed. A larger queue is not free reliability: it can convert short loss into seconds of stale video. Use bounded retransmission when it can still meet the playout deadline; otherwise drop obsolete frames.
  5. Measure actual call quality. The app reports first received media, audio gaps and freeze duration. A successful subscribe response alone is not an observed good call. Reevaluate layout/quality as visible tiles and network conditions change.
  6. Authorize and pin recording playback. For later recording playback, authorize the recording request separately, atomically select and pin a committed LIVE manifest and its chunk references, then fetch allowed chunks. Release the playback pin when streaming finishes; remove a pin left by an abandoned playback only after the service has prevented that reader from fetching further chunks or confirmed that its reads have finished. A former live-room member does not automatically retain indefinite access to every recording. Expired or deleted recording state rejects new playback even if object cleanup is delayed.

Re-establish a network path

A new network path is established with ICE restart when required, not by replaying old packet addresses. Signaling carries the new credentials/candidates, and the current peer connection transitions under its negotiated protocol. Send media on its negotiated transport, outside the control WebSocket. Do not apply the control messages’ durable retry policy to ordinary media packets.

Simulcast versus scalable coding

Layer and transport choices. Simulcast sends separately encoded versions of the same source, such as the 1.5, 0.4 and 0.15 Mbps streams above. Scalable video coding (SVC) encodes dependent spatial/temporal layers within a scalable stream; the SFU selects a decodable subset, not arbitrary enhancement packets without their dependencies. Codec/profile, browser, device and SFU support determine which option is practical. Test negotiation and layer switching on the supported client matrix rather than assuming every browser supports every codec or scalable mode.

Relay transport and head-of-line blocking

For UDP-blocked clients, an available TURN-over-TCP or TURN-over-TLS connection can reach the relay; the relay-to-SFU leg can still use UDP. TCP delivers bytes in order, so a lost packet can delay later media bytes on that connection until retransmission succeeds; this is head-of-line blocking. A working fallback is therefore not proof of equal call quality. In the normal SFU setup, Datagram Transport Layer Security (DTLS) establishes keys, and Secure Real-time Transport Protocol (SRTP) encrypts and authenticates the Real-time Transport Protocol (RTP) media packets between browser and SFU; a TURN relay forwards that protected traffic and does not thereby become the media decryption endpoint.

13Correctness deep dive

Three independent generations

Use three different versions for three different problems: room epoch identifies the assigned authority/SFU generation; participant generation identifies participant P1's current device session; negotiation generation identifies a transport negotiation within that session. ICE restart alone need not create a new room membership or a second camera identity. This prevents the vague instruction “add a version” from hiding what the version protects.

Authority-issued lease deadline

For policy leases, the authority's replicated transaction checks current SFU/epoch and membership version, then records an absolute deadline no more than two seconds after that authoritative decision. The signed lease reflects that committed grant. Pausing a grant response does not move its expiry forward. An isolated old controller cannot mint renewed grants from local state. SFUs enforce deadlines with conservative clock bounds; loss of the configured bound stops forwarding.

Control and forwarding guards

apply_control(room, epoch, participant, generation, message):
  require room.currentEpoch == epoch
  require member[participant].generation == generation
  require member[participant].status == JOINED
  require message.seq is newer for this control stream
  apply allowed role/state transition atomically
forward_packet(room, track, subscriber):
  require lease.room == room and lease.sfu == this_sfu
  require lease.epoch == installedRoomEpoch
  require lease.membershipVersion >= installedPolicyFloor
  require conservative_now < lease.validUntil
  require track.publisher and track.generation match its authenticated transport
  require subscriber.participant and subscriber.generation match its authenticated transport
  require both generations are authorized by lease membership
  require publisher may publish and subscriber may subscribe
  forward only a selected timely packet

Removal race

Reconnect race

Reconnect race: P1's replacement device commits generation 13. A delayed leave(participant P1,generation12) is rejected and cannot remove generation 13. A3 may accept old generation-12 traffic only under its preexisting bounded lease; the next update/expiry removes it. New track publication must use the current generation. Within generation 13, an ICE restart advances negotiation identity; old candidates are rejected for the new negotiation without inventing another logical participant.

SFU replacement

SFU replacement: The authority records A4 at epoch 5 and stops granting A3 renewals. For a strict single-active-media-owner policy, A4's lease starts only after the last A3 lease's expiry plus the clock reserve. A4 does not use a cached directory entry to skip that wait. Clients then negotiate new transports and republish. The price is a short interruption; merely incrementing a directory epoch could not make a partitioned A3 stop sending. This lease scheme is our application design, not a claim that the WebRTC protocol itself supplies room authorization.

Monotonic policy installation

Within one room epoch, the SFU accepts only newer policy state. A version-41 removal raises its minimum accepted policy version and immediately removes the affected forwarding rules; a delayed, authentic version-40 lease cannot restore P2. At the same policy version, accept only an authorized renewal with a later absolute expiry. Never restart its duration when the reply arrives. A newer room epoch replaces the old assignment, but its not-before time still prevents overlapping owners. Each lease contains the complete allowed membership or identifies an immutable membership snapshot the SFU verifies. A version number alone cannot authorize an unrelated cached member list.

Bind publisher and subscriber transport identity

The packet path binds both publisher and subscriber to the authenticated transport's participant generation. Checking only a track ID and a generic subscribe role would let an old device retain another device's authority. A recorder uses the same membership/lease mechanism, including updates when recording permission or required consent is withdrawn; its chunk-publication authority is checked separately.

sequence · removalA lost removal update cannot renew an old permission

The authority-issued deadline remains fixed. A3 stops when its old lease expires; reconnecting retrieves version 41, which still excludes participant P2.

A lost removal update cannot renew an old permissionThe authority-issued deadline remains fixed. A3 stops when its old lease expires; reconnecting retrieves version 41, which still excludes participant P2. authority to sfu: v40 lease: absolute expiry t2; host to authority: Remove participant P2 at t0 + 0.1; authority to authority: Commit v41: participant P2 removed; authority to host: Removal committed; authority to sfu: v41 update lost in partition; sfu to bob: Old grant valid only until t2; sfu to sfu: Conservative clock reaches expiry; sfu to bob: Stop forwarding; no local renewal; sfu to authority: Reconnect; request current lease; authority to sfu: v41 grant excludes participant P2PARTICIPANTHost participantP1PARTICIPANTRoom authorityPARTICIPANTSFU A3PARTICIPANTParticipant P2transport1. v40 lease: absolute expiryt22. Remove participant P2 att0 + 0.13. Commit v41:participant P2 removed4. Removal committed5. v41 update lost in partition6. Old grant valid only until t27. Conservative clockreaches expiry8. Stop forwarding; no localrenewal9. Reconnect; request currentlease10. v41 grant excludesparticipant P2controlsyncreturnblockedmedia
Read each connection in order
  1. controlv40 lease: absolute expiry t2Room authority → SFU A3
  2. syncRemove participant P2 at t0 + 0.1Host participant P1 → Room authority
  3. syncCommit v41: participant P2 removedRoom authority → Room authority
  4. returnRemoval committedRoom authority → Host participant P1
  5. blockedv41 update lost in partitionRoom authority → SFU A3
  6. mediaOld grant valid only until t2SFU A3 → Participant P2 transport
  7. syncConservative clock reaches expirySFU A3 → SFU A3
  8. blockedStop forwarding; no local renewalSFU A3 → Participant P2 transport
  9. controlReconnect; request current leaseSFU A3 → Room authority
  10. returnv41 grant excludes participant P2Room authority → SFU A3

14Failure and recovery

Failure and recovery table

Failure timeline User result State and recovery
Join commits, response disappears participant P1 retries the same attempt Recover S11 from durable attempt state; negotiate media afterward
participant P1 changes Wi-Fi to cellular Reconnecting/brief audio gap Keep identity; perform ICE restart and current-generation negotiation
Signaling gateway crashes Existing media may continue briefly Reconnect control, fetch versioned snapshot; leases still govern permission
SFU A3 dies Lost frames and a visible interruption Assign A4 safely, wait out old authority if needed, renegotiate/republish
Recording upload succeeds but manifest update fails Recording remains incomplete Retry the same chunk identity and publish verified manifest entry

Authority partition

During a room-authority partition, an existing SFU can use only the remaining signed lease interval. After expiry it stops forwarding even if the media network is healthy. This is the unavoidable operational consequence of our short revocation promise. Do not simultaneously claim minutes of isolated-call continuity with unchanged permissions. If the product chooses that alternative, lengthen and disclose the revocation bound.

Overload and quality policy

At overload, reject new room allocations before exhausting active-call packet buffers. Reserve headroom for loss recovery and short bursts; reduce optional video quality/subscriptions before sacrificing audio. A slow recorder may drop or mark gaps under its contract, but must not backpressure every live subscriber. Expiring TURN allocations, dead sessions and orphan recording chunks have separate cleanup jobs; delayed cleanup never reauthorizes a removed user.

Regional loss

A regional loss sends clients to another region after room authority is safely recovered/promoted. A restored database does not restore live encryption/ICE state. Explain the rejoin interruption and any recording gap rather than calling this transparent packet migration.

Recording publication versus collection

Recording publication and cleanup must use the same metadata transaction checks. A collector may atomically mark a chunk DELETING only after its upload grant is aborted or safely fenced and it has no retained-manifest references or playback pins. A new pin or publication requires LIVE and therefore cannot succeed after that transition. If publication wins first, its reference prevents deletion; if cleanup wins first, publication is rejected and the recorder must recover with a new protected upload. Deleting bytes happens after the durable DELETING claim. Waiting before cleanup may ease operations, but cannot replace these atomic checks. Replacing a recording manifest retains old chunks until existing pinned playbacks finish; recording authorization still governs whether a new playback may start.

15Operations, security, and cost

Media-quality metrics

Observe join success, time to first decoded audio/video, ICE failure, relay fraction, per-network round-trip time/loss/jitter, sender bitrate, freeze duration, audio gaps and reconnect time. On servers, watch packets/s, egress, CPU, buffer age, lease-renewal lag and expired-permission drops. High average bandwidth utilization is not a success when queueing has made conversation unusable. Inspect distributions by region, browser/device and network type.

Signaling, TURN and recording security

Protect signaling and TURN with authenticated scoped credentials, quotas and bounded message sizes. Never let a room token authorize arbitrary relay destinations indefinitely. Validate publish/subscribe ownership at the SFU; a client-side mute setting is merely user intent. Separate host moderation, recording initiation and administrative permissions. Encrypt transport, protect stored recordings and audit access; log identifiers/quality metrics without routinely retaining raw media for debugging.

Egress and relay cost

The egress estimate shows why subscription policy can matter more than a minor database optimization. At ten thousand rooms, changing six-person all-to-all video from 45 to 12.6 Mbps/room changes payload egress from 450 to 126 Gbps under our assumptions. That saves 324 Gbps but changes visual quality/layout and may increase publisher encoding work. Price those bytes and compute against an actual provider quote later; do not invent a universal per-call dollar cost.

Canary, drain and network drills

Canary a new SFU version on new rooms, monitor quality cohorts, then drain old nodes. Keep enough spare capacity to replace a failed node without overloading its neighbors. Test blocked UDP/TURN fallback, a 70% bandwidth drop, browser suspension, clock-bound violation, delayed generation-12 leave and A3 partition during removal. Recording restore tests verify manifest/chunk consistency and access policy, not only object checksums.

16Decision ledger and limitations

Decision table

Decision Benefit Cost / residual limitation Revisit when
SFU instead of mesh Lower client upload fanout and server-enforced subscriptions Server egress and reconnect on media-node failure Small calls can use mesh under a compatible permission contract
Selected layers/visible tiles Less bandwidth and receiver decoding Publisher layer cost and variable visual quality Device/network measurements favor a single encoding or MCU
Short authority leases Bounded removal even when updates are lost Control renewals and call cutoff during authority isolation Product explicitly accepts longer revocation delay
One regional SFU per room Clear live ownership and simple forwarding Distant participants may have high latency Large distributed rooms justify cascaded SFUs
Separate chunked recording Live call avoids recording-storage latency Gaps/orphans need manifest and cleanup logic A stronger recording promise buys buffering/redundancy

When an MCU fits

An MCU is not universally inferior: a low-powered client receiving one composition can benefit, especially when fixed layouts or server recording are central. It costs decoding/reencoding capacity and may add delay. An SFU does not make every participant's network fast; it creates a place to control subscriptions and adapt delivery.

Current encryption trust boundary

The current encryption contract trusts media endpoints including the SFU/authorized recorder. Infrastructure-blind media encryption requires participant-held content keys, membership/key rotation, compatible clients and an explicit recorder key-sharing policy. It is not a flag that preserves every server-side feature unchanged. These remaining decisions belong in the closing, not in a hidden “future work” list that contradicts the requirements.

SFrame and group-key responsibilities

For an infrastructure-blind design, SFrame (RFC 9605) is a concrete content-encryption building block: encrypt encoded frames while leaving the forwarding information needed by the chosen SFU design available. It does not itself define the application's group membership, key distribution or recording consent. Removed members must not receive future epoch keys, and supported clients must negotiate a compatible content-encryption path. Browser API and codec support still require testing; citing a standard does not establish universal client deployment.

17Interview closing

Rehearse the architecture and contract

“I start with authenticated signaling, ICE connectivity and a two-party media path. Mesh becomes expensive: even six users require 7.5 Mbps upload each at the assumed quality. I introduce a regional SFU, then selected layers and subscriptions to reduce client upload and server egress. Signaling and durable room state remain separate from ephemeral media packets.

Defend the critical boundary

“The authority assigns one room epoch and current participant generations. Short leases make the SFU enforce permissions even if a removal update is lost; that costs renewal traffic and a call interruption during a long control partition. ICE restart repairs a changed network path, while SFU failure requires a safely assigned replacement and renegotiation. Recording is an authorized subscriber with chunked storage and a committed manifest.

State the cost and next measurement

“I would next measure audio gaps, join/reconnect tails, TURN fraction and egress under realistic restrictive networks. A room is successful when people can communicate, not merely when its WebSocket is connected.”

Answer the follow-up

Interviewer: “The infrastructure must never decrypt the meeting.” Candidate: “I add participant-controlled content encryption and membership-based key distribution/rotation. SFUs can still forward opaque media where the protocol permits, but ordinary server mixing/recording can no longer assume plaintext access. The recorder must be an explicitly trusted participant with appropriate keys, or recording moves to consenting clients. I would revisit moderation and recording requirements before claiming the same feature set.”

Practise the interview questions

Say your answer aloud before opening the model answer. Then answer the follow-up and compare the reasoning.

Foundation · Question 1

A client is connected to signaling but receives no video. Which boundaries would you investigate?

Reveal a model answer

Signaling arranges membership and exchanges session/candidate information; media uses separate negotiated paths and security state. ICE or media negotiation may fail even while the WebSocket is healthy. I would inspect candidate-pair state and media statistics rather than treat the signaling connection as proof of a working call.

What the answer must demonstrate: Control connectivity and media connectivity are separate.

Foundation · Question 2

Does a STUN server relay media packets?

Reveal a model answer

No. STUN helps discover and test reachable addressing. TURN provides an actual relay allocation when the selected connection needs one. ICE combines candidate discovery and connectivity checks to choose the usable pair; a discovered address is not by itself a completed path.

What the answer must demonstrate: Define discovery, checking, and relay distinctly.

Applied · Question 3

For six 1.5-Mbps publishers, why does SFU egress still reach 45 Mbps?

Reveal a model answer

Each of six participants receives the other five streams, so there are thirty forwarded stream copies at 1.5 Mbps. The SFU saves each sender from uploading five copies, but it still must deliver the chosen copies to receivers. Reducing subscriptions/quality changes that egress.

What the answer must demonstrate: Do not confuse client-uplink savings with free server fanout.

Applied · Question 4

Why choose an SFU rather than an MCU for this meeting?

Reveal a model answer

An SFU forwards encoded streams so each viewer can select layouts/qualities without the server decoding and composing every frame. An MCU can send a simpler mixed composition but pays mixing/reencoding CPU and latency. I choose according to client capacity, layout, recording, and network requirements.

What the answer must demonstrate: Tie topology to resource and product requirements.

Follow-up · Question 5

A participant switches from Wi-Fi to cellular. Which state survives, and which transport state must be rebuilt?

Reveal a model answer

The authorized room/participant identity survives, while old network candidates may stop working. I initiate ICE restart with new negotiation credentials/candidates under the current participant generation. A transport restart does not itself require another logical participant P1 track. An intentional new-device session advances participant generation so delayed control messages from the old device cannot overwrite it.

What the answer must demonstrate: Rebuild network reachability while preserving participant identity.

Follow-up · Question 6

Can you promise an SFU never sees plaintext and also record every call server-side?

Reveal a model answer

Not with ordinary hop-by-hop media termination alone. Infrastructure-blind end-to-end encryption requires participant-held keys or another explicit scheme, and recording needs authorized key/media access or participant cooperation. I would make that architecture and consent tradeoff visible rather than claim both automatically.

What the answer must demonstrate: State encryption endpoints and recording authority accurately.

Applied · Question 7

The database removed participant P2, but its notification to A3 was lost. Why does forwarding stop?

Reveal a model answer

A3 can use only an authority-issued lease with an absolute expiry. Our example grants at most two seconds plus a conservative timing reserve inside the three-second removal promise. A3 cannot reset expiry when packets arrive or sign a fresh grant from local state; on expiry or excessive clock uncertainty it stops forwarding. Installed policy versions also advance monotonically, so an authentic but delayed pre-removal lease cannot re-enable a removed participant.

What the answer must demonstrate: Show the actual enforcement point and the availability cost.

Follow-up · Question 8

A3 is partitioned rather than dead. Does changing the directory to A4 fence its media?

Reveal a model answer

Changing the directory cannot stop A3. Stop renewing epoch 4 and make A3 reject packets after its fixed lease deadline. To permit only one media owner, A4 must wait until the last A3 grant expires, including the clock-uncertainty reserve. Clients then establish the epoch-5 transport. That wait is the availability cost of preventing overlap.

What the answer must demonstrate: Separate directory ownership, participant identity and transport negotiation.

Blank-page exercise · 45 minutes

Build the answer yourself

Connect participant P1 and participant P2 in a six-person room. Put participant P2 behind a restrictive network, calculate SFU bandwidth, switch participant P1 to cellular, fail the SFU, and request recording.

  • State functional actions, media latency targets, revocation boundary and exclusions.
  • Calculate six- and twenty-five-person mesh/SFU costs and selected-layer savings.
  • Draw the baseline, identify its bandwidth and permission flaws, and estimate the bandwidth, server and renewal costs of each change.
  • Trace join commit, ICE selection, publication, subscription and recording manifest.
  • Prove removal with a lost update and reject an old-generation leave.
  • Explain SFU replacement interruption, encryption endpoints and the closing tradeoff.

Check that each component and design decision follows from your requirements and workload.

Recall the key ideas

Answer from memory before opening each card. Explain why the choice works and what it costs. Revisit missed cards tomorrow.

Design a live video-conferencing serviceDoes signaling carry the video?Recall first, then reveal

Usually it carries room membership and session descriptions/candidates; media uses separately negotiated transports.

Arrange the call, then carry the media.

Return to lesson
Design a live video-conferencing serviceWhat is the difference between STUN and TURN?Recall first, then reveal

STUN helps discover reachable addressing/connectivity; TURN supplies a relay when a suitable direct path is unavailable.

Discover with STUN; relay with TURN.

Return to lesson
Design a live video-conferencing serviceWhat does an SFU do?Recall first, then reveal

An SFU forwards selected encoded streams or quality layers to participants. It normally does not decode and mix them into one new video.

Select and forward; do not assume mix.

Return to lesson

Final revision

Summary and interview notes

Store room permissions durably; send live media through regional SFUs and handle recording separately. SFUs reduce repeated browser uploads, and selected quality layers control bandwidth. Short authority leases make an SFU stop forwarding when permission updates can no longer be confirmed.

Remember these points

  • Signaling success does not prove ICE connectivity, negotiated media or audible/decoded playback.
  • An SFU saves client duplicate uploads but still pays selected-stream egress and packet-processing cost.
  • Room epoch identifies the assigned SFU; participant generation identifies the current device session; negotiation generation rejects stale messages from an earlier transport setup.
  • Policy versions install monotonically; fixed-expiry leases stop removed membership even during a lost update.
  • Recording manifests retain verified immutable chunk versions. Publishing a reference and garbage collection (GC) both check the same metadata so cleanup cannot delete a chunk a committed recording still needs.

Interview tips

  • Calculate mesh upload, SFU ingress/egress and layered publisher overhead separately.
  • Walk removal with a lost notification, then a delayed old lease arriving after the new policy.
  • Explain exactly where encryption terminates and how an authorized recorder obtains content access.

Important qualifications

  • The three-second removal promise depends on the explicit clock/lease assumptions and sacrifices long control-partition continuity.
  • TURN can relay encrypted media without being the media encryption endpoint; TCP fallback can still increase latency.
  • SFrame supplies content encryption, not automatic group-key management or universal browser/codec support.

Technical references

  • RFC 8825: WebRTC protocol overviewPrimary overview separating signaling, real-time transports, media, and security responsibilities.
  • RFC 8445: ICEDefines candidate gathering/checking, selected connectivity, and ICE restart.
  • RFC 8656: TURNDefines relay allocation and its role when direct connectivity is unsuitable.
  • RFC 7667: RTP topologiesPrimary taxonomy for media topologies, including selective forwarding and mixing; our placement/lease scheme is an application design.
  • W3C WebRTC RecommendationBrowser peer-connection, negotiation and media API behavior; room identity and authorization remain application responsibilities.
  • RFC 8853: SimulcastSimulcast negotiation and independent encoded alternatives; support must be tested.
  • RFC 9605: SFrameContent encryption for real-time media, distinct from application group-key management.

Practice marks stay in this browser.