Design Hotstar or Amazon Prime Video: choose live, VOD, or both
A candidate-led walkthrough with distinct on-demand and live-sports paths. Shared authorization does not make ingest, latency and recovery identical. This is an illustrative architecture, not an internal company diagram.
1. Ask what the streaming prompt actually means
Before drawing, I ask: on-demand movies, live sports, or both? Either Hotstar or Prime Video can represent either workload. The agreed scope, not the brand name, decides the architecture.
For VOD I emphasize asset processing, sessions and global delivery. For live sports I emphasize burst admission, fresh segments, redundant ingest and glass-to-glass delay.
| Candidate asks | Illustrative interviewer reply | Design consequence |
|---|---|---|
| VOD, live sports, or both? | Both; deep dive into a major live match. | Separate offline asset preparation and realtime pipeline. |
| Core user journeys? | Browse/search titles, play, seek where supported and resume. | Defer recommendations, ads auctions and offline downloads. |
| Which devices and qualities? | Web/mobile/TV; adaptive 240p–1080p. | Rendition ladder, compatible codecs and tested players. |
| Concurrent viewers and arrival pattern? | Assume 1M steady and 5M event peak. | Size bandwidth separately from start/authorization bursts. |
| Acceptable live delay? | Target under 10 seconds capture-to-display. | Budget encoding, packaging, network and player buffer together. |
| Paid rights, geography and screen limits? | Yes; two concurrent sessions/account. | Entitlement, DRM integration and atomic lease admission. |
| Frame-perfect sync across viewers? | Not required. | Do not promise resilient large buffers and zero delay simultaneously. |
2. Separate playback experience from durability
I will support catalog lookup, authorized adaptive playback, VOD seek/resume and a bounded live DVR window. Video bytes bypass the catalog API. A subscription/geography check cannot be replaced with possession of an object URL.
A manifest must reference ready segments with the correct asset/key version. Sessions have explicit expiry/renewal behavior. Billing itself and rights acquisition are external to this scope.
| Requirement | Illustrative target or rule |
|---|---|
| Startup | p95 under 2 seconds for declared network/device cohorts; measure auth, license, manifest and buffer phases separately. |
| Live delay | p95 under 10 seconds capture-to-display in target regions; trade against rebuffering. |
| Rebuffering | Below 1% of watched time in declared cohorts; measured through player telemetry. |
| Availability | 99.99% playback-start API target; isolate catalog/ranking outages from valid existing playback. |
| Rights/session limits | Revalidate startup and renewal; two unexpired leases/account; bounded existing-grant revocation window. |
| Durability | Retain versioned VOD source/outputs and test restores; loss before redundant live ingest may be unrecoverable. |
| Excluded | Billing implementation, ads auction, offline DRM downloads, full recommender training and exact viewer synchronization. |
3. Size bytes and the event-start spike separately
Assume 4 Mb/s average delivered bitrate, not the top ladder bitrate. One million concurrent viewers is a bandwidth problem even if session creation is only thousands of requests per second.
Assume five million starts over ten minutes. This average hides sharper spikes, so I would load-test burst envelopes, license capacity and admission behavior.
| Calculation | Result | Consequence |
|---|---|---|
| 1M viewers × 4 Mb/s | 4 Tb/s edge delivery | Application servers cannot proxy this byte path. |
| 5M viewers × 4 Mb/s | 20 Tb/s peak edge delivery | Pre-plan regional CDN capacity and exercise steering. |
| 1M × 4 Mb/s × 3,600 ÷ 8 | 1.8 PB for one hour | Geography, watch time and actual bitrate drive cost. |
| 5M starts ÷ 600 seconds | 8,333 admissions/s average during entry window | Auth, entitlements, leases and DRM must scale together. |
| 1M viewers ÷ 4-second video segments | 250,000 edge video requests/s | Audio/manifests/chunks add work; shield origins. |
| 2-hour asset × 12 Mb/s combined rendition ladder ÷ 8 | 10.8 GB encoded output | Source, audio/captions, alternate codecs and replicas extra. |
4. Explain asset versions, rights and session leases
A title differs from its immutable encoded asset version. Catalog metadata describes it, a manifest identifies playable outputs, and entitlements determine who can watch in which market/time window.
For screen limits I use authoritative per-account lease admission. A cached increment is unsafe under concurrent starts and leaks when clients disappear. Explicit release helps but expiry is required.
| Entity | Access pattern | Invariant |
|---|---|---|
| Title(titleId,metadata,type,availability) | Catalog/search by market | Search index does not grant rights; playback rechecks. |
| AssetVersion(assetId,version,state,manifest,keyId) | Current playable version | Publish only complete validated outputs. |
| LiveEvent(eventId,inputEpoch,regions,DVRWindow) | Current manifests and health | Sequence belongs to a known input epoch and available segments. |
| Entitlement(accountId,market,package,validUntil) | Startup/renewal decision | Bounded cached grants cannot extend rights indefinitely. |
| PlaybackSession(sessionId,accountId,device,asset,expiresAt) | Atomic account admission; session renewal | At most configured unexpired leases at commit. |
| WatchProgress(profileId,asset,position,eventVersion) | Resume lookup | Delayed updates cannot blindly overwrite newer progress. |
5. Keep metadata APIs separate from media delivery
The player receives a scoped grant and manifest after authorization. The CDN validates supported authorization without routing every segment through my API. The DRM license exchange is a separate protected operation; signed URLs alone are not a DRM system.
| Interface | Request → result | Failure / retry rule |
|---|---|---|
| GET /v1/catalog?query=…&cursor=… | Market-filtered titles and next cursor | Cache can degrade; no playback authorization implied. |
| POST /v1/playback-sessions | titleId,profile,device capabilities,operation key → session,manifest,grant expiry,license endpoint | 403 rights, 409 screen limit, 429 overload; idempotent admission. |
| PUT /v1/playback-sessions/{id}/heartbeat | Own authenticated renewal → expiry | Deny expired/revoked entitlement; jitter renewal. |
| DELETE /v1/playback-sessions/{id} | Release own lease | Repeat-safe; crash cleanup relies on expiry. |
| PUT /v1/profiles/{id}/progress/{asset} | Versioned session event and position → saved result | Explicit cross-session policy; reject stale events. |
| GET manifests and immutable segments | HLS/DASH plus authorized media requests | Live manifests short freshness; immutable versioned segments long cache lifetime. |
6. Explain on-demand preparation and playback
For Prime Video as an on-demand prompt, I begin with this path. Upload an original, validate/transcode/package it asynchronously, and publish a playable version only when required outputs exist. The viewer fetches through a CDN.
A catalog/playback application, transactional metadata and queue-driven workers are a sufficient baseline. Separate services later according to scaling and ownership boundaries.
Ingest
Save immutable original with checksum, ownership and job ID. Successful transfer alone does not make it playable.
Process
Generate a bounded rendition ladder with aligned switching boundaries, audio/captions and supported formats. Validate output integrity.
Publish
Commit a pointer to the complete manifest/version. Retries cannot mutate segments already being watched; incomplete attempts stay unpublished.
Authorize
Check identity, market, rights, device compatibility and session slot. Return a bounded grant and compatible manifest.
Adapt
Player chooses segments using throughput and buffer health. Measure startup, stalls and quality, not only successful API responses.
7. Add the live-sports pipeline explicitly
For a Hotstar match or Prime Video live sports, there is no completed movie to process before viewing. I need a continuously advancing stream with redundant input, encoding and packaging. Healthy HTTP endpoints do not prove the broadcast is advancing.
Smaller chunks can reduce latency but increase overhead and sensitivity to jitter. I budget capture/encode, packaging, network and player buffering rather than promising zero delay and perfect resilience.
Redundant feeds
Use independent failure domains where justified. Detect missing frames, slate and stale sequences, not only transport availability.
Aligned encoding
Keep compatible rendition/keyframe boundaries, segment naming and encryption configuration across failover paths. Version the input epoch on restart.
Fresh manifests
Reference only available segments; choose freshness compatible with the latency budget. Immutable segment URLs can remain highly cacheable.
Protect origins
Use shields/coalescing for popular new-segment misses. A million viewers should not produce a million origin fetches.
Fail over deliberately
Use segment age, missing sequence and player errors. A backup must be media-compatible; test player discontinuity and license/key behavior.
DVR recovery
Retain a bounded segment window. A viewer paused beyond retention needs explicit window bounds and a jump-to-live option.
8. Trace startup and screen-limit races
Two devices may reach different API instances, but simultaneous admission must serialize through authoritative account lease state. A lost startup response replays the same operation instead of consuming another slot.
Once granted, media stays on the delivery path. Existing unexpired sessions can survive a catalog outage according to policy, but grant expiry and rights revocation still bound access.
Validate rights
Check authenticated profile, market, title window, subscription and device. A caller-provided country string is not sufficient geography enforcement.
Admit atomically
Expire stale leases using authoritative time, test remaining slots and record the operation result in one account transaction.
Acquire playback material
Return manifest/grant and complete the DRM exchange. Attribute startup stalls to auth, license, manifest or initial media separately.
Renew/end
Jitter heartbeats; renew only the caller’s lease. Expiry handles crashes. Explicit stop is an optimization.
Explain limit errors
Return a clear screen-limit response and, if scoped, an authorized session-management option. Do not silently evict an unrelated viewer.
9. Explain burst handling and experience trade-offs
At match start, authentication, lease creation, DRM and manifests spike before stable watching begins. Pre-scale and rehearse those dependencies together. Reserve capacity for existing viewers and use bounded retry-after with jitter.
Recommendations, thumbnails or analytics sampling can degrade. Entitlements cannot simply be bypassed and manifests cannot reference missing content.
| Pressure | Approach | Trade-off |
|---|---|---|
| Startup burst | Pre-scale and bounded admission | Some new viewers wait; protect existing playback. |
| Cold segment stampede | Shield, coalesce and stable cache keys | Shield failure needs controlled fallback, not origin flooding. |
| Low latency | Tune segment/chunk duration and buffer by device cohort | Smaller buffers can stall more on variable networks. |
| CDN degradation | Steer new sessions and recover players using health | DNS alone cannot instantly move ongoing playback. |
| DRM/rights outage | Redundant paths and bounded grants | Longer cached rights increase revocation delay. |
| Watch progress | Coalesce events and reject stale versions | Exact last-frame accuracy may trade against write volume. |
10. Rehearse player-visible recovery
I would disconnect an encoder, serve a stale manifest, remove a segment, slow licensing and drop a region. Success means a known player outcome within a declared recovery budget, not an HTTP 200.
Track startup percentiles, rebuffer/watch-time ratio, fatal errors, live-edge lag, segment freshness, origin offload and license success by device, region, rendition and CDN.
| Failure | Recovery | Assertion |
|---|---|---|
| Encoder stops while endpoint stays up | Detect stale sequence/age and switch compatible path | No endless old-content loop; recovery within budget. |
| CDN region degrades | Steer affected cohorts and bounded alternate retries | Player metrics recover without overwhelming origins. |
| Manifest points to absent segment | Reject publication or recover safe rendition/path | No permanent 404 loop; alert on integrity. |
| Two starts compete for one slot | Atomic per-account admission | Exactly one new lease; replay creates none extra. |
| Rights/DRM timeout | Bounded retry and only still-valid grants | No unauthorized new session; retryability explained. |
| VOD job dies mid-transcode | Retry versioned attempt; publish complete outputs only | Existing versions remain playable. |
| Pause exceeds DVR retention | Return window bounds and jump-to-live recovery | No repeated requests for expired media. |
11. Tailor the close to the actual prompt
For “Prime Video movies,” my core story is immutable VOD preparation, authorized sessions, adaptive delivery and resume. For “Hotstar during a major match,” I spend the remaining time on ingest redundancy, freshness, bursts and player recovery. Either product may need both; I clarify rather than infer.
Senior depth connects control and byte paths, bandwidth, leases and user-visible failures. Staff depth adds regional budgets, device/codec rollouts, rights dependencies, CDN economics and scheduled-event rehearsals.
Technical references
Primary references explain underlying mechanisms. Workloads and architecture choices above remain proposed interview assumptions.