Skip to content
Navigation
Dashboard
← All system design problems
Hard · Streaming & Video · About 75 minutes

Design Netflix, Hotstar / Amazon Prime Video - OTT Streaming Platform

Understand the requirements. Trace the requests. Explain the trade-offs.

CANDIDATE-LED INTERVIEW WALKTHROUGH

Design Hotstar or Amazon Prime Video: choose live, VOD, or both

A candidate-led walkthrough with distinct on-demand and live-sports paths. Shared authorization does not make ingest, latency and recovery identical. This is an illustrative architecture, not an internal company diagram.

Interviewer replies, workloads and targets are illustrative assumptions to agree on in an interview. Use this as a study resource: establish scope, draw a complete baseline, then choose the most consequential deep dives with your interviewer.

1. Ask what the streaming prompt actually means

Candidate explains

Before drawing, I ask: on-demand movies, live sports, or both? Either Hotstar or Prime Video can represent either workload. The agreed scope, not the brand name, decides the architecture.

For VOD I emphasize asset processing, sessions and global delivery. For live sports I emphasize burst admission, fresh segments, redundant ingest and glass-to-glass delay.

Candidate asksIllustrative interviewer replyDesign consequence
VOD, live sports, or both?Both; deep dive into a major live match.Separate offline asset preparation and realtime pipeline.
Core user journeys?Browse/search titles, play, seek where supported and resume.Defer recommendations, ads auctions and offline downloads.
Which devices and qualities?Web/mobile/TV; adaptive 240p–1080p.Rendition ladder, compatible codecs and tested players.
Concurrent viewers and arrival pattern?Assume 1M steady and 5M event peak.Size bandwidth separately from start/authorization bursts.
Acceptable live delay?Target under 10 seconds capture-to-display.Budget encoding, packaging, network and player buffer together.
Paid rights, geography and screen limits?Yes; two concurrent sessions/account.Entitlement, DRM integration and atomic lease admission.
Frame-perfect sync across viewers?Not required.Do not promise resilient large buffers and zero delay simultaneously.

2. Separate playback experience from durability

Candidate explains

I will support catalog lookup, authorized adaptive playback, VOD seek/resume and a bounded live DVR window. Video bytes bypass the catalog API. A subscription/geography check cannot be replaced with possession of an object URL.

A manifest must reference ready segments with the correct asset/key version. Sessions have explicit expiry/renewal behavior. Billing itself and rights acquisition are external to this scope.

RequirementIllustrative target or rule
Startupp95 under 2 seconds for declared network/device cohorts; measure auth, license, manifest and buffer phases separately.
Live delayp95 under 10 seconds capture-to-display in target regions; trade against rebuffering.
RebufferingBelow 1% of watched time in declared cohorts; measured through player telemetry.
Availability99.99% playback-start API target; isolate catalog/ranking outages from valid existing playback.
Rights/session limitsRevalidate startup and renewal; two unexpired leases/account; bounded existing-grant revocation window.
DurabilityRetain versioned VOD source/outputs and test restores; loss before redundant live ingest may be unrecoverable.
ExcludedBilling implementation, ads auction, offline DRM downloads, full recommender training and exact viewer synchronization.

3. Size bytes and the event-start spike separately

Candidate explains

Assume 4 Mb/s average delivered bitrate, not the top ladder bitrate. One million concurrent viewers is a bandwidth problem even if session creation is only thousands of requests per second.

Assume five million starts over ten minutes. This average hides sharper spikes, so I would load-test burst envelopes, license capacity and admission behavior.

CalculationResultConsequence
1M viewers × 4 Mb/s4 Tb/s edge deliveryApplication servers cannot proxy this byte path.
5M viewers × 4 Mb/s20 Tb/s peak edge deliveryPre-plan regional CDN capacity and exercise steering.
1M × 4 Mb/s × 3,600 ÷ 81.8 PB for one hourGeography, watch time and actual bitrate drive cost.
5M starts ÷ 600 seconds8,333 admissions/s average during entry windowAuth, entitlements, leases and DRM must scale together.
1M viewers ÷ 4-second video segments250,000 edge video requests/sAudio/manifests/chunks add work; shield origins.
2-hour asset × 12 Mb/s combined rendition ladder ÷ 810.8 GB encoded outputSource, audio/captions, alternate codecs and replicas extra.

4. Explain asset versions, rights and session leases

Candidate explains

A title differs from its immutable encoded asset version. Catalog metadata describes it, a manifest identifies playable outputs, and entitlements determine who can watch in which market/time window.

For screen limits I use authoritative per-account lease admission. A cached increment is unsafe under concurrent starts and leaks when clients disappear. Explicit release helps but expiry is required.

EntityAccess patternInvariant
Title(titleId,metadata,type,availability)Catalog/search by marketSearch index does not grant rights; playback rechecks.
AssetVersion(assetId,version,state,manifest,keyId)Current playable versionPublish only complete validated outputs.
LiveEvent(eventId,inputEpoch,regions,DVRWindow)Current manifests and healthSequence belongs to a known input epoch and available segments.
Entitlement(accountId,market,package,validUntil)Startup/renewal decisionBounded cached grants cannot extend rights indefinitely.
PlaybackSession(sessionId,accountId,device,asset,expiresAt)Atomic account admission; session renewalAt most configured unexpired leases at commit.
WatchProgress(profileId,asset,position,eventVersion)Resume lookupDelayed updates cannot blindly overwrite newer progress.

5. Keep metadata APIs separate from media delivery

Candidate explains

The player receives a scoped grant and manifest after authorization. The CDN validates supported authorization without routing every segment through my API. The DRM license exchange is a separate protected operation; signed URLs alone are not a DRM system.

InterfaceRequest → resultFailure / retry rule
GET /v1/catalog?query=…&cursor=…Market-filtered titles and next cursorCache can degrade; no playback authorization implied.
POST /v1/playback-sessionstitleId,profile,device capabilities,operation key → session,manifest,grant expiry,license endpoint403 rights, 409 screen limit, 429 overload; idempotent admission.
PUT /v1/playback-sessions/{id}/heartbeatOwn authenticated renewal → expiryDeny expired/revoked entitlement; jitter renewal.
DELETE /v1/playback-sessions/{id}Release own leaseRepeat-safe; crash cleanup relies on expiry.
PUT /v1/profiles/{id}/progress/{asset}Versioned session event and position → saved resultExplicit cross-session policy; reject stale events.
GET manifests and immutable segmentsHLS/DASH plus authorized media requestsLive manifests short freshness; immutable versioned segments long cache lifetime.

6. Explain on-demand preparation and playback

Candidate explains

For Prime Video as an on-demand prompt, I begin with this path. Upload an original, validate/transcode/package it asynchronously, and publish a playable version only when required outputs exist. The viewer fetches through a CDN.

A catalog/playback application, transactional metadata and queue-driven workers are a sufficient baseline. Separate services later according to scaling and ownership boundaries.

  1. Ingest

    Save immutable original with checksum, ownership and job ID. Successful transfer alone does not make it playable.

  2. Process

    Generate a bounded rendition ladder with aligned switching boundaries, audio/captions and supported formats. Validate output integrity.

  3. Publish

    Commit a pointer to the complete manifest/version. Retries cannot mutate segments already being watched; incomplete attempts stay unpublished.

  4. Authorize

    Check identity, market, rights, device compatibility and session slot. Return a bounded grant and compatible manifest.

  5. Adapt

    Player chooses segments using throughput and buffer health. Measure startup, stalls and quality, not only successful API responses.

7. Add the live-sports pipeline explicitly

Candidate explains

For a Hotstar match or Prime Video live sports, there is no completed movie to process before viewing. I need a continuously advancing stream with redundant input, encoding and packaging. Healthy HTTP endpoints do not prove the broadcast is advancing.

Smaller chunks can reduce latency but increase overhead and sensitivity to jitter. I budget capture/encode, packaging, network and player buffering rather than promising zero delay and perfect resilience.

  1. Redundant feeds

    Use independent failure domains where justified. Detect missing frames, slate and stale sequences, not only transport availability.

  2. Aligned encoding

    Keep compatible rendition/keyframe boundaries, segment naming and encryption configuration across failover paths. Version the input epoch on restart.

  3. Fresh manifests

    Reference only available segments; choose freshness compatible with the latency budget. Immutable segment URLs can remain highly cacheable.

  4. Protect origins

    Use shields/coalescing for popular new-segment misses. A million viewers should not produce a million origin fetches.

  5. Fail over deliberately

    Use segment age, missing sequence and player errors. A backup must be media-compatible; test player discontinuity and license/key behavior.

  6. DVR recovery

    Retain a bounded segment window. A viewer paused beyond retention needs explicit window bounds and a jump-to-live option.

8. Trace startup and screen-limit races

Candidate explains

Two devices may reach different API instances, but simultaneous admission must serialize through authoritative account lease state. A lost startup response replays the same operation instead of consuming another slot.

Once granted, media stays on the delivery path. Existing unexpired sessions can survive a catalog outage according to policy, but grant expiry and rights revocation still bound access.

  1. Validate rights

    Check authenticated profile, market, title window, subscription and device. A caller-provided country string is not sufficient geography enforcement.

  2. Admit atomically

    Expire stale leases using authoritative time, test remaining slots and record the operation result in one account transaction.

  3. Acquire playback material

    Return manifest/grant and complete the DRM exchange. Attribute startup stalls to auth, license, manifest or initial media separately.

  4. Renew/end

    Jitter heartbeats; renew only the caller’s lease. Expiry handles crashes. Explicit stop is an optimization.

  5. Explain limit errors

    Return a clear screen-limit response and, if scoped, an authorized session-management option. Do not silently evict an unrelated viewer.

9. Explain burst handling and experience trade-offs

Candidate explains

At match start, authentication, lease creation, DRM and manifests spike before stable watching begins. Pre-scale and rehearse those dependencies together. Reserve capacity for existing viewers and use bounded retry-after with jitter.

Recommendations, thumbnails or analytics sampling can degrade. Entitlements cannot simply be bypassed and manifests cannot reference missing content.

PressureApproachTrade-off
Startup burstPre-scale and bounded admissionSome new viewers wait; protect existing playback.
Cold segment stampedeShield, coalesce and stable cache keysShield failure needs controlled fallback, not origin flooding.
Low latencyTune segment/chunk duration and buffer by device cohortSmaller buffers can stall more on variable networks.
CDN degradationSteer new sessions and recover players using healthDNS alone cannot instantly move ongoing playback.
DRM/rights outageRedundant paths and bounded grantsLonger cached rights increase revocation delay.
Watch progressCoalesce events and reject stale versionsExact last-frame accuracy may trade against write volume.

10. Rehearse player-visible recovery

Candidate explains

I would disconnect an encoder, serve a stale manifest, remove a segment, slow licensing and drop a region. Success means a known player outcome within a declared recovery budget, not an HTTP 200.

Track startup percentiles, rebuffer/watch-time ratio, fatal errors, live-edge lag, segment freshness, origin offload and license success by device, region, rendition and CDN.

FailureRecoveryAssertion
Encoder stops while endpoint stays upDetect stale sequence/age and switch compatible pathNo endless old-content loop; recovery within budget.
CDN region degradesSteer affected cohorts and bounded alternate retriesPlayer metrics recover without overwhelming origins.
Manifest points to absent segmentReject publication or recover safe rendition/pathNo permanent 404 loop; alert on integrity.
Two starts compete for one slotAtomic per-account admissionExactly one new lease; replay creates none extra.
Rights/DRM timeoutBounded retry and only still-valid grantsNo unauthorized new session; retryability explained.
VOD job dies mid-transcodeRetry versioned attempt; publish complete outputs onlyExisting versions remain playable.
Pause exceeds DVR retentionReturn window bounds and jump-to-live recoveryNo repeated requests for expired media.

11. Tailor the close to the actual prompt

Candidate explains

For “Prime Video movies,” my core story is immutable VOD preparation, authorized sessions, adaptive delivery and resume. For “Hotstar during a major match,” I spend the remaining time on ingest redundancy, freshness, bursts and player recovery. Either product may need both; I clarify rather than infer.

Senior depth connects control and byte paths, bandwidth, leases and user-visible failures. Staff depth adds regional budgets, device/codec rollouts, rights dependencies, CDN economics and scheduled-event rehearsals.

Technical references

Primary references explain underlying mechanisms. Workloads and architecture choices above remain proposed interview assumptions.