قيد الاختبار حاليًا: سيتم فتح كود GitHub عند الاكتمال.

الإعداد (متغيرات البيئة)

تأتي configuration من environment variables فقط. الأسماء case-insensitive والقيمة الفارغة unset، ولا يعني true إلا 1/true/yes/on. يوقف أي range/combination غير صالح startup. لا تستخدم scratch image قرصًا محليًا أو PV.

الإعدادات العامة وحدود الموارد

VariableDefaultAllowedPurpose
SERVER_PORT5225valid u16 portsingle client port; cluster advertises CLUSTER_SELF
SOCKET_BIND0.0.0.0bindable addressclient and Raft bind host
DEBUG_MODEbuild settingflagdebug logging
DOCKER_MODEfalseflagofficial image binds internal 5225/6225
MAX_CONNECTIONS10241..8192concurrent client connections
MAX_RAFT_CONNECTIONS641..256separate Raft/control reserve
MAX_WAITERS20481..16384waiters per key; excess acquire gets B
MAX_TOTAL_WAITERS16384MAX_WAITERS..65536total waiters; excess acquire gets B
Hard capValueSaturation behavior
in-flight acquire per connection64B for that acquire
global in-flight acquire4096B for that acquire
global in-flight release512 separate lanebounded wait until connection close
queued replies per connection256close slow client
coordinator channel4096backpressure
cluster active keys65536B for new-key acquire
Raft frame64MiBreject RPC
encoded snapshot64MiB - 64KiBreject build/install
concurrent Raft decode budget72MiBbounded permit wait/timeout

يستهدف default profile حد memory مقداره 512MiB. لا يمكن تجاوز hard ceilings ولا توجد قيمة unlimited.

مصادقة client وTLS

VariableDefaultPurpose
CLIENT_TOKENSone empty tokencomma-separated client credentials; production should use nonblank secrets
TLS_CERT / TLS_KEYunsetserver certificate chain/private key; set together
TLS_CAsystem rootsCA for peer certificate verification
TLS_SKIP_VERIFYfalsetest only
CLUSTER_ALLOW_PLAINTEXT_PRIVATEfalseexplicit opt-out for isolated private networks

يوصى بـTLS. يتطلب plaintext cluster opt-out صريحًا لشبكة خاصة ولا يوفر confidentiality أو certificate-based node identity.

هوية voter مستقرة

VariableConstraintPurpose
CLUSTER_ID1–128 ASCII alnum/./_/-fencing domain
CLUSTER_NODE_IDu64Raft ID; never reuse after retirement
CLUSTER_INCARNATIONnon-zero u128freshly issued per process start
CLUSTER_SELFhost:client-portstable client slot and redirect address
CLUSTER_RAFT_SELFhost:raft-portunique Raft/control address for this process
CLUSTER_PEERSexactly 3 or 5NodeId@incarnation@client-address@raft-address entries

كل cluster identity variables مطلوبة معًا؛ غيابها كلها يعني single mode. يحتاج كل process start إلى incarnation جديدة صادرة خارجيًا. لا يعاد استخدام retired NodeId؛ يدخل replacement كـlearner بـNodeId جديدة. Client/Raft ports صريحة ولا قاعدة +1000.

Startup admission هو fail-closed. لا يصبح initial cluster Open حتى يثبت كل peer حالة empty/unconsumed ويجتاز Prepared barrier. لا يفتح replacement إلا بعد one-shot Join. ترفض Pending/Prepared طلبات Vote وAppend وSnapshot وclient mutation. لا يُفترض peer غير متاح empty.

Raft وclock موثقة

VariableDefaultConstraint
CLUSTER_HEARTBEAT_MS500>=10
CLUSTER_ELECTION_TIMEOUT_MS2000>=600, >=4× heartbeat
CLUSTER_SNAPSHOT_TIMEOUT_MS120000>=1000
RAFT_PROGRESS_TIMEOUT_MS10000>=1000
CLUSTER_CLOCK_AGENT_ENDPOINTunsetrequired numeric IP:port in cluster
CLUSTER_CLOCK_AGENT_SECRETunsetrequired, at least 32 bytes, separate domain
CLUSTER_CLOCK_PAIRWISE_DELTA_MS202..=60000, identical on all nodes
CLUSTER_CLOCK_MAX_STALENESS_MS5000greater than sample interval + timeout
CLUSTER_CLOCK_SAMPLE_INTERVAL_MS1000positive and below staleness
CLUSTER_CLOCK_TIMEOUT_MS250positive and below staleness
CLUSTER_CLOCK_MAX_RTT_MS50positive and at most timeout
CLUSTER_CLOCK_MAX_UNCERTAINTY_MS2at most pairwise delta / 2
CLUSTER_CLOCK_MAX_SOURCE_AGE_MS2000positive

يعيد clock endpoint authenticated reference time وuncertainty وsync state وsource age. فشل auth/freshness/RTT/pairwise delta/wall-step يوقف mutation وdrain clients ويغلق Raft.

مصادقة cluster وreplacement join

VariableRequirement
CLUSTER_TOKENSnonblank list required in cluster
CLUSTER_CONTROL_TOKENSnonblank list required in cluster
CLUSTER_BOOTSTRAP_CREDENTIALinitial cluster process only; recorded once in replicated state

Replacement process values generated by prepare-replacement:

  • CLUSTER_JOIN_LEADER
  • CLUSTER_JOIN_LEADER_NODE_ID
  • CLUSTER_JOIN_LEADER_INCARNATION
  • CLUSTER_JOIN_CREDENTIAL
  • CLUSTER_JOIN_SEED_PEERS
  • fresh CLUSTER_NODE_ID, CLUSTER_INCARNATION, CLUSTER_SELF, CLUSTER_RAFT_SELF, CLUSTER_PEERS

Credentials الخاصة بـcluster/control/clock/bootstrap/join domains منفصلة بلا reuse. Join values فقط من prepare-replacement؛ credential one-shot، default 60s والمسموح 5–300s. Peer wire يطابق CLUSTER_WIRE_VERSION=1 حرفيًا؛ لا تستخدم package version.

See zero-downtime fresh-NodeId learner replacement.