বর্তমানে পরীক্ষা চলছে: সম্পূর্ণ হলে GitHub কোড উন্মুক্ত করা হবে।

কনফিগারেশন (এনভায়রনমেন্ট ভ্যারিয়েবল)

Configuration শুধু environment variables থেকে আসে। Names case-insensitive, empty হলো unset, এবং শুধু 1/true/yes/on true। ভুল range/combination startup থামায়। Scratch image local disk বা PV ব্যবহার করে না।

Common settings ও resource limits

VariableDefaultAllowedPurpose
SERVER_PORT5225valid u16 portsingle client port; cluster advertises CLUSTER_SELF
SOCKET_BIND0.0.0.0bindable addressclient and Raft bind host
DEBUG_MODEbuild settingflagdebug logging
DOCKER_MODEfalseflagofficial image binds internal 5225/6225
MAX_CONNECTIONS10241..8192concurrent client connections
MAX_RAFT_CONNECTIONS641..256separate Raft/control reserve
MAX_WAITERS20481..16384waiters per key; excess acquire gets B
MAX_TOTAL_WAITERS16384MAX_WAITERS..65536total waiters; excess acquire gets B
Hard capValueSaturation behavior
in-flight acquire per connection64B for that acquire
global in-flight acquire4096B for that acquire
global in-flight release512 separate lanebounded wait until connection close
queued replies per connection256close slow client
coordinator channel4096backpressure
cluster active keys65536B for new-key acquire
Raft frame64MiBreject RPC
encoded snapshot64MiB - 64KiBreject build/install
concurrent Raft decode budget72MiBbounded permit wait/timeout

Default profile 512MiB memory limit লক্ষ্য করে। Hard ceilings পার হওয়া যায় না এবং কোনো unlimited value নেই।

Client authentication ও TLS

VariableDefaultPurpose
CLIENT_TOKENSone empty tokencomma-separated client credentials; production should use nonblank secrets
TLS_CERT / TLS_KEYunsetserver certificate chain/private key; set together
TLS_CAsystem rootsCA for peer certificate verification
TLS_SKIP_VERIFYfalsetest only
CLUSTER_ALLOW_PLAINTEXT_PRIVATEfalseexplicit opt-out for isolated private networks

TLS recommended। Plaintext cluster-এর জন্য explicit private-network opt-out দরকার এবং এটি confidentiality বা certificate-based node identity দেয় না।

Stable voter identity

VariableConstraintPurpose
CLUSTER_ID1–128 ASCII alnum/./_/-fencing domain
CLUSTER_NODE_IDu64Raft ID; never reuse after retirement
CLUSTER_INCARNATIONnon-zero u128freshly issued per process start
CLUSTER_SELFhost:client-portstable client slot and redirect address
CLUSTER_RAFT_SELFhost:raft-portunique Raft/control address for this process
CLUSTER_PEERSexactly 3 or 5NodeId@incarnation@client-address@raft-address entries

সব cluster identity variable একসঙ্গে বাধ্যতামূলক; সব absent হলে single mode। প্রতিটি process start-এ externally issued fresh incarnation দরকার। Retired NodeId reuse নয়; replacement fresh NodeId learner। Client/Raft ports explicit, +1000 rule নেই।

Startup admission fail-closed। Initial cluster শুধু তখন Open যখন প্রতিটি peer empty/unconsumed প্রমাণ করে Prepared barrier পার হয়। Replacement শুধু one-shot Join-এর পরে Open। Pending/Prepared Vote, Append, Snapshot ও client mutation reject করে। Unreachable peer কখনো empty ধরা হয় না।

Raft ও authenticated clock

VariableDefaultConstraint
CLUSTER_HEARTBEAT_MS500>=10
CLUSTER_ELECTION_TIMEOUT_MS2000>=600, >=4× heartbeat
CLUSTER_SNAPSHOT_TIMEOUT_MS120000>=1000
RAFT_PROGRESS_TIMEOUT_MS10000>=1000
CLUSTER_CLOCK_AGENT_ENDPOINTunsetrequired numeric IP:port in cluster
CLUSTER_CLOCK_AGENT_SECRETunsetrequired, at least 32 bytes, separate domain
CLUSTER_CLOCK_PAIRWISE_DELTA_MS202..=60000, identical on all nodes
CLUSTER_CLOCK_MAX_STALENESS_MS5000greater than sample interval + timeout
CLUSTER_CLOCK_SAMPLE_INTERVAL_MS1000positive and below staleness
CLUSTER_CLOCK_TIMEOUT_MS250positive and below staleness
CLUSTER_CLOCK_MAX_RTT_MS50positive and at most timeout
CLUSTER_CLOCK_MAX_UNCERTAINTY_MS2at most pairwise delta / 2
CLUSTER_CLOCK_MAX_SOURCE_AGE_MS2000positive

Clock endpoint authenticated reference time, uncertainty, sync state ও source age দেয়। Auth/freshness/RTT/pairwise delta/wall-step failure mutation বন্ধ করে, clients drain এবং Raft shutdown করে।

Cluster authentication ও replacement join

VariableRequirement
CLUSTER_TOKENSnonblank list required in cluster
CLUSTER_CONTROL_TOKENSnonblank list required in cluster
CLUSTER_BOOTSTRAP_CREDENTIALinitial cluster process only; recorded once in replicated state

Replacement process values generated by prepare-replacement:

  • CLUSTER_JOIN_LEADER
  • CLUSTER_JOIN_LEADER_NODE_ID
  • CLUSTER_JOIN_LEADER_INCARNATION
  • CLUSTER_JOIN_CREDENTIAL
  • CLUSTER_JOIN_SEED_PEERS
  • fresh CLUSTER_NODE_ID, CLUSTER_INCARNATION, CLUSTER_SELF, CLUSTER_RAFT_SELF, CLUSTER_PEERS

Cluster/control/clock/bootstrap/join credentials আলাদা domains, reuse নয়। Join values শুধু prepare-replacement থেকে; one-shot credential default 60s, allowed 5–300s। Peer wire exact CLUSTER_WIRE_VERSION=1; package version ব্যবহার হয় না।

See zero-downtime fresh-NodeId learner replacement.