設定 (環境変数)
設定は環境変数だけから読みます。nameは大文字小文字を区別せず、空値は未設定、1/true/yes/onだけがtrueです。不正な範囲/組合せはstartupを中止します。scratch imageはlocal disk/PVを使いません。
共通設定とresource上限
| Variable | Default | Allowed | Purpose |
|---|---|---|---|
SERVER_PORT | 5225 | valid u16 port | single client port; cluster advertises CLUSTER_SELF |
SOCKET_BIND | 0.0.0.0 | bindable address | client and Raft bind host |
DEBUG_MODE | build setting | flag | debug logging |
DOCKER_MODE | false | flag | official image binds internal 5225/6225 |
MAX_CONNECTIONS | 1024 | 1..8192 | concurrent client connections |
MAX_RAFT_CONNECTIONS | 64 | 1..256 | separate Raft/control reserve |
MAX_WAITERS | 2048 | 1..16384 | waiters per key; excess acquire gets B |
MAX_TOTAL_WAITERS | 16384 | MAX_WAITERS..65536 | total waiters; excess acquire gets B |
| Hard cap | Value | Saturation behavior |
|---|---|---|
| in-flight acquire per connection | 64 | B for that acquire |
| global in-flight acquire | 4096 | B for that acquire |
| global in-flight release | 512 separate lane | bounded wait until connection close |
| queued replies per connection | 256 | close slow client |
| coordinator channel | 4096 | backpressure |
| cluster active keys | 65536 | B for new-key acquire |
| Raft frame | 64MiB | reject RPC |
| encoded snapshot | 64MiB - 64KiB | reject build/install |
| concurrent Raft decode budget | 72MiB | bounded permit wait/timeout |
default profileは512MiB memory limit向けです。hard ceilingを超えられず、unlimited設定はありません。
client認証とTLS
| Variable | Default | Purpose |
|---|---|---|
CLIENT_TOKENS | one empty token | comma-separated client credentials; production should use nonblank secrets |
TLS_CERT / TLS_KEY | unset | server certificate chain/private key; set together |
TLS_CA | system roots | CA for peer certificate verification |
TLS_SKIP_VERIFY | false | test only |
CLUSTER_ALLOW_PLAINTEXT_PRIVATE | false | explicit opt-out for isolated private networks |
TLSを推奨します。plaintext clusterはprivate network向け明示opt-outが必要で、機密性やcertificate-based node identityを提供しません。
安定したvoter identity
| Variable | Constraint | Purpose |
|---|---|---|
CLUSTER_ID | 1–128 ASCII alnum/./_/- | fencing domain |
CLUSTER_NODE_ID | u64 | Raft ID; never reuse after retirement |
CLUSTER_INCARNATION | non-zero u128 | freshly issued per process start |
CLUSTER_SELF | host:client-port | stable client slot and redirect address |
CLUSTER_RAFT_SELF | host:raft-port | unique Raft/control address for this process |
CLUSTER_PEERS | exactly 3 or 5 | NodeId@incarnation@client-address@raft-address entries |
cluster identity変数は全て一緒に必須で、全省略はsingle modeです。process startごとに外部発行の新incarnationが必要です。retired NodeIdは再利用せず、replacementは新NodeId learnerです。client/Raft portは明示し、+1000規則はありません。
startup admissionはfail-closedです。初期clusterは全peerがempty/unconsumedを証明しPrepared barrierを通って初めてOpenです。replacementはone-shot Join承認後のみOpenです。Pending/PreparedはVote/Append/Snapshot/client mutationを拒否し、unreachable peerをemptyと推定しません。
Raftと認証clock
| Variable | Default | Constraint |
|---|---|---|
CLUSTER_HEARTBEAT_MS | 500 | >=10 |
CLUSTER_ELECTION_TIMEOUT_MS | 2000 | >=600, >=4× heartbeat |
CLUSTER_SNAPSHOT_TIMEOUT_MS | 120000 | >=1000 |
RAFT_PROGRESS_TIMEOUT_MS | 10000 | >=1000 |
CLUSTER_CLOCK_AGENT_ENDPOINT | unset | required numeric IP:port in cluster |
CLUSTER_CLOCK_AGENT_SECRET | unset | required, at least 32 bytes, separate domain |
CLUSTER_CLOCK_PAIRWISE_DELTA_MS | 20 | 2..=60000, identical on all nodes |
CLUSTER_CLOCK_MAX_STALENESS_MS | 5000 | greater than sample interval + timeout |
CLUSTER_CLOCK_SAMPLE_INTERVAL_MS | 1000 | positive and below staleness |
CLUSTER_CLOCK_TIMEOUT_MS | 250 | positive and below staleness |
CLUSTER_CLOCK_MAX_RTT_MS | 50 | positive and at most timeout |
CLUSTER_CLOCK_MAX_UNCERTAINTY_MS | 2 | at most pairwise delta / 2 |
CLUSTER_CLOCK_MAX_SOURCE_AGE_MS | 2000 | positive |
clock endpointは認証済みreference time、uncertainty、sync state、source ageを返します。auth/freshness/RTT/pairwise delta/wall-step検査失敗は新mutationを停止しclientをdrainしてRaftを終了します。
cluster認証とreplacement join
| Variable | Requirement |
|---|---|
CLUSTER_TOKENS | nonblank list required in cluster |
CLUSTER_CONTROL_TOKENS | nonblank list required in cluster |
CLUSTER_BOOTSTRAP_CREDENTIAL | initial cluster process only; recorded once in replicated state |
Replacement process values generated by prepare-replacement:
CLUSTER_JOIN_LEADERCLUSTER_JOIN_LEADER_NODE_IDCLUSTER_JOIN_LEADER_INCARNATIONCLUSTER_JOIN_CREDENTIALCLUSTER_JOIN_SEED_PEERS- fresh
CLUSTER_NODE_ID,CLUSTER_INCARNATION,CLUSTER_SELF,CLUSTER_RAFT_SELF,CLUSTER_PEERS
cluster/control/clock/bootstrap/join credentialは別domainで再利用禁止です。Join値はprepare-replacement出力だけを使い、credentialはone-shot(default 60秒、5–300秒)です。peer wireはCLUSTER_WIRE_VERSION=1 exact matchでpackage versionは使いません。