配置 (环境变量)
配置仅来自环境变量。名称不区分大小写;空值视为未设置;只有1/true/yes/on为true。范围或组合错误会中止startup。scratch image不使用local disk/PV。
通用设置与resource上限
| Variable | Default | Allowed | Purpose |
|---|---|---|---|
SERVER_PORT | 5225 | valid u16 port | single client port; cluster advertises CLUSTER_SELF |
SOCKET_BIND | 0.0.0.0 | bindable address | client and Raft bind host |
DEBUG_MODE | build setting | flag | debug logging |
DOCKER_MODE | false | flag | official image binds internal 5225/6225 |
MAX_CONNECTIONS | 1024 | 1..8192 | concurrent client connections |
MAX_RAFT_CONNECTIONS | 64 | 1..256 | separate Raft/control reserve |
MAX_WAITERS | 2048 | 1..16384 | waiters per key; excess acquire gets B |
MAX_TOTAL_WAITERS | 16384 | MAX_WAITERS..65536 | total waiters; excess acquire gets B |
| Hard cap | Value | Saturation behavior |
|---|---|---|
| in-flight acquire per connection | 64 | B for that acquire |
| global in-flight acquire | 4096 | B for that acquire |
| global in-flight release | 512 separate lane | bounded wait until connection close |
| queued replies per connection | 256 | close slow client |
| coordinator channel | 4096 | backpressure |
| cluster active keys | 65536 | B for new-key acquire |
| Raft frame | 64MiB | reject RPC |
| encoded snapshot | 64MiB - 64KiB | reject build/install |
| concurrent Raft decode budget | 72MiB | bounded permit wait/timeout |
默认profile面向512MiB memory limit。不能超过hard ceiling,也没有unlimited设置。
client认证与TLS
| Variable | Default | Purpose |
|---|---|---|
CLIENT_TOKENS | one empty token | comma-separated client credentials; production should use nonblank secrets |
TLS_CERT / TLS_KEY | unset | server certificate chain/private key; set together |
TLS_CA | system roots | CA for peer certificate verification |
TLS_SKIP_VERIFY | false | test only |
CLUSTER_ALLOW_PLAINTEXT_PRIVATE | false | explicit opt-out for isolated private networks |
推荐TLS。plaintext cluster必须显式选择private network opt-out,并且不提供机密性或certificate-based node identity。
稳定voter identity
| Variable | Constraint | Purpose |
|---|---|---|
CLUSTER_ID | 1–128 ASCII alnum/./_/- | fencing domain |
CLUSTER_NODE_ID | u64 | Raft ID; never reuse after retirement |
CLUSTER_INCARNATION | non-zero u128 | freshly issued per process start |
CLUSTER_SELF | host:client-port | stable client slot and redirect address |
CLUSTER_RAFT_SELF | host:raft-port | unique Raft/control address for this process |
CLUSTER_PEERS | exactly 3 or 5 | NodeId@incarnation@client-address@raft-address entries |
cluster identity变量必须一起设置;全部省略为single mode。每次process start都必须由外部签发新incarnation。retired NodeId不再复用;replacement以新NodeId learner加入。client与Raft port均显式指定,不存在+1000规则。
startup admission为fail-closed。初始cluster仅在所有peer证明empty/unconsumed并通过Prepared barrier后Open。replacement仅在one-shot Join批准后Open。Pending/Prepared拒绝Vote、Append、Snapshot和client mutation;绝不把unreachable peer当作empty。
Raft与认证clock
| Variable | Default | Constraint |
|---|---|---|
CLUSTER_HEARTBEAT_MS | 500 | >=10 |
CLUSTER_ELECTION_TIMEOUT_MS | 2000 | >=600, >=4× heartbeat |
CLUSTER_SNAPSHOT_TIMEOUT_MS | 120000 | >=1000 |
RAFT_PROGRESS_TIMEOUT_MS | 10000 | >=1000 |
CLUSTER_CLOCK_AGENT_ENDPOINT | unset | required numeric IP:port in cluster |
CLUSTER_CLOCK_AGENT_SECRET | unset | required, at least 32 bytes, separate domain |
CLUSTER_CLOCK_PAIRWISE_DELTA_MS | 20 | 2..=60000, identical on all nodes |
CLUSTER_CLOCK_MAX_STALENESS_MS | 5000 | greater than sample interval + timeout |
CLUSTER_CLOCK_SAMPLE_INTERVAL_MS | 1000 | positive and below staleness |
CLUSTER_CLOCK_TIMEOUT_MS | 250 | positive and below staleness |
CLUSTER_CLOCK_MAX_RTT_MS | 50 | positive and at most timeout |
CLUSTER_CLOCK_MAX_UNCERTAINTY_MS | 2 | at most pairwise delta / 2 |
CLUSTER_CLOCK_MAX_SOURCE_AGE_MS | 2000 | positive |
clock endpoint必须返回认证reference time、uncertainty、sync state与source age。auth、freshness、RTT、pairwise delta或wall-step检查失败会停止新mutation、drain client并关闭Raft。
cluster认证与replacement join
| Variable | Requirement |
|---|---|
CLUSTER_TOKENS | nonblank list required in cluster |
CLUSTER_CONTROL_TOKENS | nonblank list required in cluster |
CLUSTER_BOOTSTRAP_CREDENTIAL | initial cluster process only; recorded once in replicated state |
Replacement process values generated by prepare-replacement:
CLUSTER_JOIN_LEADERCLUSTER_JOIN_LEADER_NODE_IDCLUSTER_JOIN_LEADER_INCARNATIONCLUSTER_JOIN_CREDENTIALCLUSTER_JOIN_SEED_PEERS- fresh
CLUSTER_NODE_ID,CLUSTER_INCARNATION,CLUSTER_SELF,CLUSTER_RAFT_SELF,CLUSTER_PEERS
cluster/control/clock/bootstrap/join credential属于不同认证domain,不得复用。Join值只来自prepare-replacement输出;credential为one-shot(默认60秒,允许5–300秒)。peer wire必须exact匹配CLUSTER_WIRE_VERSION=1,不使用package version判断。