Deliveries run on a Mongo job queue with leases, backoff and per-host limits
The single serial DeliveryWorker is replaced by Infrastructure/Jobs: - Job rows are leased with one FindOneAndUpdate (oldest RunAt first, a two-minute lease) and a reaper returns expired leases every 30 s; - enqueueing wakes the workers, which otherwise poll every five seconds; - delivery runs eight at a time with at most two per host, so a slow or dead server holds two slots, not the queue; - a failure waits n^4 + 15 + jitter seconds (Mastodon's curve) for up to 16 attempts; a 4xx other than 408/429 is final, a 429 honours Retry-After; - RemoteInstance is a per-host circuit breaker: ten consecutive failures quarantine a host for an hour, doubling to a week, and its jobs wait without spending attempts; - a delivery is queued once per activity and inbox (unique DedupeKey), and finished jobs expire after seven days (TTL on FinishedAt). Migration _004 moves pending Delivery rows into jobs and marks them abandoned, so a rollback to the old worker cannot send them twice. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
1 parent
934b6fe687
commit
d1a91c40c4
15 files changed
+704
-99
No files matched your search
@@ -0,0 +1,14 @@
|
||||
using MongoDB.Entities;
|
||||
|
||||
namespace PrivaPub.Models.Jobs
|
||||
{
|
||||
public class RemoteInstance : Entity
|
||||
{
|
||||
public string Host { get; set; }
|
||||
public int ConsecutiveFailures { get; set; }
|
||||
public DateTime? UnavailableUntil { get; set; }
|
||||
public DateTime? LastSuccessAt { get; set; }
|
||||
public DateTime? LastFailureAt { get; set; }
|
||||
public string LastError { get; set; }
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user