pub struct Envelope {Show 29 fields
pub id: String,
pub kind: String,
pub schema_version: u32,
pub payload: Vec<u8>,
pub queue: String,
pub partition_key: String,
pub rate_class: String,
pub weight: u32,
pub fingerprint: String,
pub priority: i32,
pub attempt: u32,
pub crash_attempt: u32,
pub max_attempts: u32,
pub scheduled_at_ms: i64,
pub timeout_ms: i64,
pub deadline_ms: i64,
pub unique_key: Option<Vec<u8>>,
pub unique_states: u32,
pub unique_window_ms: i64,
pub unique_replace: u32,
pub unique_debounce_ms: i64,
pub unique_exclude_kind: bool,
pub retention_ms: i64,
pub periodic_schedule_id: String,
pub periodic_tick_ms: i64,
pub headers: BTreeMap<String, String>,
pub tags: Vec<String>,
pub pending: bool,
pub sticky_worker: String,
}Fields§
§id: String§kind: String§schema_version: u32§payload: Vec<u8>§queue: String§partition_key: String§rate_class: String§weight: u32surveyed policy behavior estimated rate-budget cost. 0 is the backward-compatible omitted wire
value and is normalized to 1 at the store boundary; APIs reject an explicit 0.
Actual usage may be reported by the handler and reconciled atomically on ack.
fingerprint: String§priority: i32§attempt: u32§crash_attempt: u32§max_attempts: u32§scheduled_at_ms: i64§timeout_ms: i64§deadline_ms: i64§unique_key: Option<Vec<u8>>job uniqueness uniqueness is an index, not a lock. None opts out.
unique_states: u32Bitmask of states uniqueness applies in — River’s design (wire schema field 15).
unique_window_ms: i64job uniqueness uniqueness mode. 0 = LIFECYCLE: one live job per key, released by terminal state. > 0 = THROTTLE: at most one per this many ms, released by the clock. Negative is invalid, and a caller-side duration that rounds to zero must be REJECTED (boundary validation), never clamped into lifecycle mode.
unique_replace: u32surveyed policy behavior fields to replace atomically when unique_key conflicts. This is a
request-only bitmask; it is never persisted as job state. Unknown bits fail at
the boundary. Replacement is deliberately single-job so batch atomicity remains
explicit rather than partially mutating a mixed batch.
unique_debounce_ms: i64Trailing-edge debounce window. Requires a unique key. Store time determines the due instant on the initial insert and every conflict.
unique_exclude_kind: boolWhen false the task kind is part of the effective uniqueness key. True removes it deliberately, allowing equal caller keys to coalesce across kinds.
retention_ms: i64retention and eviction contract/retention policy retention after success. 0 = ephemeral: delete on completion.
periodic_schedule_id: StringTyped durable origin for periodic jobs. Both fields are set together; empty/zero means an ordinary enqueue. Operators never have to parse ids or opaque headers.
periodic_tick_ms: i64§headers: BTreeMap<String, String>telemetry and trace context opaque caller metadata carried with the job (proto field 20). The store
never interprets these bytes — it round-trips them. Two keys are RESERVED:
TRACEPARENT and TRACESTATE (W3C Trace Context). A BTreeMap rather
than a hash map because the JSON the adapters write must be byte-identical
between the two languages, and Go’s encoding/json sorts map keys.
Canonical, operator-indexed labels. Stores persist these separately from headers.
pending: boolDurable but admission-ineligible until Inspect::promote_job succeeds.
sticky_worker: StringExact stable worker identity allowed to claim this job. Empty means any worker. The route survives retries and lease recovery because it is envelope state, not lease state. Eligibility is enforced inside the atomic admission gate.