pub struct InstanceRuntimeConfig {
pub snapshots: SnapshotManagerConfig,
pub leases: AccountLeaseConfig,
pub usage: UsageWriterConfig,
pub sharding: LocalSharding,
pub snapshot_history_capacity: NonZeroUsize,
pub idle_account_linger: Duration,
pub manager_restart_backoff: Duration,
pub shutdown_deadline: Duration,
}Expand description
Everything an InstanceRuntime needs to run one instance’s control
plane: snapshot distribution, per-account lease refill, usage accounting,
local sharding, account lifecycle timing and the shutdown budget.
There are no defaults; every value is a deployment decision.
validate runs before any task starts (INVARIANTS.md 16),
and docs/GETTING_STARTED.md walks through a worked configuration.
Fields§
§snapshots: SnapshotManagerConfigSnapshot distribution: which principals to serve, and how often and
how patiently to fetch them. Validated by
SnapshotManagerConfig::validate; a TrackedPrincipals::Fixed
list must also fit snapshot_history_capacity.
leases: AccountLeaseConfigLease refill settings applied to every account the runtime discovers.
Validated by AccountLeaseConfig::validate. Its
shutdown_release_deadline is one of the two phases
shutdown_deadline must cover.
usage: UsageWriterConfigThe bounded usage queue and its writer. Validated by
UsageWriterConfig::validate. Its shutdown_drain_deadline is the
other phase shutdown_deadline must cover.
sharding: LocalShardingInstance-local shard layout for the snapshot map and every account’s
lease slot. LocalSharding::SINGLE is the unsharded layout; more
shards trade per-account memory for less cache-line sharing between
request-serving threads, and help only while those threads do not
outnumber the shards (RuntimeReport::sharding reports whether they
do). See docs/LOCAL_SHARDING.md.
snapshot_history_capacity: NonZeroUsizeRetained snapshot histories, including in-flight authoritative reads. Cover the simultaneously served principal set; exceeding it evicts principals until a fresh source read can reconstruct their history.
Counted in principals. Too small evicts live principals, which deny
until the next authoritative read restores them and show up in
SnapshotStats::history_evictions; larger costs memory per retained
history. Must be at least the length of a
TrackedPrincipals::Fixed list.
idle_account_linger: DurationTime with no fresh active principal before returning routine grants. Zero requests immediate retirement; this is not a traffic-idle timer.
An account becomes ineligible when its last active, unexpired snapshot is removed, revoked, suspended or expires; its lease manager then lingers for this long and is retired (releasing its lease) unless a fresh active principal returns first. Too short churns lease acquire and release when an account’s snapshots briefly lapse; too long holds granted units on an instance that can no longer spend them. Must fit the monotonic clock.
manager_restart_backoff: DurationDelay before restarting an account’s lease manager that exited while
the account was still eligible. The account is in
AccountPhase::Backoff meanwhile, with no manager refilling its
slot.
Too short retries a failing allocator or a crashing task in a tight loop; too long leaves the account’s slot unrefilled, and readiness counts it unmanaged, for the whole delay. An integrity fault is never restarted: it shuts the runtime down instead (INVARIANTS.md 31). Must be positive.
shutdown_deadline: DurationOne budget, measured from the first shutdown request.
Covers the usage drain, the snapshot manager’s stop and every
account’s lease release; a background failure that triggers shutdown
starts it too. Must be at least
usage.shutdown_drain_deadline + leases.shutdown_release_deadline.
Too short leaves usage unresolved and leases abandoned to TTL reclaim
(INVARIANTS.md 9), reported in RuntimeShutdownReport; the value is
also how long an orchestrator must allow the process to stop.
Implementations§
Source§impl InstanceRuntimeConfig
impl InstanceRuntimeConfig
Sourcepub fn validate(&self) -> Result<(), InstanceRuntimeConfigError>
pub fn validate(&self) -> Result<(), InstanceRuntimeConfigError>
Check the whole configuration without starting anything: each
component’s own validate, a fixed principal list within
snapshot_history_capacity, a shutdown_deadline that covers the
usage drain plus lease release, a positive manager_restart_backoff,
and every duration representable on the monotonic clock.
InstanceRuntime::spawn calls this first.
§Errors
The first rule the configuration breaks.