pub struct UsageWriterConfig {
pub queue_capacity: usize,
pub max_batch: usize,
pub flush_interval: Duration,
pub retry_backoff: Duration,
pub shutdown_drain_deadline: Duration,
pub ingest_timeout: Duration,
}Expand description
The usage queue’s size and the writer’s batching, retry and shutdown timing.
There are no defaults; every value is a deployment decision.
validate runs before the task starts
(INVARIANTS.md 16).
Fields§
§queue_capacity: usizeChannel capacity — the shed point. Size it to cover the sink’s worst tolerable outage at peak admission rate.
Counted in usage events, one per in-flight or committed-but-unwritten
request. Every reserved permit holds a slot, so it also caps
concurrent admitted requests. Too small sheds
(AccountingBackpressure, zero charge) during brief sink hiccups or
bursts; too large lets a longer outage pile up unbilled events in
memory and in the shutdown drain. The writer splits it exactly into
lanes by host parallelism, with at least 64 slots a lane when there is
more than one. Must be positive.
max_batch: usizeLargest batch handed to one ingest call.
Counted in events. Too small multiplies sink calls under load; too
large makes each call, and each retry of a failing one, heavier. It
also sets how full a lane gets before it wakes the writer early. Must
be positive and at most MAX_INGEST_BATCH, the ingest endpoint’s
limit.
flush_interval: DurationA partial batch is flushed after at most this long.
The latency between a charge being recorded and the sink seeing it at low traffic. Too long delays billing and leaves more events in the queue when a process dies; too short sends many small batches. Must be positive.
retry_backoff: DurationBackoff between retries of a failing ingest.
A failing sink is retried forever at this pace while the queue fills and sheds upstream. Too short hot-spins against a failing sink; too long delays recovery after it returns. Must be positive.
shutdown_drain_deadline: DurationWall-clock bound on the shutdown drain: how long shutdown waits for
outstanding permits (slots reserved by in-flight requests or committed
committed guards) to resolve, including the ingest calls it makes along
the way. Must be positive. Size it within
expiry_safety_margin + reclaim_grace so an event landing at the end
of the drain is still billable against its lease.
Too short reports permits as WriterStats::unresolved and batches
as WriterStats::lost that a longer drain would have billed; too
long risks events landing after their lease settled, which the sink
rejects. Under an InstanceRuntime the
runtime’s shutdown_deadline must cover it.
ingest_timeout: DurationWall-clock bound on one UsageSink::ingest call. A sink that hangs
rather than erroring would otherwise park the writer task forever, and
with it every later shutdown step. Must be positive.
A timed-out call is a failed attempt and is retried; the sink may
still have recorded the batch, which the retry then reports as
duplicate. Set it above the sink’s slowest legitimate ingest of a
full batch: too short turns a slow sink into endless retries; too long
holds the queue behind a hung call.
Implementations§
Source§impl UsageWriterConfig
impl UsageWriterConfig
Sourcepub fn validate(&self) -> Result<(), UsageWriterConfigError>
pub fn validate(&self) -> Result<(), UsageWriterConfigError>
Every field is a contract, so none of them is silently repaired (INVARIANTS.md GL-16): a zero capacity or batch size has no sensible coercion, a zero backoff hot-spins against a failing sink, and a zero deadline or timeout reports failure without waiting at all.