Conversation
manjari25
requested review from
a team,
behinddwalls and
sbalabanov
as code owners
September 29, 2026 22:36
sbalabanov
reviewed
Sep 30, 2026
|
|
||
| ## Open questions | ||
|
|
||
| - **Fail open or closed on freeze.** Reject fails closed when pause state cannot be read, because `Land()` returns the error. However, the consumer treats a gate read error as open, so an adapter that returns the store's error would silently unfreeze a queue during a store outage. The adapter can instead return a blocked entry on error to fail closed. Which posture should freeze take? |
| ## Open questions | ||
|
|
||
| - **Fail open or closed on freeze.** Reject fails closed when pause state cannot be read, because `Land()` returns the error. However, the consumer treats a gate read error as open, so an adapter that returns the store's error would silently unfreeze a queue during a store outage. The adapter can instead return a blocked entry on error to fail closed. Which posture should freeze take? | ||
| - **Cancel during freeze.** Should cancel take effect while processing is frozen, as an incident workflow of freeze, cancel, unfreeze would need? If so, freeze becomes no new effects rather than nothing runs, and needs the topic on the gate key ([Cancellation](#cancellation)). |
Contributor
There was a problem hiding this comment.
marking the request as cancelled is probably fine, the processing to resume on unfreeze
| - **Fail open or closed on freeze.** Reject fails closed when pause state cannot be read, because `Land()` returns the error. However, the consumer treats a gate read error as open, so an adapter that returns the store's error would silently unfreeze a queue during a store outage. The adapter can instead return a blocked entry on error to fail closed. Which posture should freeze take? | ||
| - **Cancel during freeze.** Should cancel take effect while processing is frozen, as an incident workflow of freeze, cancel, unfreeze would need? If so, freeze becomes no new effects rather than nothing runs, and needs the topic on the gate key ([Cancellation](#cancellation)). | ||
| - **OSS backing.** `file` is proposed first because it needs no schema and works with a mounted config file. A MySQL-backed store would serve multi-host OSS deployments, and needs a way for an operator to write it. | ||
| - **Read cost.** The `file` store reads on every `Land()` and on every gated delivery. A short cache may be needed. |
| } | ||
| ``` | ||
|
|
||
| The orchestrator wires a gate over the same store: |
Contributor
There was a problem hiding this comment.
why this cannot be integrated with consumergate? Altering consumergate to satisfy both scenarios is a possibility, was it considered?
Contributor
Author
There was a problem hiding this comment.
Can you clarify what both scenarios you mean here?
Collaborator
There was a problem hiding this comment.
i think that could work here, we can just block on consumer gate to stop consuming things from the queue, we just need change where we read the gating information i guess
Contributor
Author
There was a problem hiding this comment.
That would mean there is no "reject" mode. Just accept + hold for processing. Is that what you mean?
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why?
We need a mechanism to pause and unpause queues during incidents, maintenance windows etc.
What?
This PR adds an RFC for pausing and unpausing a queue at runtime, comparing pause state on queue config against a separate pause-state extension.
Test Plan
RFC only; code change in next PR.
Issue