Distributed Lock Service · View 12 of 26 · 4 · Data
Decisions
- The tailer watches each cluster from its last checkpointed revision and inserts in batches keyed by cluster ID and revision. Replays are idempotent, so RPO is the checkpoint interval, well inside 60 seconds.
- Expiries are captured because they are committed revocations in the log. An audit trail written by the arbiter would miss every expiry, which is the event investigators most need.
- Force-release archives sit under MinIO object lock in retention mode for seven years. Grant history goes to Parquet for one year.
The one failure to design for
- If the tailer lags past etcd's compaction window, the revisions it needs are gone. It alarms at half the window and never skips: a gap is recorded as a gap with its revision range, not papered over.
Assumptions
- etcd compacts hourly, keeping one hour of revisions. The tailer's normal lag is seconds.
- Denied acquisitions and rate-limit rejections go to logs and metrics, not the audit store. They are operational signals, not grants.