Distributed Job Scheduler · View 01 of 20 · Context and scope
Decisions
- The scheduler's output is a durable decision — a fire record — not a completed job. Execution is outside the boundary in all three target forms.
- Workflow and DAG orchestration is explicitly out of scope and points at the separate distributed-workflow-orchestration-platform package.
- The time authority is a dependency, not an assumption: the service asks for a bounded uncertainty interval and is prepared to be told the clock is untrustworthy.
Assumptions
- 50,000 tenants, 20 million active triggers, 500 million fires a day — all assumed, not measured.
- Executors can deduplicate on a key supplied with the fire. If they cannot, the at-least-once contract in view 12 is unsafe and ADR-03 has to change.
Risks
- Tenants will read "dispatched" as "the work ran". The outcome split in view 12 exists to make that distinction visible, and it will still be misread.
- Four outbound target forms means four different failure vocabularies arriving at one history view.