Distributed Job Scheduler · View 02 of 20 · Context and scope
Decisions
- Commit precedes dispatch at every point on the spine. A dispatcher that dies mid-attempt loses an attempt and never a fire (ADR-01).
- Rate shaping sits between the ledger and the dispatcher, not inside it, so a backlog is queued state rather than a burst of retries (ADR-09).
- Lateness facts land in a separate reporting store so a punctuality question never competes with the fire path for capacity.
Assumptions
- A design peak of 45,000 fires per second for five seconds at the top of the hour, from an assumed 60% of fires landing in the first second of a minute.
- Steady state 5,800 fires a second — so the peak is roughly 8× the mean minute and is a dispatch problem rather than a scheduling one.
Deliberate omissions
- The identity and monitoring fan-out touches every stage and is drawn only in views 16 and 18.
- The management read paths (dry-run, next-fires, history) are in view 08, not on the spine.