Distributed Job Scheduler · View 07 of 20 · Structure
Decisions
- Three dispatch lanes as separate queues rather than priorities in one, so the shedding order is enforced by which queue stops draining (ADR-09).
- The shadow rebuilder is a first-class component, not a script: the due index's rebuildability is verified continuously rather than asserted (ADR-11).
- Only the attempt runner has egress. Everything else is reachable only from inside the perimeter (ADR-14).
Assumptions
- A 1-second due-scan tick, and 256 partitions. Both assumed; the partition count is the knob that trades scan cost against claim contention.
Deliberate omissions
- Five edges are drawn. The registry writes, the history fan-out and the identity and monitoring dependencies of every tier are omitted so the fire path stays readable.