Distributed Job Scheduler  ·  View 11 of 20  ·  Data

Data Model

Eleven entities, and one four-part primary key that does the work of a deduplication service.

Editable source SVG draw.io All views
tenant tenant_id PK quota_triggers quota_dispatch_per_s quota_inflight catchup_rate_pct trigger trigger_id PK tenant_id FK name UQ(tenant,name) state live|paused|deleted current_version FK trigger_version version_id PK trigger_id FK recurrence zone IANA target_id FK payload_ref encrypted missed_policy overlap_policy catchup_horizon_s attempt_budget target target_id PK tenant_id FK kind http|queue|exec endpoint verified_at verification_state audit_entry audit_id PK tenant_id FK actor action prior_value at due_index_row partition_id PK1 next_instant PK2 trigger_id FK version_id FK claimed_by nullable fire tenant_id PK1 trigger_id PK2 scheduled_instant PK3 sequence PK4 version_id FK origin sched|manual|backfill state non_dispatch_cause decided_at tzdata_version attempt attempt_id PK fire_key FK n dispatched_at transport_result http_status token_jti partition_lease partition_id PK owner_id expires_at epsilon_ms_at_grant work_outcome fire_key PK/FK terminal_state reported_at reported_by cause history_row row_key tenant#trigger#instant fire + attempts, projected ttl 90 d 1 : N 1 : N N : 1 1 : N 1 : 1 1 : N 1 : N N : 1 1 : 0..1 N : 1 Data Model — Trigger, Instant, Fire, Attempt The fire's four-part primary key is the idempotency key: a duplicate decision is a constraint violation, not a detection problem. Non-dispatch is a field on the fire, not a separate record. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • The fire's primary key is (tenant, trigger, scheduled instant, sequence) — which is the idempotency key. A duplicate decision is a constraint violation, not something to detect (ADR-03).
  • Definitions are versioned and immutable once fired against, and every fire names its version, so a disputed instant is explainable after an amendment (ADR-05).
  • The tzdata version is a column on the fire, because a time-zone database update is a silent change to a future instant otherwise (ADR-07).

Assumptions

  • Non-dispatch is a field on the fire rather than a separate record, which assumes a fire has at most one terminal non-dispatch cause.
  • work_outcome is 1:0..1 against the fire: the absent row is the unknown state, which overlap control in view 14 must handle rather than wait on.

Deliberate omissions

  • Quota counters, next-fire caches and the billing rollup are projections and appear in view 10, not here.