Distributed Job Scheduler  ·  View 14 of 20  ·  Runtime

Dispatch Lanes

Five classes of fire through one pipeline, with a published order for who loses first.

Editable source SVG draw.io All views
Admit Shape Queue Attempt Account On-time Due now Jitter smear opt-out allowed On-time lane drains first Full attempt budget Lateness p99 Catch-up Missed instant Cap at 10% Catch-up lane Original instant kept Backlog depth Backfill Authorised window Volume ceiling Backfill lane shed first Labelled backfill Audit entry Manual run Operator action No displacement On-time lane Own fire key Labelled manual Retry Transport failure Backoff + jitter Origin lane Truncated at next instant Attempt rows Dispatch Lanes — Fire Classes Through the Same Machinery Application we own Queue / topic Data store Decision point Security / platform Person or role Risk / gap One pipeline, five classes, one published shedding order: backfill, then catch-up, then over-quota, then on-time. v 1.0 · owner Platform Architecture · date 2026-10

Decisions

  • The shedding order is published: backfill, then catch-up, then over-quota steady state, and only then on-time fires. Degradation is a decision rather than an emergent property (ADR-09).
  • A retry stays in its origin lane and its budget is truncated at the next scheduled instant, so a failing minute-schedule cannot accumulate a backlog of its own retries (ADR-12).
  • Jitter smearing is opt-out rather than opt-in, because most triggers do not care about their exact instant and the few that do know it (ADR-10).

Assumptions

  • Default per-tenant quotas: 2,000 active triggers, 50 dispatches/s, 200 in-flight fires, 5,000 backfilled fires per operation. All assumed and independently raisable.

Risks

  • Smearing makes the scheduled instant inexact for triggers that silently did care. The opt-out is discoverable only if the tenant reads the lateness distribution.