Distributed Job Scheduler · View 14 of 20 · Runtime
Decisions
- The shedding order is published: backfill, then catch-up, then over-quota steady state, and only then on-time fires. Degradation is a decision rather than an emergent property (ADR-09).
- A retry stays in its origin lane and its budget is truncated at the next scheduled instant, so a failing minute-schedule cannot accumulate a backlog of its own retries (ADR-12).
- Jitter smearing is opt-out rather than opt-in, because most triggers do not care about their exact instant and the few that do know it (ADR-10).
Assumptions
- Default per-tenant quotas: 2,000 active triggers, 50 dispatches/s, 200 in-flight fires, 5,000 backfilled fires per operation. All assumed and independently raisable.
Risks
- Smearing makes the scheduled instant inexact for triggers that silently did care. The opt-out is discoverable only if the tenant reads the lateness distribution.