| Scheduled instant |
The absolute UTC instant a recurrence resolves to, derived from the expression, the named zone and a recorded time-zone database version. |
The thing the fire is identified by, ordered by, and measured against. |
"Fire time", which is usually used for the moment a dispatch actually left — the quantity this package calls the dispatch instant. |
| Fire record |
An immutable row committed before any dispatch attempt, carrying the tenant, trigger, definition version, scheduled instant and a deterministic key. |
The scheduler's durable product and the system of record for "was this instant decided". |
A "job run", which implies work happened; a fire record says only that a decision was taken. |
| Idempotency key |
The fire's four-part primary key (tenant, trigger, scheduled instant, sequence), computed rather than generated. |
Makes a duplicate decision a uniqueness violation instead of something to detect, and gives the executor something to deduplicate on. |
A generated request identifier, which deduplicates transport retries but cannot deduplicate two independent decisions. |
| ε (clock uncertainty) |
The half-width of the interval a bounded time source reports around the current instant. |
The quantity the scheduler waits out, which is what converts clock skew into lateness rather than earliness. |
"Clock skew", which usually names the error itself rather than a reported bound on it. |
| Lateness |
Dispatch instant minus scheduled instant, measured per fire and published per trigger as a distribution. |
The budget the design spends; it is the measure of availability for the dispatch plane. |
"Latency", which in a request-shaped service means time to respond rather than distance from a deadline. |
| Missed-fire policy |
A per-trigger declaration — fire-all, fire-once-now or skip — of what to do with instants that should have fired and did not. |
Moves the post-outage decision from the incident to the definition. |
"Misfire instruction" in some scheduler libraries, usually with the same three options and no horizon. |
| Catch-up horizon |
The maximum age of a missed instant that may still be dispatched; beyond it the instant is recorded as expired. |
The platform's bound on how much work any interruption can accumulate, overriding the tenant's policy. |
A "grace period", which usually means how long a late fire is still considered on time. |
| Catch-up storm |
A backlog of missed instants released at once by a recovery, a resume or a backfill. |
The expected failure mode of a scheduler, and the thing the lane split and the rate cap exist for. |
A "thundering herd", which names simultaneous arrival generally rather than the self-inflicted recovery case. |
| Overlap policy |
A per-trigger declaration — allow, skip or queue — of what to do when a fire comes due while the previous execution has not reported terminal. |
The only control the scheduler has over concurrency in work it does not run. |
"Concurrency policy", which in some systems bounds parallel runs numerically rather than deciding what to do about one. |
| Unknown (terminal state) |
The recorded state of a fire whose outcome never arrived inside its outcome window, including a dispatch attempt that timed out. |
Prevents the scheduler withholding every later fire on a missing callback, at the price of occasional concurrent execution. |
"Failed", which asserts the work did not happen — a claim the platform cannot make about a timeout. |
| Backfill |
An authorised generation of fires for a declared past window, labelled as such and rate-capped in its own lane. |
The recovery path for work lost beyond the horizon, and a privilege separate from authorship. |
A "replay", which in event systems means re-delivering records that already exist rather than creating new ones. |
| Partition lease |
A short-TTL claim on a range of the trigger keyspace, recording the ε observed at grant. |
The unit of mutual exclusion in the timing plane — deliberately imperfect, because the fire key makes imperfection survivable. |
"Leader election", which implies one authority per service rather than one per partition. |
| Due index |
One row per live trigger holding its single next instant, partitioned and scanned in time order. |
The structure the scheduler reads; a rebuildable projection of the registry, not a system of record. |
A "timer wheel", which is an in-memory structure with the same purpose and no durability. |
| Oldest undispatched due age |
The age of the oldest instant that is due and has not yet been dispatched, measured per partition. |
The paging alert, because it is the only signal that distinguishes a healthy scheduler from a silent one. |
"Queue depth", which counts work waiting without saying how long the oldest item has been waiting. |