ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Rules.Effectful

Description

The resilience harness around the advisory package read: a per-attempt timeout, bounded retry with backoff, and a per-rule circuit breaker, attached by prepare.

Any value the read returns resets the breaker unretried, so only a harness-observed fault advances the breaker and returns a ReadFault. runResilient never throws.

Synopsis

The resilience policy

data Resilience Source #

The resilience policy around one advisory rule's reads. Each rule holds its own breaker state.

Constructors

Resilience 

Fields

data EffectfulConfig Source #

The resilience knobs around an advisory rule's package read. The breaker's timing reads resClock fresh at failure commit, not the request snapshot ctxNow.

Constructors

EffectfulConfig 

Fields

  • ecTimeout :: Int

    The per-attempt timeout in microseconds. The harness treats an attempt that does not return within it as a failure, a transient and retryable cause.

  • ecBackoff :: [Int]

    The delay in microseconds before each retry, one entry per retry. Its length is the retry budget, so [] admits no retry at all.

  • ecBreakerThreshold :: Int

    Consecutive exhausted reads that trip the breaker, one read per request.

  • ecBreakerCooldown :: NominalDiffTime

    How long the breaker stays open (fast-failing the rule) before it allows a single half-open probe to test recovery.

  • ecRetryAfter :: Maybe RetryAfter

    The Retry-After hint a faulted evaluation carries back to the client. Nothing sends no hint.

defaultEffectfulConfig :: EffectfulConfig Source #

A 2-second per-attempt timeout and two retries, at 100ms then 250ms. The breaker trips after 5 consecutive failures and cools for 30 seconds.

newBreaker :: IO (TVar Breaker) Source #

A fresh, healthy breaker (no failures recorded) in a new TVar.

Running a read through it

runResilient :: Resilience -> IO a -> IO (Either ReadFault a) Source #

Run one read under its Resilience policy: the read's value, or why the harness gave it up.

data ReadFault Source #

Why the harness gave a read up. Each rule relying on it resolves this under its own alignment.

Constructors

ReadFault 

Fields

  • rfTransience :: Transience

    Whether a retry may succeed, with the configured Retry-After hint.

  • rfReason :: Text

    The client-facing cause a decision carries.

  • rfDetail :: Text

    The fault detail an operator reads in the outage report, never in a client message.

Instances

Instances details
Show ReadFault Source # 
Instance details

Defined in Ecluse.Core.Rules.Effectful

Eq ReadFault Source # 
Instance details

Defined in Ecluse.Core.Rules.Effectful